Abstract

We have briefly described a conceptual model for authorizing web services. If one contrasts it with “more traditional” models, the more interesting differences include: authorization based not just on user identity and group memberships but also on attributes of users, support for partial trust on attributes as well as user identity and group memberships, trust and authorization policy that can be arguments to requests from untrusted clients, as long as they originate with parties trusted to set such policy.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call