The Private Access Channel: A Security Mechanism for Shared Distribution Objects

We present a security mechanism designed for use with object-based multi-user applications. This mechanism the private access channel provides the same level of fine grain object-based security as the capability scheme. Whereas capabilities have been applied only to limited sets of objects with identical operations, we propose a generic protection mechanism that can be applied to any object, whatever its operations. Our mechanism is provided at the object level which makes it available for direct use by multi-user applications. It has the additional advantage that clients need not be aware of the presence of access control. We discuss the use of the private access channel in the context of two distributed multi-user applications.