Seminar, 20th February 2001


Speaker:
Morris Sloman and Emil Lupu, Imperial College, London

Date:
Tuesday 20th February 2001 at 16:15

Place:
Room TP4, Computer Laboratory

Title:
PONDER: A LANGUAGE FOR SPECIFYING SECURITY AND MANAGEMENT POLICIES FOR DISTRIBUTED SYSTEMS


This seminar describes Ponder - a new declarative, object-oriented language for specifying policies for security and management of distributed systems. The language includes constructs for authorisation policies defining permitted actions; event triggered obligation policies specifying actions to be performed by manager agents; refrain policies specifying actions that subjects must refrain from performing; delegation policies defining what authorisations can be delegated and to whom. Filtered actions extend authorisations to define transformation of input or output parameters. Constraints specify limitations on the applicability of policies based on time or object state. Roles group the policies relating to a position in an organisation. A management structure defines a configuration of role instances as well as the relationship between roles. These concepts can be used to model roles, rights and duties relating to organisational patterns which occur in many large enterprises.


Seminar, 20th February 2001 / Ross.Anderson@cl.cam.ac.uk
Last updated: 14th February 2001