Loading...
Please wait, while we are loading the content...
Similar Documents
Distributed programming with distributed authorization
| Content Provider | ACM Digital Library |
|---|---|
| Author | Datta, Anupam Harper, Robert Avijit, Kumar |
| Abstract | We propose a programming language, called $PCML_{5},$ for building distributed applications with distributed access control. Target applications include web-based systems in which programs must compute with stipulated resources at different sites. In such a setting, access control policies are decentralized (each site may impose restrictions on access to its resources without the knowledge of or cooperation with other sites) and spatially distributed each site may store its policies locally). To enforce such policies $PCML_{5}$ employs a distributed proof-carrying authorization framework in which sensitive resources are governed by reference monitors that authenticate principals and demand logical proofs of compliance with site-specific access control policies. The language provides primitive operations for authentication, and acquisition of proofs from local policies. The type system of $PCML_{5}$ enforces locality restrictions on resources, ensuring that they can only be accessed from the site at which they reside, and enforces the authentication and authorization obligations required to comply with local access control policies. This ensures that a well-typed $PCML_{5}$ program cannot incur a runtime access control violation at a reference monitor for a controlled resource. |
| Starting Page | 27 |
| Ending Page | 38 |
| Page Count | 12 |
| File Format | |
| ISBN | 9781605588919 |
| DOI | 10.1145/1708016.1708021 |
| Language | English |
| Publisher | Association for Computing Machinery (ACM) |
| Publisher Date | 2010-01-23 |
| Publisher Place | New York |
| Access Restriction | Subscribed |
| Subject Keyword | Distributed programming Logical frameworks Phase distinction Proof-carrying authorization Authorization logic |
| Content Type | Text |
| Resource Type | Article |