publication . Conference object . Article . 2002

The PERMIS X.509 role based privilege management infrastructure

David Chadwick; Otenko, A.;
Open Access
  • Published: 01 Jun 2002
  • Publisher: ACM Press
  • Country: United Kingdom
This paper describes the output of the PERMIS project, which has developed a role based access control infrastructure that uses X.509 attribute certificates (ACs) to store the users' roles. All access control decisions are driven by an authorization policy, which is itself stored in an X.509 attribute certificate, thus guaranteeing its integrity. All the ACs can be stored in one or more LDAP directories, thus making them widely available. Authorization policies are written in XML according to a DTD that has been published at The Access Control Decision Function (ADF) is written in Java and the Java API is simple to use, comprising of just 3 methods and ...
free text keywords: QA76
