Re: some capability queries
"Karp, Alan H" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <8AD823089998C849A832D86972E69CD5419C67AD@G4W3222.americas.hpqcorp.net> |
An excellent set of questions. Let me answer just one of them here. Jithu Joseph wrote: > > 5. Can we express anything (policies) more / differently using > capability systems than with other systems/ access control models ? > Consider the problem of service chaining. Alice invokes Bob's service. In order to satisfy her request, Bob’s service invokes Carol's service. If we are using identity, role or attribute based access control, what I call autheNtication-Based Access control (NBAC), then Alice presents proof of her identity, role, or attributes with her request. Bob's service verifies that Alice is authorized to make the request and proceeds to invoke Carol's service. Whose authentication does Bob present with that request? If he presents his own, Alice could be asking for something Bob's service is allowed to do but Alice is not. Bob’s service has become a confused deputy. If Bob's service uses Alice's credentials when invoking Carol's service, then Bob's service can do anything Alice has permission to do whether Alice wants it done or not, a gross violation of the Principle of Least Privilege. Things work better with capabilities. Alice invokes Bob's service with her capability, passing as arguments delegations of those of her capabilities Bob's service will need when invoking Carol's service. Bob's service can now invoke Carol's service with the capabilities received from Alice. No confused deputy. No violation of least privilege. This example is covered in more detail in Solving the Transitive Access Problem for the Services Oriented Architecture<http://www.hpl.hp.com/techreports/2008/HPL-2008-204R1.html>, Fifth International Conference on Availability, Reliability, and Security (ARES 2010), February 15-18, Krakow, Poland (Best Paper) That paper points out the key difference between NBAC and capabilities, which I've been calling authoriZation-Based Access Control (ZBAC), namely how the access matrix gets updated. NBAC requires rules outside the system to control updates, basically needing an ACL to control updates to the ACL. The inherent delegatability of capabilities handles these updates within the capability system. A comparison of NBAC versus ZBAC is in From ABAC to ZBAC: The Evolution of Access Control Models<http://www.hpl.hp.com/techreports/2009/HPL-2009-30.html>, Journal of Information Warfare, vol. 9, #2, pp. 37-45,September 2010 The Zebra Copy paper mentioned by Rob is at Access Control for the Services Oriented Architecture<http://dl.acm.org/authorize?932537>, with J. Li, ACM Workshop on Secure Web Services, ACM #459074, pp. 9-17, Fairfax, VA, November 2007 Note that this last paper uses the acronym ABAC for what we now call ZBAC. ________________________ Alan Karp Principal Scientist Enterprise Services, Office of the CTO Hewlett-Packard Company 1501 Page Mill Road Palo Alto, CA 94304 (650) 857-3967, fax (650) 857-7029 http://www.hpl.hp.com/personal/Alan_Karp _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk