Access control policies: Some unanswered questions

Discretionary access control policies are not so simple as most assume, especially in light of the requirements in the Trusted Computer System Evaluation Criteria for group authorizations and specific denial of authorizations at the higher evaluation classes. Many interpretations of these requirements can be made. We investigate the possible interpretations of specific denial of authorization and also how to reconcile conflicting user and group authorizations and denials. We discuss several alternatives for implementing such policies for complex systems, such as database systems.