next up previous
Next: GAA API Up: Policy Language Previous: Extended Access Control Lists

Capabilities

We present here an implementation of a capability, stating that the capability granted by the group "admin" grants read access if the capability is presented during the specified time period.

Token Type: grantor_identity_GROUP    
Defining Authority: kerberos.V5    
Value: admin@USC.EDU    


Token Type: positive_access_rights    
Defining Authority: local_manager    
Value: FILE:read    


Token Type: time_window    
Defining Authority: eastern_timezone    
Value: 8:00AM-5:00PM    



Tatyana Ryutov 2002-06-25