{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T01:51:56Z","timestamp":1778637116826,"version":"3.51.4"},"reference-count":81,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2008,8,1]],"date-time":"2008-08-01T00:00:00Z","timestamp":1217548800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["F39502-99-1-0512-MOD P0001CCR-TC-0208972CISE-EIA-02-02063"],"award-info":[{"award-number":["F39502-99-1-0512-MOD P0001CCR-TC-0208972CISE-EIA-02-02063"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000083","name":"Directorate for Computer and Information Science and Engineering","doi-asserted-by":"publisher","award":["F39502-99-1-0512-MOD P0001CCR-TC-0208972CISE-EIA-02-02063"],"award-info":[{"award-number":["F39502-99-1-0512-MOD P0001CCR-TC-0208972CISE-EIA-02-02063"]}],"id":[{"id":"10.13039\/100000083","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2008,8]]},"abstract":"<jats:p>The Internet enables global sharing of data across organizational boundaries. Distributed file systems facilitate data sharing in the form of remote file access. However, traditional access control mechanisms used in distributed file systems are intended for machines under common administrative control, and rely on maintaining a centralized database of user identities. They fail to scale to a large user base distributed across multiple organizations. We provide a survey of decentralized access control mechanisms in distributed file systems intended for large scale, in both administrative domains and users. We identify essential properties of such access control mechanisms. We analyze both popular production and experimental distributed file systems in the context of our survey.<\/jats:p>","DOI":"10.1145\/1380584.1380588","type":"journal-article","created":{"date-parts":[[2008,8,12]],"date-time":"2008-08-12T13:10:22Z","timestamp":1218546622000},"page":"1-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["Decentralized access control in distributed file systems"],"prefix":"10.1145","volume":"40","author":[{"given":"Stefan","family":"Miltchev","sequence":"first","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jonathan M.","family":"Smith","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vassilis","family":"Prevelakis","sequence":"additional","affiliation":[{"name":"Drexel University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Angelos","family":"Keromytis","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sotiris","family":"Ioannidis","sequence":"additional","affiliation":[{"name":"Institute of Computer Science (ICS), Foundation for Research and Technology, Hellas (FORTH)"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,8,13]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"The simple public-key GSS-API mechanism (SPKM). RFC (Proposed Standard)","author":"Adams C.","year":"2025","unstructured":"Adams , C. 1996. The simple public-key GSS-API mechanism (SPKM). RFC (Proposed Standard) 2025 , Bell-Northern Research . Adams, C. 1996. The simple public-key GSS-API mechanism (SPKM). RFC (Proposed Standard) 2025, Bell-Northern Research."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224066"},{"key":"e_1_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Baize E. and Pinkas D. 1998. The simple and protected GSS-API negotiation mechanism. RFC (Proposed Standard) 2478 Bull.   Baize E. and Pinkas D. 1998. The simple and protected GSS-API negotiation mechanism. RFC (Proposed Standard) 2478 Bull.","DOI":"10.17487\/rfc2478"},{"key":"e_1_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Balenson D. 1993. Privacy enhancement for Internet electronic mail: Part III: Algorithms modes and identifiers. RFC (Proposed Standard) 1423 IAB IRTF PSRG IETF PEM WG.   