Teaching System Access Control
John Bauer Mengelberg
Abstract
John Bauer Mengelberg
Abstract
Many specialists believe that more emphasis on system infrastructure is needed, including the protection of the system’s data against unauthorized use or updates. This paper proposes a way to teach future information system specialists the main concepts involved, using a powerful yet very flexible method to implement access control. Constraints, widely known as context constraints, which depend on the value of a variable or data item, are included. We discovered it was extremely difficult for students to understand, let alone adopt, a model as general as the one we use to explain the necessary ingredients of an Access Control model. However, the order in which the concepts were introduced produced a very significant increase in the degree of understanding on the part of the students. Rather than just provide another method, the paper’s objective is to promote discussion as well as further study of the subject.
OpenAlex reports 2 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Many specialists believe that more emphasis on system infrastructure is needed, including the protection of the system’s data against unauthorized use or updates. This paper proposes a way to teach future information system specialists the main concepts involved, using a powerful yet very flexible method to implement access control. Constraints, widely known as context constraints, which depend on the value of a variable or data item, are included. We discovered it was extremely difficult for students to understand, let alone adopt, a model as general as the one we use to explain the necessary ingredients of an Access Control model. However, the order in which the concepts were introduced produced a very significant increase in the degree of understanding on the part of the students. Rather than just provide another method, the paper’s objective is to promote discussion as well as further study of the subject.
Key concepts: Computer science, Access control, Context (archaeology), Control (management), Order (exchange), Variable (mathematics), Data science, Computer security