arXiv · 1210.5443
Secure Abstraction with Code Capabilities
Abstract
We propose embedding executable code fragments in cryptographically protected capabilities to enable flexible discretionary access control in cloud-like computing infrastructures. We are developing this as part of a sports analytics application that runs on a federation of public and enterprise clouds. The capability mechanism is implemented completely in user space. Using a novel combination of X.509 certificates and Javscript code, the capabilities support restricted delegation, confinement, revocation, and rights amplification for secure abstraction.
Explore related subjects
Keep this discovery
Robbert van Renesse, Håvard Johansen, Nihar Naigaonkar, Dag Johansen. 2012-10-19. Secure Abstraction with Code Capabilities. https://arxiv.org/abs/1210.5443
Cite the original work for its findings. Save a collection to share your selection of sources.