Revogação com Downgrade

Fábio NegrelloJacques Wainer

This paper presents a flexible authorization model that allows the precise control of delegation chains. This can be obtained both by defining the maximum lenght of delegation chains, and by associating constraints for the acceptance of delegations. In this model, we propose an efficient revocation with downgrade algorithm, that keeps the subjects with the biggest set of rights, considering the remaining alternative chains, after the revocation of delegations. Also, it is discussed an algorithm for determining the acceptance of new delegations, which verifies if there is at least one valid support chain for each new delegation.

