【24h】

Designing a distributed authorization service

机译:设计分布式授权服务

获取原文

摘要

We present the design of a distributed authorization service which parallels existing authentication services for distributed systems. Such a service would operate on top of an authentication substrate. There are two distinct ideas underlying our design: (1) the use of a language, called generalized access control list (GACL), as a common representation of authorization requirements; and (2) the use of authenticated delegation to effect authorization offloading from an end server to an authorization server. We present the syntax and semantics of GACL, and illustrate how it can be used to specify authorization requirements that cannot be easily specified by ordinary ACL. We also describe the protocols in our design.
机译:我们提出了一种分布式授权服务的设计,该服务与分布式系统的现有身份验证服务并行。这样的服务将在认证衬底的顶部上运行。我们的设计有两个截然不同的想法:(1)使用一种称为通用访问控制列表(GACL)的语言作为授权要求的通用表示; (2)使用经过身份验证的委托来实现从终端服务器到授权服务器的授权卸载。我们介绍了GACL的语法和语义,并说明了如何使用它来指定普通ACL不能轻松指定的授权要求。我们还在设计中描述了协议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号