School of Computing

Delegation Issuing Service

David Chadwick

In NIST 4th Annual PKI Workshop, pages 182-196, Gaithersberg, USA, April 2005 Available from : http://middleware.internet2.edu/pki05/proceedings/chadwick-delegation-issuing.pdf.

Abstract

This paper describes the concept of a delegation issuing service (DIS), which is a service that issues X.509 attribute certificates on behalf of an attribute authority (typically a manager). The paper defines the X.509 certificate extensions that are being proposed for the 2005 edition of X.509 in order to implement the DIS concept, as well as the additional steps that a relying party will need to undertake when validating certificates issued in this way. The paper also presents our initial experiences of designing a DIS to add to the PERMIS authorization infrastructure. The paper concludes by reviewing some of the previous standards work in delegation of authority and anticipating some of the further standardization work that is still required in the field of privilege management.

Download publication 186 kbytes (PDF)

Bibtex Record

@inproceedings{2286,
author = {David Chadwick},
title = {{Delegation Issuing Service}},
month = {April},
year = {2005},
pages = {182-196},
keywords = {determinacy analysis, Craig interpolants},
note = {Available from : http://middleware.internet2.edu/pki05/proceedings/chadwick-delegation-issuing.pdf},
doi = {},
url = {http://www.cs.kent.ac.uk/pubs/2005/2286},
    publication_type = {inproceedings},
    submission_id = {29539_1131460831},
    booktitle = {NIST 4th Annual PKI Workshop},
    address = {Gaithersberg, USA},
}

School of Computing, University of Kent, Canterbury, Kent, CT2 7NF

Enquiries: +44 (0)1227 824180 or contact us.

Last Updated: 21/03/2014