It has become common practise to construct software systems as a collection of heterogeneous distributed components. Information within these components tends to be of a sensitive nature, and therefore requires some form of access control. Although there are existing architectures available to provide this control, they tend to be an add on feature that is complicated and inflexible. The aim of this paper is to investigate the access constraints of a real-world example where information is of a highly sensitive nature, and to design a system whose security is based on the use of bracket capabilities. |
|