Balenson D. 1993. Privacy enhancement for Internet electronic mail: Part III: Algorithms modes and identifiers. RFC (Proposed Standard) 1423 IAB IRTF PSRG IETF PEM WG.","DOI":"10.17487\/rfc1423"},{"key":"e_1_2_1_5_1","volume-title":"Proceedings of the USENIX Security Symposium. 15--30","author":"Belani E.","unstructured":"Belani , E. , Vahdat , A. , Anderson , T. , and Dahlin , M . 1998. The CRISIS wide area security architecture . In Proceedings of the USENIX Security Symposium. 15--30 . Belani, E., Vahdat, A., Anderson, T., and Dahlin, M. 1998. The CRISIS wide area security architecture. In Proceedings of the USENIX Security Symposium. 15--30."},{"key":"e_1_2_1_6_1","volume-title":"Secure Internet Programming. Lecture Notes in Computer Science","volume":"1603","author":"Blaze M.","unstructured":"Blaze , M. , Feigenbaum , J. , Ioannidis , J. , and Keromytis , A . 1999a. The role of trust management in distributed systems security . In Secure Internet Programming. Lecture Notes in Computer Science , vol. 1603 . Springer-Verlag Inc., Berlin, Germany, 185--210. Blaze, M., Feigenbaum, J., Ioannidis, J., and Keromytis, A. 1999a. The role of trust management in distributed systems security. In Secure Internet Programming. Lecture Notes in Computer Science, vol. 1603. Springer-Verlag Inc., Berlin, Germany, 185--210."},{"key":"e_1_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Blaze M. Feigenbaum J. Ioannidis J. and Keromytis A. D. 1999b. The KeyNote trust management system version 2. RFC (Proposed Standard) 2074 AT&T Labs - Research.   Blaze M. Feigenbaum J. Ioannidis J. and Keromytis A. D. 1999b. The KeyNote trust management system version 2. RFC (Proposed Standard) 2074 AT&T Labs - Research.","DOI":"10.17487\/rfc2704"},{"key":"e_1_2_1_8_1","volume-title":"Proceedings of the 17th IEEE Symposium on Security and Privacy","author":"Blaze M.","unstructured":"Blaze , M. , Feigenbaum , J. , and Lacy , J . 1996. Decentralized trust management . In Proceedings of the 17th IEEE Symposium on Security and Privacy . Oakland, CA, 164--173. Blaze, M., Feigenbaum, J., and Lacy, J. 1996. Decentralized trust management. In Proceedings of the 17th IEEE Symposium on Security and Privacy. Oakland, CA, 164--173."},{"key":"e_1_2_1_9_1","volume-title":"Proceedings of the 5th International Conference on Financial Cryptography.","author":"Blaze M.","unstructured":"Blaze , M. , Ioannidis , J. , and Keromytis , A. D . 2001. Offline micropayments without trusted hardware . In Proceedings of the 5th International Conference on Financial Cryptography. Blaze, M., Ioannidis, J., and Keromytis, A. D. 2001. Offline micropayments without trusted hardware. In Proceedings of the 5th International Conference on Financial Cryptography."},{"key":"e_1_2_1_10_1","volume-title":"WebNFS client specification. RFC (Proposed Standard)","author":"Callaghan B.","year":"2054","unstructured":"Callaghan , B. 1996a. WebNFS client specification. RFC (Proposed Standard) 2054 , Sun Microsystems, Inc. Callaghan, B. 1996a. WebNFS client specification. RFC (Proposed Standard) 2054, Sun Microsystems, Inc."},{"key":"e_1_2_1_11_1","volume-title":"WebNFS server specification. RFC (Proposed Standard)","author":"Callaghan B.","year":"2055","unstructured":"Callaghan , B. 1996b. WebNFS server specification. RFC (Proposed Standard) 2055 , Sun Microsystems, Inc. October. Callaghan, B. 1996b. WebNFS server specification. RFC (Proposed Standard) 2055, Sun Microsystems, Inc. October."},{"key":"e_1_2_1_12_1","unstructured":"Callaghan B. 2000. NFS Illustrated. Addison-Wesley.   Callaghan B. 2000. NFS Illustrated. Addison-Wesley."},{"key":"e_1_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Callaghan B. Pawlowski B. and Staubach P. 1995. NFS version 3 protocol specification. RFC (Proposed Standard) 1813 Sun Microsystems Inc.   