Abstract
Specifying and managing access rights in large distributed systems is a non-trivial task. This paper presents a language-based approach to policy-based management of access rights. We develop an object-oriented access model and a concrete syntax that is designed to allow both flexible and manageable access control policies for CORBA objects. We introduce a typed construct for access rights called view that allows static type checking of specifications and show how a realistic example policy is expressed using this notation.
Get full access to this article
View all access options for this article.
