My Photo

« Computation and Computer Science: A Two Way Street | Main | Computation Institute »

August 26, 2006

Attribute-based Authorization

A wonderful thing has been happening over the past year: many previously disparate and apparently incompatible threads (PKI, Grid Security Infrastructure, Shibboleth, SAML, etc.) have come together in a consistent "attribute-based access control" architecture, in which access control decisions can be made on the basis of various user attributes in addition to simple identity. Many people have contributed to making this happen, but Frank Siebenlist has been a major contributor on the architecture and standards.

If you want to learn more about this, one good starting point is a draft article that Von Welch, myself, and others have put together describing how this can work within the context of the TeraGrid cyberinfrastructure. See also a recent article by Bo Lang. It's all very exciting.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/5791619

Listed below are links to weblogs that reference Attribute-based Authorization:

Comments

Post a comment

Comments are moderated, and will not appear on this weblog until the author has approved them.

If you have a TypeKey or TypePad account, please Sign In