Callaghan B. Pawlowski B. and Staubach P. 1995. NFS version 3 protocol specification. RFC (Proposed Standard) 1813 Sun Microsystems Inc.","DOI":"10.17487\/rfc1813"},{"key":"e_1_2_1_14_1","volume-title":"The Directory Authentication Framework","unstructured":"CCITT. 1989. X.509 : The Directory Authentication Framework . International Telecommunications Union . CCITT. 1989. X.509: The Directory Authentication Framework. International Telecommunications Union."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/365230.365252"},{"key":"e_1_2_1_16_1","doi-asserted-by":"crossref","unstructured":"Dierks T. and Allen C. 1999. The TLS protocol version 1.0. RFC (Proposed Standard) 2246 Internet Engineering Task Force.   Dierks T. and Allen C. 1999. The TLS protocol version 1.0. RFC (Proposed Standard) 2246 Internet Engineering Task Force.","DOI":"10.17487\/rfc2246"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the USENIX Winter Technical Conference. 183--190","author":"Dyer S. P.","year":"1988","unstructured":"Dyer , S. P. 1988 . The Hesiod name server . In Proceedings of the USENIX Winter Technical Conference. 183--190 . Dyer, S. P. 1988. The Hesiod name server. In Proceedings of the USENIX Winter Technical Conference. 183--190."},{"key":"e_1_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Eisler M. 2000. LIPKEY\u2014A low infrastructure public key mechanism using SPKM. RFC (Proposed Standard) 2847 Zambeel.   Eisler M. 2000. LIPKEY\u2014A low infrastructure public key mechanism using SPKM. RFC (Proposed Standard) 2847 Zambeel.","DOI":"10.17487\/rfc2847"},{"key":"e_1_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Eisler M. Chiu A. and Ling L. 1997. RPCSEC_GSS protocol specification. RFC (Proposed Standard) 2203.   Eisler M. Chiu A. and Ling L. 1997. RPCSEC_GSS protocol specification. RFC (Proposed Standard) 2203.","DOI":"10.17487\/rfc2203"},{"key":"e_1_2_1_20_1","unstructured":"Farmer D. and Venema W. 2004. Forensic Discovery. Addison Wesley Professional Publishing.   Farmer D. and Venema W. 2004. Forensic Discovery. Addison Wesley Professional Publishing."},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/505452.505453"},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the Summer USENIX Conference. 63--71","author":"Guy R. G.","unstructured":"Guy , R. G. , Heidemann , J. S. , Mak , W. , Page , Jr., T. W. , Popek , G. J. , and Rothmeir , D . 1990. Implementation of the Ficus replicated file system . In Proceedings of the Summer USENIX Conference. 63--71 . Guy, R. G., Heidemann, J. S., Mak, W., Page, Jr., T. W., Popek, G. J., and Rothmeir, D. 1990. Implementation of the Ficus replicated file system. In Proceedings of the Summer USENIX Conference. 63--71."},{"key":"e_1_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Harkins D. and Carrel D. 1998. The Internet key exchange (IKE). RFC (Proposed Standard) 2409 Internet Engineering Task Force.   Harkins D. and Carrel D. 1998. The Internet key exchange (IKE). RFC (Proposed Standard) 2409 Internet Engineering Task Force.","DOI":"10.17487\/rfc2409"},{"key":"e_1_2_1_24_1","volume-title":"Implementing CIFS: The Common Internet File System","author":"Hertel C. R.","unstructured":"Hertel , C. R. 2003. Implementing CIFS: The Common Internet File System . Prentice Hall . Hertel, C. R. 2003. Implementing CIFS: The Common Internet File System. Prentice Hall."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/564870.564877"},{"key":"e_1_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Housley R. Polk W. Ford W. and Solo D. 2002. Internet X.509 public key infrastructure: Certificate and certificate revocation list (CRL) profile. RFC (Proposed Standard) 3280.   