A new model of security for metasystems

被引:11
作者
Chapin, SJ [1 ]
Wang, CX [1 ]
Wulf, WA [1 ]
Knabe, F [1 ]
Grimshaw, A [1 ]
机构
[1] Univ Virginia, Sch Engn & Appl Sci, Dept Comp Sci, Charlottesville, VA 22903 USA
基金
美国国家科学基金会;
关键词
security; metasystem;
D O I
10.1016/S0167-739X(99)00021-7
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the rapid growth of high-speed networking and microprocessing power, metasystems have become increasingly popular. The need for protection and security in such environments has never been greater. However, the conventional approach to security, that of enforcing a single system-wide policy, will not work for the large-scale distributed systems we envision. Our new model shifts the emphasis from 'system as enforcer' to user-definable policies, making users responsible for the security of their objects. This security model has been implemented as part of the Legion project. Legion is an object-oriented metacomputing system, with strong support for autonomy. This includes support for per-object, user-defined policies in many areas, including resource management and security. This paper briefly describes the Legion system, presents our security model, and discusses the realization of that model in Legion. (C) 1999 Elsevier Science B.V. All rights reserved.
引用
收藏
页码:713 / 722
页数:10
相关论文
共 12 条
  • [1] Cheswick WilliamR., 1994, FIREWALLS INTERNET S
  • [2] FAIRTHORNE B, 940416 OBJ MAN GROUP
  • [3] GRIMSHAW AS, 1994, CS9421 UVA CS
  • [4] LAMPSON BW, 1971, P 5 PRINC S INF SCI, P437
  • [5] KERBEROS - AN AUTHENTICATION SERVICE FOR COMPUTER-NETWORKS
    NEUMAN, BC
    TSO, T
    [J]. IEEE COMMUNICATIONS MAGAZINE, 1994, 32 (09) : 33 - 38
  • [6] PARKER T, 1995, SESAME TECHNOLOGY VE
  • [7] RIVEST RL, 1978, COMMUN ACM, V21, P120, DOI 10.1145/357980.358017
  • [8] PROTECTION AND CONTROL OF INFORMATION SHARING IN MULTICS
    SALTZER, JH
    [J]. COMMUNICATIONS OF THE ACM, 1974, 17 (07) : 388 - 402
  • [9] Schneier B, 1994, Applied Cryptography
  • [10] WANG C, CS9608 UVA CS