In a secure object-based system, only authorized subjects are allowed to manipulate objects in authorized methods. In addition, every information flow to occur among objects is required to be legal, i.e. no confinement problem occur. First, abstract methods are classified with respect to whether or not data is input to and output from objects and state is changed. In this paper, we discuss how to prevent illegal information flow to occur among objects by performing methods in a role-based access control model. In addition, we discuss an algorithm to check if illegal information flow occurs each time a method is issued by a transaction.
Index Terms:
Security, Informaiton flow control, Access control
Citation:
Keiji Izaki, Katsuya Tanaka, Makoto Takizawa, "Timed Information Flow among Objects Based on Role Concept," words, pp.0139, Seventh IEEE International Workshop on Object-Oriented Real-Time Dependable Systems (WORDS'02), 2002