Housley R. Polk W. Ford W. and Solo D. 2002. Internet X.509 public key infrastructure: Certificate and certificate revocation list (CRL) profile. RFC (Proposed Standard) 3280.","DOI":"10.17487\/rfc3280"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/35037.35059"},{"key":"e_1_2_1_28_1","volume-title":"Proceedings of the USENIX Winter Technical Conference","author":"Howard J. H.","year":"1988","unstructured":"Howard , J. H. 1988 . An overview of the Andrew file system . In Proceedings of the USENIX Winter Technical Conference . Dallas, TX, 213--216. Howard, J. H. 1988. An overview of the Andrew file system. In Proceedings of the USENIX Winter Technical Conference. Dallas, TX, 213--216."},{"key":"e_1_2_1_29_1","volume-title":"No.6322916","author":"IBM Corp. 1984.","unstructured":"IBM Corp. 1984. IBM PC Network Technical Reference Manual , No.6322916 , 1 st Ed. IBM Corp. 1984. IBM PC Network Technical Reference Manual, No.6322916, 1st Ed.","edition":"1"},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the 6th International Conference on Financial Cryptography.","author":"Ioannidis J.","unstructured":"Ioannidis , J. , Ioannidis , S. , Keromytis , A. , and Prevelakis , V . 2002. Fileteller: Paying and getting paid for file storage . In Proceedings of the 6th International Conference on Financial Cryptography. Ioannidis, J., Ioannidis, S., Keromytis, A., and Prevelakis, V. 2002. Fileteller: Paying and getting paid for file storage. In Proceedings of the 6th International Conference on Financial Cryptography."},{"key":"e_1_2_1_31_1","volume-title":"Proceedings of the World Conference On Tools and Techniques for System Administration, Networking, and Security.","author":"Sch\u00f6nw\u00e4lder J.","unstructured":"Sch\u00f6nw\u00e4lder , J. and Langend\u00f6rfer , H . 1993. Administration of large distributed UNIX LANs with BONES . In Proceedings of the World Conference On Tools and Techniques for System Administration, Networking, and Security. Sch\u00f6nw\u00e4lder, J. and Langend\u00f6rfer, H. 1993. Administration of large distributed UNIX LANs with BONES. In Proceedings of the World Conference On Tools and Techniques for System Administration, Networking, and Security."},{"key":"e_1_2_1_32_1","doi-asserted-by":"crossref","unstructured":"Kaliski B. 1993. Privacy enhancement for Internet electronic mail: Part IV: Key certification and related services. RFC (Proposed Standard) 1424 RSA Laboratories.   Kaliski B. 1993. Privacy enhancement for Internet electronic mail: Part IV: Key certification and related services. RFC (Proposed Standard) 1424 RSA Laboratories.","DOI":"10.17487\/rfc1424"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/945445.945452"},{"key":"e_1_2_1_34_1","doi-asserted-by":"crossref","unstructured":"Kent S. 1993. Privacy enhancement for Internet electronic mail: Part II: Certificate-based key management. RFC (Proposed Standard) 1422 IAB IRTF PSRG IETF PEM WG.   Kent S. 1993. Privacy enhancement for Internet electronic mail: Part II: Certificate-based key management. RFC (Proposed Standard) 1422 IAB IRTF PSRG IETF PEM WG.","DOI":"10.17487\/rfc1422"},{"key":"e_1_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Kent S. and Atkinson R. 1998. Security architecture for the Internet protocol. RFC (Proposed Standard) 2401 Internet Engineering Task Force.   Kent S. and Atkinson R. 1998. Security architecture for the Internet protocol. RFC (Proposed Standard) 2401 Internet Engineering Task Force.","DOI":"10.17487\/rfc2401"},{"key":"e_1_2_1_36_1","unstructured":"Keromytis A. D. 2001. STRONGMAN: A scalable solution to trust management in networks. Ph.D. thesis University of Pennsylvania.   Keromytis A. D. 2001. STRONGMAN: A scalable solution to trust management in networks. Ph.D. thesis University of Pennsylvania."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1239971.1239972"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/121132.121166"},{"key":"e_1_2_1_39_1","doi-asserted-by":"crossref","unstructured":"Kohl J. and Neuman C. 1993. The Kerberos network authentication service (V5). RFC (Proposed Standard) 1510.   