next up previous
Next: Extended Access Control Lists Up: Policy Language Previous: Specification of Access Rights

Specification of Conditions

Conditions specify the type-specific policies under which an operation can be performed on an object. A condition is interpreted according to its type. Conditions can be categorized as generic or specific. Generic conditions are evaluated by the access control model; specific conditions are application-dependent and usually are evaluated by the application. These are several of the more useful generic conditions [1].

If generic conditions are not sufficient for expressing application-specific security policies, applications specify their own conditions. Anything that can be expressed as alphanumeric string can be a condition. The application must provide evaluation rules for the application-specific conditions.


next up previous
Next: Extended Access Control Lists Up: Policy Language Previous: Specification of Access Rights
Tatyana Ryutov 2002-06-25