2008
DOI: 10.1002/cpe.1313
|View full text |Cite
|
Sign up to set email alerts
|

PERMIS: a modular authorization infrastructure

Abstract: Authorization infrastructures manage privileges and render access control decisions, allowing applications to adjust their behavior according to the privileges allocated to users. This paper describes the PERMIS role-based authorization infrastructure along with its conceptual authorization, access control, and trust models. PERMIS has the novel concept of a credential validation service, which verifies a user's credentials prior to access control decision-making and enables the distributed management of crede… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
55
0

Year Published

2009
2009
2016
2016

Publication Types

Select...
6
4

Relationship

1
9

Authors

Journals

citations
Cited by 67 publications
(55 citation statements)
references
References 15 publications
0
55
0
Order By: Relevance
“…Privilege and Role Management Infrastructure Standards Validation (PERMIS) is a more ornate authorization model implementation that follows the principles of Role Based Access Control (RBAC) [9]. Attribute authorities in PERMIS are often independent and issue attributes that associate a role with a user.…”
Section: Permismentioning
confidence: 99%
“…Privilege and Role Management Infrastructure Standards Validation (PERMIS) is a more ornate authorization model implementation that follows the principles of Role Based Access Control (RBAC) [9]. Attribute authorities in PERMIS are often independent and issue attributes that associate a role with a user.…”
Section: Permismentioning
confidence: 99%
“…PERMIS [12,13] is an application independent privilege management infrastructure that comprises credential issuing and credential validation functionality as well as policy creation and policy decision making functionality. The components that are important to the current discussion are the Attribute Certificate Manager (ACM) and the Delegation Issuing Service (DIS), which both issue X.509 role ACs to holders, and the Credential Validation Service (CVS) which validates the issued role ACs (see Figure 2).…”
Section: Using Webdav In Permismentioning
confidence: 99%
“…In the case of PERMIS (Figure 6), the situation is more complex. PERMIS [8] provides a standalone authorization service (PERMIS Policy Decision Point), however it depends on the LDAP service which contains proper information in terms of Attribute Certificates and Policies. FiVO works with PERMIS by feeding an LDAP service with proper policies, generated automatically from policies which are part of the VO contract.…”
Section: Semantically Supported Vo Securitymentioning
confidence: 99%