Web-based authorization based on X.509 Privilege Management Infrastructure

被引:0
|
作者
Forné, J [1 ]
Hinarejos, MF [1 ]
机构
[1] Univ Politecn Catalunya, Dept Telemat Engn, ES-08034 Barcelona, Spain
关键词
PMI Privilege Management Infrastructure; X.509 attribute certificate; web-based authorization; access control;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The access control to resources is bound up with the authentication and the authorization. The methods used up tin now are quite static and maintain the information centralized with some important scalability problems. In addition, they do not take advantage of public key cryptography for the authorization. In order to overcome these disadvantages the IT UT X.509 Recommendation defines a framework for authentication (PKI, Public Key Infrastructure, based on identity certificates) and authorization (PMI, Privilege Management Infrastructure, based on attribute certificate). This paper presents an implementation of an authorization system for web based applications based on the ITU-T X.509 Recommendation. For compatibility with web clients and servers, the credentials are transmitted using a standard web communications protocol, such as https. The goal of our system is that is easy-to-use, X.509 compatible and a standard web browser can be used as a client.
引用
收藏
页码:565 / 568
页数:4
相关论文
共 50 条
  • [1] The PERMIS X.509 role based privilege management infrastructure
    Chadwick, DW
    Otenko, A
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2003, 19 (02): : 277 - 289
  • [2] The X.509 privilege management infrastructure
    Chadwick, DW
    [J]. SECURITY AND PRIVACY IN ADVANCED NETWORKING TECHNOLOGIES, 2004, 193 : 15 - 25
  • [3] RBAC policies in XML for X.509 based privilege management
    Chadwick, DW
    Otenko, A
    [J]. SECURITY IN THE INFORMATION SOCIETY: VISIONS AND PERSPECTIVES, 2002, 86 : 39 - 53
  • [4] Implementing role based access controls using X.509 privilege management - The PERMIS authorisation infrastructure
    Chadwick, DW
    Otenko, A
    [J]. SECURITY AND PRIVACY IN ADVANCED NETWORKING TECHNOLOGIES, 2004, 193 : 26 - 39
  • [5] XML based X.509 authorization in CERNET grid
    Liu, W
    Wu, JP
    Duan, HX
    Li, X
    Ren, P
    [J]. GRID AND COOPERATIVE COMPUTING GCC 2004, PROCEEDINGS, 2004, 3251 : 325 - 332
  • [6] The concept of a Distributed Repository for Validating X.509 Attribute Certificates in a Privilege Management Infrastructure
    Gergely, Adam Mihai
    Crainicu, Bogdan
    [J]. 9TH INTERNATIONAL CONFERENCE INTERDISCIPLINARITY IN ENGINEERING, INTER-ENG 2015, 2016, 22 : 926 - 930
  • [7] X.509 Authentication/Authorization in FermiCloud
    Kim, Hyunwoo
    Timm, Steven C.
    [J]. 2014 IEEE/ACM 7TH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC), 2014, : 732 - 737
  • [8] Beyond X.509 Token-based authentication and authorization in practice
    Ceccanti, Andrea
    Vianello, Enrico
    Giacomini, Francesco
    [J]. 24TH INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP 2019), 2020, 245
  • [9] Beyond X.509: token-based authentication and authorization for HEP
    Ceccanti, Andrea
    Vianello, Enrico
    Caberletti, Marco
    Giacomini, Francesco
    [J]. 23RD INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP 2018), 2019, 214
  • [10] EVAWEB: A web-based assessment system to learn X.509/PKIX-based digital signatures
    Gonzalez-Tablas Ferreres, Ana Isabel
    Wouters, Karel
    Ramos Alvarez, Benjamin
    Ribagorda Garnacho, Arturo
    [J]. IEEE TRANSACTIONS ON EDUCATION, 2007, 50 (02) : 112 - 117