Skip to main content

Group paradigms in discretionary access controls for object management systems

  • Conference paper
  • First Online:

Part of the book series: Lecture Notes in Computer Science ((LNCS,volume 467))

Abstract

This paper deals with group-oriented discretionary access controls (DAC) in object management systems (OMS). Group-oriented means that subgroup structures which are typical of the organization of design projects are supported. Group paradigms are interpretations of the subgroup structure.

Examples of OMS with group-oriented DAC are CAIS-A and PCTE+. Both support a paradigm which we term the rights package paradigm. In this paradigm, a group corresponds to a set of rights which shall be granted to a group of users.

The goal of this paper is to show that a new paradigm, called the task paradigm, must be supported. Here, a group corresponds to a task which shall be dealt with by a group of users. The main reasons for supporting the task paradigm are access rights required to perform operations with complex objects and requirements of autonomous subgroups.

This is a preview of subscription content, log in via an institution.

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. “Common Ada Programming Support Environment (APSE) Interface Set (CAIS), Revision A”, DoD-STD-1838A, May 1988.

    Google Scholar 

  2. Dittrich, K.R., “Ein universelles Konzept zum flexiblen Informationsschutz in und mit Rechensystemen”, Informatik-Fachberichte 75, Springer-Verlag, 1983.

    Google Scholar 

  3. Downs, D.D., Rub, J.R., Kung, K.C. and Jordan, C.S., “Issues in discretionary access control”, in Proc. 1985 Symp. on Security and Privacy, Oakland, April 22–24, 1985, 1985, pp. 208–218.

    Google Scholar 

  4. “Department of Defense trusted computer system evaluation criteria”, DOD document CSC-STD-001-83, August 1983.

    Google Scholar 

  5. Ellis, C.A. and Gibbs, S.J., “Concurrency control in groupware systems”, in Proc. SIGMOD 89, 1989, pp. 399–407.

    Google Scholar 

  6. “German PCTE Initiative: Introduction to the specifications of the GPI-OMS-Data-Model”, GPI, 1989.

    Google Scholar 

  7. Greif, I. and Sarin, S., “Data sharing in group work”, ACM TOIS 5:2, April 1987, pp. 187–211.

    Google Scholar 

  8. Kelter, U., “Gruppen-Transaktionen vs. gruppenorientierte Zugriffsrechte”, in Proc. GI Jahrestagung 1989, Springer-Verlag, October 1989 pp. 287–300, (English version available as SWT Memo 37, Dept. of Computer Science, University of Dortmund).

    Google Scholar 

  9. Kelter, U., Petry, E. and Simon, M., “Access rights for complex objects in PCTE/OMS”, SWT Memo 36, Dept. of Computer Science, University of Dortmund, ISSN 0933-7725, June 1989.

    Google Scholar 

  10. “PCTE+ Functional Specification, Issue 3”, IEPG TA-13, October 1988.

    Google Scholar 

  11. “System PVS from its users' point of view, Version PVS/6 (in German)”, Softlab GmbH, 1987.

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Fred Long

Rights and permissions

Reprints and permissions

Copyright information

© 1990 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Kelter, U. (1990). Group paradigms in discretionary access controls for object management systems. In: Long, F. (eds) Software Engineering Environments. Lecture Notes in Computer Science, vol 467. Springer, Berlin, Heidelberg. https://doi.org/10.1007/3-540-53452-0_45

Download citation

  • DOI: https://doi.org/10.1007/3-540-53452-0_45

  • Published:

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-53452-5

  • Online ISBN: 978-3-540-46886-8

  • eBook Packages: Springer Book Archive

Publish with us

Policies and ethics