Access control (AC) technology has come a long way from its roots as the means for sharing resources between processes running on a single machine, to a mechanism for regulating the interaction among agents (software components, and people) distributed throughout the internet. But despite the distributed nature of the systems being regulated, the conventional enforcement mechanism for AC policies remains basically centralized, where a single (although possibly replicated) reference monitor (RM) is used to mediate the interaction between members of a given community of agents, according to a given policy. This papers demonstrates one of the main drawbacks of centralized AC mechanisms, when applied to distributed systems, and to shows the absence of this drawback under the inherently decentralized law-governed interaction (LGI) mechanism.
Naftaly H. Minsky