An operational semantics of Java']Java 2 access control

被引:5
|
作者
Karjoth, G [1 ]
机构
[1] IBM Corp, Zurich Res Lab, Zurich, Switzerland
关键词
D O I
10.1109/CSFW.2000.856939
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Java 2 Security enhanced with Java Authentication and Authorization Service (JAAS) provide sophisticated access control features via a user-configurable authorization policy. Fine-grained access control, code-based as well as user-based authorization, and implicit access rights allow the implementation of real-world policies, but of the cost of increased complexity. In this paper we provide a formal specification of the Java 2 and JAAS access control model that helps remove ambiguities of the informal definitions. It defines Java 2 access control in terms of an abstract machine, whose behavior is determined by a small set of transition rules. we illustrate the power of Java 2 access control by showing how commonly encountered authorization requirements can be implemented in Java 2.
引用
收藏
页码:224 / 232
页数:3
相关论文
共 50 条
  • [11] Access Control of Web and Java']Java Based Applications
    Tso, Kam S.
    Pajevski, Michael J.
    Johnson, Bryan
    2011 IEEE 17TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC), 2011, : 320 - 325
  • [12] Extending Java']Java for package based access control
    Papa, M
    Bremer, O
    Chandia, R
    Hale, J
    Shenoi, S
    16TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2000, : 67 - 76
  • [13] Coalgebras and monads in the semantics of Java']Java
    Jacobs, B
    Poll, E
    THEORETICAL COMPUTER SCIENCE, 2003, 291 (03) : 329 - 349
  • [14] A monad for basic Java']Java semantics
    Jacobs, B
    Poll, E
    ALGEBRAIC METHODOLOGY AND SOFTWARE TECHNOLOGY, PROCEEDINGS, 2000, 1816 : 150 - 164
  • [15] Dynamic semantics of Java']Java bytecode
    Bertelsen, P
    FUTURE GENERATION COMPUTER SYSTEMS, 2000, 16 (07) : 841 - 850
  • [16] Access Control in Java']JavaScript
    Toledo, Rodolfo
    Tanter, Eric
    IEEE SOFTWARE, 2011, 28 (05) : 76 - 84
  • [17] A flexible access control service for Java']Java mobile code
    Corradi, A
    Montanari, R
    Lupu, E
    Sloman, M
    Stefanelli, C
    16TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2000, : 356 - 365
  • [18] Game Semantics for Interface Middleweight Java']Java
    Murawski, Andrzej S.
    Tzevelekos, Nikos
    JOURNAL OF THE ACM, 2021, 68 (01)
  • [19] A Java']Java Inspired Semantics for Transactions in SOC
    Bocchi, Laura
    Tuosto, Emilio
    TRUSTWORTHY GLOBAL COMPUTING, 2010, 6084 : 120 - 134
  • [20] Formal semantics of Java']Java expressions and statements
    Zamulin, AV
    PROGRAMMING AND COMPUTER SOFTWARE, 2003, 29 (05) : 259 - 269