Zusammenfassung der Ressource
U3.2 Access Control
Structures
- Access Control Matrix
- Based on a grid. Subjects on the side, objects accross
- Not practical for large organisations with
100's of subjects and 10000's of objects, to
many empty spaces and wasted memory
- Access Control List
- Concentrate on objects
- ACL for object is stored within the object
- Checked before access is granted
- More widely used than Matrix
- Used by UNIX
- Main disadvantage is checking the list is time
consuming, if access is revoked for a user then
every object has to be checked for that user
- Capability list
- Focus on access rights of Subjects
- Concentrate on the rows of a matrix
- Used in databases
- Disadvantages
- difficult to ascertain the rights to an object
- difficult to revoke permissions if owner
has granted certain rights to subjects
- How does the Reference Monitor ascertain
which subjects have access to which objects?