the access-control matrix can be used to determine whether a process can switch from, say, domain a to domain b and enjoy the access privileges of domain b. is this approach equivalent to including the access privileges of domain b in those of domain a?