We have implemented and deployed an access control mechanism that uses digitally-signed certificates to define and enforce an access policy for a set of distributed resources that have multiple, independent and geographically dispersed stakeholders. The stakeholders assert their access requirements in use-condition certificates and designate those trusted to attest to the corresponding user attributes. Users are identified by X.509 identity certificates. During a request to use a resource, a policy engine collects all the relevant certificates and decides if the user satisfies all the requirements. This paper describes the model, architecture and implementation of this system. It also includes some preliminary performance measurements and o...
International audienceThe challenge of pervasive computing consists in offering access to computing ...
International audienceIn distributed systems especially in pervasive environments, the users usually...
We describe an architecture for secure, indepen-dent, interworking services (Oasis). Each service is...
We describe a system whose purpose is to explore the use of certificates for the distributed manage...
We describe a system whose purpose is to explore the use of certificates for the distributed manage...
Rights to individual papers remain with the author or the author's employer. Permission is gran...
A new approach to the deployment of public key infrastructure is presented, based on a separation be...
The Internet enables connectivity between many strangers- entities that don't know each other. ...
This paper describes a policy driven role based access control system. The user's roles, and the po...
Reviewer: DellaMea, Vincenzo[This item is a preserved copy and is not necessarily the most recent ve...
Reviewer: DellaMea, Vincenzo[This item is a preserved copy and is not necessarily the most recent ve...
Abstract. The Internet provides tremendous connectivity and immense information sharing capability w...
This paper describes a security system for authorization in open networks. Authorization means autho...
The advance of web services technologies promises to have far-reaching effects on the Internet and e...
International audienceThe challenge of pervasive computing consists in offering access to computing ...
International audienceThe challenge of pervasive computing consists in offering access to computing ...
International audienceIn distributed systems especially in pervasive environments, the users usually...
We describe an architecture for secure, indepen-dent, interworking services (Oasis). Each service is...
We describe a system whose purpose is to explore the use of certificates for the distributed manage...
We describe a system whose purpose is to explore the use of certificates for the distributed manage...
Rights to individual papers remain with the author or the author's employer. Permission is gran...
A new approach to the deployment of public key infrastructure is presented, based on a separation be...
The Internet enables connectivity between many strangers- entities that don't know each other. ...
This paper describes a policy driven role based access control system. The user's roles, and the po...
Reviewer: DellaMea, Vincenzo[This item is a preserved copy and is not necessarily the most recent ve...
Reviewer: DellaMea, Vincenzo[This item is a preserved copy and is not necessarily the most recent ve...
Abstract. The Internet provides tremendous connectivity and immense information sharing capability w...
This paper describes a security system for authorization in open networks. Authorization means autho...
The advance of web services technologies promises to have far-reaching effects on the Internet and e...
International audienceThe challenge of pervasive computing consists in offering access to computing ...
International audienceThe challenge of pervasive computing consists in offering access to computing ...
International audienceIn distributed systems especially in pervasive environments, the users usually...
We describe an architecture for secure, indepen-dent, interworking services (Oasis). Each service is...