Kohl J. and Neuman C. 1993. The Kerberos network authentication service (V5). RFC (Proposed Standard) 1510.","DOI":"10.17487\/rfc1510"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/378993.379239"},{"key":"e_1_2_1_41_1","volume-title":"Protection. In Proceedings of the 5th Princeton Conference on Information Science and Systems. 437--443","author":"Lampson B.","year":"1971","unstructured":"Lampson , B. 1971 . Protection. In Proceedings of the 5th Princeton Conference on Information Science and Systems. 437--443 . Lampson, B. 1971. Protection. In Proceedings of the 5th Princeton Conference on Information Science and Systems. 437--443."},{"key":"e_1_2_1_42_1","volume-title":"CIFS: A common Internet file system. Microsoft Internet Developer.","author":"Leach P.","year":"1996","unstructured":"Leach , P. and Perry , D . 1996 . CIFS: A common Internet file system. Microsoft Internet Developer. Leach, P. and Perry, D. 1996. CIFS: A common Internet file system. Microsoft Internet Developer."},{"key":"e_1_2_1_43_1","volume-title":"Proceedings of the IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETIC), Workshop on Distributed and Mobile Collaboration","author":"Levine A.","unstructured":"Levine , A. , Prevelakis , V. , Ioannidis , J. , Ioannidis , S. , and Keromytis , A. D . 2003. Webdava: An administrator-free approach to web file-sharing . In Proceedings of the IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETIC), Workshop on Distributed and Mobile Collaboration . Linz, Austria, 59--64. Levine, A., Prevelakis, V., Ioannidis, J., Ioannidis, S., and Keromytis, A. D. 2003. Webdava: An administrator-free approach to web file-sharing. In Proceedings of the IEEE International Workshops on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETIC), Workshop on Distributed and Mobile Collaboration. Linz, Austria, 59--64."},{"key":"e_1_2_1_44_1","volume-title":"Capability-Based Computer Systems. Butterworth-Heinemann","author":"Levy H. M.","unstructured":"Levy , H. M. 1984. Capability-Based Computer Systems. Butterworth-Heinemann , Newton, MA . Levy, H. M. 1984. Capability-Based Computer Systems. Butterworth-Heinemann, Newton, MA."},{"key":"e_1_2_1_45_1","doi-asserted-by":"crossref","unstructured":"Linn J. 1993a. Generic security service application program interface. RFC (Proposed Standard) 1508 Geer Zolot Associates.   Linn J. 1993a. Generic security service application program interface. RFC (Proposed Standard) 1508 Geer Zolot Associates.","DOI":"10.17487\/rfc1508"},{"key":"e_1_2_1_46_1","doi-asserted-by":"crossref","unstructured":"Linn J. 1993b. Privacy enhancement for Internet electronic mail: Part I: Message encryption and authentication procedures. RFC (Proposed Standard) 1421 IAB IRTF PSRG IETF PEM WG.  Linn J. 1993b. Privacy enhancement for Internet electronic mail: Part I: Message encryption and authentication procedures. RFC (Proposed Standard) 1421 IAB IRTF PSRG IETF PEM WG.","DOI":"10.17487\/rfc1421"},{"key":"e_1_2_1_47_1","volume-title":"The Kerberos version 5 GSS-API mechanism. RFC (Proposed Standard)","author":"Linn J.","year":"1964","unstructured":"Linn , J. 1996. The Kerberos version 5 GSS-API mechanism. RFC (Proposed Standard) 1964 , OpenVision Technologies . Linn, J. 1996. The Kerberos version 5 GSS-API mechanism. RFC (Proposed Standard) 1964, OpenVision Technologies."},{"key":"e_1_2_1_48_1","volume-title":"Generic security service application program interface, version 2. RFC (Proposed Standard)","author":"Linn J.","year":"2078","unstructured":"Linn , J. 1997. Generic security service application program interface, version 2. RFC (Proposed Standard) 2078 , Internet Engineering Task Force . Linn, J. 1997. Generic security service application program interface, version 2. RFC (Proposed Standard) 2078, Internet Engineering Task Force."