Access control matrix

A table with subjects as rows, objects as columns and the permitted rights in each cell; the abstract model from which access control lists and capability tables are both derived.

Full guide: Graham-Denning: The Eight Protection Rules

The access control matrix is an abstract way to describe every access right in a system at once. Each row is a subject, each column is an object, and each cell lists the rights that subject holds over that object, such as read, write or own. The idea is commonly traced to Butler Lampson’s 1971 paper “Protection”, and later formal work built on it: the Graham-Denning model defines the operations that may change the matrix, and the Harrison, Ruzzo and Ullman model studied whether a given right could ever leak to a subject.

Real systems rarely store the full table, because most cells are empty. They store it in slices instead. Keeping each column with its object produces an access control list; keeping each row with its subject produces a capability table. An ACL answers who can reach an object; a capability table answers what a subject can reach. The matrix itself is policy-neutral. It can record decisions made under discretionary, mandatory or role-based rules.

Exam relevance: questions in this area tend to turn on the geometry. Candidates are expected to know that rows correspond to subjects and capability tables, columns to objects and ACLs, and that the matrix is a model of the rights, not a separate enforcement product.