Check out the new USENIX Web site. next up previous
Next: Identifying Integrity Conflicts Up: Gokyo Policy Analysis Tool Previous: Example 1

Example 2

We define a constraint type for integrity. An integrity constraint where and means that the set of read and execute permissions of must not refer to any objects to which has write permissions.

For each subject type, Gokyo stores the assigned permissions and the prohibited permissions. The prohibited permissions are the permissions whose assignment to the subject would result in the violation of a constraint, so these permissions are represented in terms of the constraint 3. Further, Gokyo identifies the access control space consisting of the intersection between the assigned and prohibited spaces. It is this space where conflict resolution is necessary.



Trent Jaeger
2003-05-11