},{"key":"e_1_2_1_49_1","volume-title":"Sun Microsystems","author":"Lyon B.","unstructured":"Lyon , B. 1984. Sun remote procedure call specification. Tech. rep ., Sun Microsystems , Inc . Lyon, B. 1984. Sun remote procedure call specification. Tech. rep., Sun Microsystems, Inc."},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/319151.319160"},{"key":"e_1_2_1_52_1","unstructured":"Microsoft Corporation. 1996. Microsoft networks SMB file sharing protocol (document version 6.0p).  Microsoft Corporation. 1996. Microsoft networks SMB file sharing protocol (document version 6.0p)."},{"key":"e_1_2_1_53_1","unstructured":"Microsoft Corporation. 2005. Microsoft access control model. http:\/\/msdn.microsoft.com\/library\/default.asp?url=\/library\/en-us\/secauthz\/security\/access_control_model.asp.  Microsoft Corporation. 2005. Microsoft access control model. http:\/\/msdn.microsoft.com\/library\/default.asp?url=\/library\/en-us\/secauthz\/security\/access_control_model.asp."},{"key":"e_1_2_1_54_1","unstructured":"Miller S. P. Neuman B. C. Schiller J. I. and Saltzer J. H. 1987. Kerberos authentication and authorization system. Tech. rep. MIT Cambridge MA.  Miller S. P. Neuman B. C. Schiller J. I. and Saltzer J. H. 1987. Kerberos authentication and authorization system. Tech. rep. MIT Cambridge MA."},{"key":"e_1_2_1_55_1","volume-title":"Proceedings of the Annual USENIX Technical Conference, Freenix Track. 165--178","author":"Miltchev S.","unstructured":"Miltchev , S. , Prevelakis , V. , Ioannidis , S. , Ioannidis , J. , Keromytis , A. , and Smith , J . 2003. Secure and flexible global file sharing . In Proceedings of the Annual USENIX Technical Conference, Freenix Track. 165--178 . Miltchev, S., Prevelakis, V., Ioannidis, S., Ioannidis, J., Keromytis, A., and Smith, J. 2003. Secure and flexible global file sharing. In Proceedings of the Annual USENIX Technical Conference, Freenix Track. 165--178."},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/359657.359659"},{"key":"e_1_2_1_57_1","volume-title":"Proceedings of 2nd International System Administration and Networking Conference (SANE).","author":"Pawlowski B.","unstructured":"Pawlowski , B. , Shepler , S. , Beame , C. , Callaghan , B. , Eisler , M. , Noveck , D. , Robinson , D. , and Thurlow , R . 2000. The NFS version 4 protocol . In Proceedings of 2nd International System Administration and Networking Conference (SANE). Pawlowski, B., Shepler, S., Beame, C., Callaghan, B., Eisler, M., Noveck, D., Robinson, D., and Thurlow, R. 2000. The NFS version 4 protocol. In Proceedings of 2nd International System Administration and Networking Conference (SANE)."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/504450.504497"},{"key":"e_1_2_1_59_1","doi-asserted-by":"crossref","unstructured":"Polk W. Housley R. and Bassham L. 2002. Algorithms and identifiers for the Internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile. RFC (Proposed Standard) 3279.  Polk W. Housley R. and Bassham L. 2002. Algorithms and identifiers for the Internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile. RFC (Proposed Standard) 3279.","DOI":"10.17487\/rfc3280"},{"key":"e_1_2_1_60_1","volume-title":"Proceedings of the USENIX Security Symposium. 211--233","author":"Regan J.","unstructured":"Regan , J. and Jensen , C . 2001. Capability file names: Separating authorization from user management in an Internet file system . In Proceedings of the USENIX Security Symposium. 211--233 . Regan, J. and Jensen, C. 2001. Capability file names: Separating authorization from user management in an Internet file system. In Proceedings of the USENIX Security Symposium. 211--233."},{"key":"e_1_2_1_61_1","volume-title":"Proceedings of the Privacy and Security Research Group Workshop on Network and Distributed System Security.","author":"Reiher P.","unstructured":"Reiher , P. , Page , T. , Crocker , S. , Cook , J. , and Popek , G . 