@inproceedings{Bishop:1979aa, author = {Bishop, Matt and Snyder, Lawrence}, title = {The Transfer of Information and Authority in a Protection System}, booktitle = {Proceedings of the Seventh ACM Symposium on Operating Systems Principles}, series = {SOSP '79}, year = {1979}, isbn = {0-89791-009-5}, location = {Pacific Grove, CA, USA}, pages = {45--54}, numpages = {10}, url = {http://doi.acm.org/10.1145/800215.806569}, doi = {10.1145/800215.806569}, publisher = {ACM}, address = {New York, NY, USA}, abstract = {In the context of a capability-based protection system, the term ``transfer'' is used (here) to refer to the situation where a user receives information when he does not initially have a direct ``right'' to it. Two transfer methods are identified: \emph{de jure} transfer refers to the case when the user acquires the direct authority to read the information; \emph{de facto} transfer refers to the case when the user acquires the information (usually in the form of a copy and with the assistance of others), without necessarily being able to get the direct authority to read the information. The Take-Grant Protection Model, which already models \emph{de jure} transfers, is extended with four rewriting rules to model \emph{de facto} transfer. The configurations under which \emph{de facto} transfer can arise are characterized. Considerable motivational discussion is included.}, }