Hybrid Capability Model

A hybrid-capability system in one in which access is allowed only if it satisfies both ObjectCapabilityModel rules and AccessControlList rules.

The IBM System/38, now known as the AS/400, has two kinds of capabilities: normal object-capabilities and so-called "unauthorized capabilities". For the latter, access also carries a principle-ID, and is allowed only if the AccessControlList mechanism says it's ok.

Hybrid-capability systems include


CategorySecurity CategorySecurityModel CapabilitySecurityModel


EditText of this page (last edited June 12, 2009) or FindPage with title or text search