The Authorization Service of Tivoli Policy Director

  • Authors:
  • G. Karjoth

  • Affiliations:
  • -

  • Venue:
  • ACSAC '01 Proceedings of the 17th Annual Computer Security Applications Conference
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents the Authorization Service provided byTivoli Policy Director (PD) and its use by PD family membersas well as third-party applications. Policies are definedover an object namespace and stored in a database, which ismanaged via a management console and accessed throughan Authorization API. The object namespace abstracts fromheterogeneous systems and thus enables the definition ofconsistent policies and their centralized management. ACLinheritance and delegated management allow these policiesto be managed efficiently. The Authorization API allows applicationswith their own access control requirements to de-coupleauthorization logic from application logic. By interceptingthe traffic over well-defined communication protocols(TCP/IP, HTTP, IIOP, and others), PD familiy membersestablish a single entry point to enforce enterprise policiesthat regulate access to corporate data.