J. Meyer et al., ACCESS-CONTROL AND SECURITY FOR A DISTRIBUTED CONTROL-SYSTEM, Nuclear instruments & methods in physics research. Section A, Accelerators, spectrometers, detectors and associated equipment, 352(1-2), 1994, pp. 289-292
The control system of the European Synchrotron Radiation Facility (ESR
F) is object-oriented and distributed. Device access is based on the c
lient-server model. To protect sensitive hardware devices an access co
ntrol and security system has been added. This offers users read, writ
e, super-user or single-user access to hardware objects, families or e
ven whole areas of the facility. A memory-based security database, acc
essed by an internal control system service, combines device names, ac
cess rights, user IDs, group IDs and host/network addresses. Access ri
ghts must be requested al connection time and are guaranteed by a fast
access key mechanism. The paper describes the design and discusses th
e needs for the implemented access rights and protection possibilities
.