next up previous
Next: EACL evaluation Up: Policy Language Previous: Extended Access Control Lists

Capabilities

Here we present here an implementation of a capability. The example states that the capability granted by the group admin permits read access if the capability is presented during the specified time period.

Token Type: grantor_id_GROUP    
Defining Authority: kerberos.V5    
Value: admin@USC.EDU    


Token Type: pos_access_rights    
Defining Authority: local_manager    
Value: FILE:read    


Token Type: time_window    
Defining Authority: eastern_timezone    
Value: 8:00AM-5:00PM    



Tatyana Ryutov 2002-06-25