1993. Truffles\u2014a secure service for widespread file sharing . In Proceedings of the Privacy and Security Research Group Workshop on Network and Distributed System Security. Reiher, P., Page, T., Crocker, S., Cook, J., and Popek, G. 1993. Truffles\u2014a secure service for widespread file sharing. In Proceedings of the Privacy and Security Research Group Workshop on Network and Distributed System Security."},{"key":"e_1_2_1_62_1","volume-title":"Proceedings of the USENIX Conference on File and Storage Technologies (FAST). USENIX.","author":"Rhea S.","unstructured":"Rhea , S. , Eaton , P. , Geels , D. , Weatherspoon , H. , Zhao , B. , and Kubiatowicz , J . 2003. Pond: The OceanStore prototype . In Proceedings of the USENIX Conference on File and Storage Technologies (FAST). USENIX. Rhea, S., Eaton, P., Geels, D., Weatherspoon, H., Zhao, B., and Kubiatowicz, J. 2003. Pond: The OceanStore prototype. In Proceedings of the USENIX Conference on File and Storage Technologies (FAST). USENIX."},{"key":"e_1_2_1_63_1","volume-title":"Proceedings of the Winter USENIX Conference. 203--212","author":"Rosenstein M. A., Jr., D. E. G.","unstructured":"Rosenstein , M. A., Jr., D. E. G. , and Levine , P. J . 1988. The Athena service management system . In Proceedings of the Winter USENIX Conference. 203--212 . Rosenstein, M. A., Jr., D. E. G., and Levine, P. J. 1988. The Athena service management system. In Proceedings of the Winter USENIX Conference. 203--212."},{"key":"e_1_2_1_64_1","unstructured":"Samba project. Samba. http:\/\/www.samba.org.  Samba project. Samba. http:\/\/www.samba.org."},{"key":"e_1_2_1_65_1","volume-title":"Proceedings of the Summer USENIX Conference.","author":"Sandberg R.","unstructured":"Sandberg , R. , Goldberg , D. , Kleiman , S. , Walsh , D. , and Lyon , B . 1985. Design and implementation of the Sun network file system . In Proceedings of the Summer USENIX Conference. Sandberg, R., Goldberg, D., Kleiman, S., Walsh, D., and Lyon, B. 1985. Design and implementation of the Sun network file system. In Proceedings of the Summer USENIX Conference."},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/65000.65002"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.53351"},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.120311"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/507052.507053"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/12.54838"},{"key":"e_1_2_1_71_1","doi-asserted-by":"crossref","unstructured":"Shepler S. Callaghan B. Robinson D. Thurlow R. Beame C. Eisler M. and Noveck D. 2003. Network file system (NFS) version 4 protocol. RFC (Proposed Standard) 3050.  Shepler S. Callaghan B. Robinson D. Thurlow R. Beame C. Eisler M. and Noveck D. 2003. Network file system (NFS) version 4 protocol. RFC (Proposed Standard) 3050.","DOI":"10.17487\/rfc3530"},{"key":"e_1_2_1_72_1","volume-title":"Common Internet file system (CIFS) technical reference. SNIA technical proposal","author":"SNIA CIFS Technical Work Group","unstructured":"SNIA CIFS Technical Work Group . 2002. Common Internet file system (CIFS) technical reference. SNIA technical proposal , Storage Networking Industry Association . SNIA CIFS Technical Work Group. 2002. Common Internet file system (CIFS) technical reference. SNIA technical proposal, Storage Networking Industry Association."},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC1831"},{"key":"e_1_2_1_74_1","doi-asserted-by":"crossref","unstructured":"Swift M. Trostle J. and Brezak J. 2002. Microsoft Windows 2000 Kerberos change password and set password protocols. RFC (Proposed Standard) 3244 University of Washington Cisco Systems and Microsoft.   