Abstract
We extend a particular access control framework, the Privilege Calculus, with a possibility to override denied access for increased flexibility in hard to define or unanticipated situations. We require the overrides to be audited and approved by appropriate managers. In order to automatically find the authorities who are able to approve an override, we present an algorithm for authority resolution. We are able to calculate from the access control policy who can approve an override without the need for any additional information. © 2005 by International Federation for Information Processing.
Cite
CITATION STYLE
Rissanen, E., Firozabadi, B. S., & Sergot, M. (2005). Discretionary overriding of access control in the privilege calculus. In IFIP Advances in Information and Communication Technology (Vol. 173, pp. 219–232). Springer New York LLC. https://doi.org/10.1007/0-387-24098-5_16
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.