Skip to main content

TS

Non-delegatable authorities in capability systems

Authors

Toby Murray and Duncan Grove

Defence Science and Technology Organisation

Abstract

We present a novel technique, known as the non-delegatable authority (NDA), for distributing authority to unconfined subjects in capability systems that prevents them from sharing the exact same authority that they have been given with anyone else. This feature is present in common systems based on access control lists (ACLs) in which one may hand out a permission without handing out the associated "grant" right, but has been thought to be impossible to express in capability systems until now. Consequently, we demonstrate that NDAs may be used to express ACL-like constructs and their basic pattern is directly applicable for implementing Multi-Level Security and identity-based access controls in the object-capability model.

The extra complexity introduced by our NDA implementation can be hidden behind constructs that allow NDAs to be wielded as if they were ordinary capabilities to the target resource. These constructs cannot break the non-delegatability constraint and allow NDAs to be used effectively, although with less efficiency than delegatable authorities.

BibTeX Entry

  @article{Murray_Grove_08,
    publisher        = {IOS Press},
    doi              = {10.3233/JCS-2008-0314},
    author           = {Toby Murray and Duncan Grove},
    journal          = {Journal of Computer Security},
    title            = {Non-Delegatable Authorities in Capability Systems},
    number           = {6},
    volume           = {16},
    year             = {2008},
    pages            = {743--759}
  }

Download

Served by Apache on Linux on seL4.
Served by Apache on Linux on seL4.