next up previous
Next: Specification of Restrictions Up: Policy Language Previous: Specification of Grantor Identity

Specification of Access Rights

All operations defined on the object are grouped by type of access to the object they represent, and named using a tag. It must be possible to specify which principals or groups of principals are authorized for specific operations, as well as which principals are explicitly denied authorizations, therefore we define positive and negative access rights.



Tatyana Ryutov 2002-06-25