Applying authorization to intranets: architectures, issues and APIs

  • Authors:
  • P. Ashley;M. Vandenwauver;F. Siebenlist

  • Affiliations:
  • TIVOLI Security Business Unit, A Division of IBM, 9020 Capital of Texas Highway, Great Hills Corporation Center, Bldg1, Austin, TX 78759, USA;TIVOLI Security Business Unit, A Division of IBM, 9020 Capital of Texas Highway, Great Hills Corporation Center, Bldg1, Austin, TX 78759, USA;TIVOLI Security Business Unit, A Division of IBM, 9020 Capital of Texas Highway, Great Hills Corporation Center, Bldg1, Austin, TX 78759, USA

  • Venue:
  • Computer Communications
  • Year:
  • 2000

Quantified Score

Hi-index 0.24

Visualization

Abstract

There are a number of proposed solutions to solve the Intranet authorization problem. They fall into two categories: architectures for providing an authorization framework, and generic authorization application programmer interfaces (APIs) for allowing applications access to the authorization services. This paper examines the leading initiatives in these areas: DCE, SESAME and Windows2000 as authorization frameworks and the GSS-API, GAA-API and AZN-API. The paper stresses the important issues related to implementing an authorization service.