Swift M. Trostle J. and Brezak J. 2002. Microsoft Windows 2000 Kerberos change password and set password protocols. RFC (Proposed Standard) 3244 University of Washington Cisco Systems and Microsoft.","DOI":"10.17487\/rfc3244"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/581271.581273"},{"key":"e_1_2_1_76_1","volume-title":"Proceedings of the 6th International Conference on Distributed Computing Systems. 558--563","author":"Tanenbaum A.","year":"1986","unstructured":"Tanenbaum , A. , Mullender , S. , and van Renesse , R. 1986 . Using sparse capabilities in a distributed operating system . In Proceedings of the 6th International Conference on Distributed Computing Systems. 558--563 . Tanenbaum, A., Mullender, S., and van Renesse, R. 1986. Using sparse capabilities in a distributed operating system. In Proceedings of the 6th International Conference on Distributed Computing Systems. 558--563."},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/224056.224070"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1978.tb02137.x"},{"key":"e_1_2_1_79_1","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS).","author":"Trostle J. T.","unstructured":"Trostle , J. T. , Kosinovsky , I. , and Swift , M. M . 2001. Implementation of crossrealm referral handling in the MIT Kerberos client . In Proceedings of the Network and Distributed System Security Symposium (NDSS). Trostle, J. T., Kosinovsky, I., and Swift, M. M. 2001. Implementation of crossrealm referral handling in the MIT Kerberos client. In Proceedings of the Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_2_1_81_1","volume-title":"Proceedings of the USENIX Annual Technical Conference, Freenix Track. 267--272","author":"Westerlund A.","unstructured":"Westerlund , A. and Danielsson , J . 2001. Heimdal and Windows 2000 Kerberos: How to get them to play together . In Proceedings of the USENIX Annual Technical Conference, Freenix Track. 267--272 . Westerlund, A. and Danielsson, J. 2001. Heimdal and Windows 2000 Kerberos: How to get them to play together. In Proceedings of the USENIX Annual Technical Conference, Freenix Track. 267--272."},{"key":"e_1_2_1_82_1","volume-title":"Generic security service API: C-bindings. RFC (Proposed Standard) 1509","author":"Wray J.","unstructured":"Wray , J. 1993. Generic security service API: C-bindings. RFC (Proposed Standard) 1509 , Digital Equipment Corporation . Wray, J. 1993. Generic security service API: C-bindings. RFC (Proposed Standard) 1509, Digital Equipment Corporation."},{"key":"e_1_2_1_83_1","volume-title":"Tapestry: An infrastructure for fault-tolerant wide-area location and routing. Tech. rep. UCB\/CSD-01-1141","author":"Zhao B. Y.","year":"2001","unstructured":"Zhao , B. Y. , Kubiatowicz , J. D. , and Joseph , A. D . 2001 . Tapestry: An infrastructure for fault-tolerant wide-area location and routing. Tech. rep. UCB\/CSD-01-1141 , University of California , Berkeley. Zhao, B. Y., Kubiatowicz, J. D., and Joseph, A. D. 2001. Tapestry: An infrastructure for fault-tolerant wide-area location and routing. Tech. rep. UCB\/CSD-01-1141, University of California, Berkeley."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1380584.1380588","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1380584.1380588","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:57:46Z","timestamp":1750255066000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1380584.1380588"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,8]]},"references-count":81,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2008,8]]}},"alternative-id":["10.1145\/1380584.1380588"],"URL":"https:\/\/doi.org\/10.1145\/1380584.1380588","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2008,8]]},"assertion":[{"value":"2006-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2007-11-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2008-08-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}