School of Computing

PERMIS: a modular authorization infrastructure

David W Chadwick, Gansen Zhao, Sassa Otenko, Romain Laborde, Linying Su, and Tuan Anh Nguyen

Concurrency and Computation: Practice and Experience, 20(11):182-196, August 2008 Online ISSN: 1532-0634 [doi].

Abstract

Authorization infrastructures manage privileges and render access control decisions, allowing applications to adjust their behavior according to the privileges allocated to users. This paper describes the PERMIS role based authorization infrastructure along with its conceptual authorization, access control, and trust models. PERMIS has the novel concept of a credential validation service, which verifies a user�s credentials prior to access control decision making and enables the distributed management of credentials. PERMIS also supports delegation of authority, thus credentials can be delegated between users, further decentralizing credential management. Finally, PERMIS supports history based decision making which can be used to enforce such things as separation of duties and cumulative use of resources. Details of the design and the implementation of PERMIS are presented along with details of its integration with Globus Toolkit, Shibboleth and GridShib. A comparison of PERMIS with other authorization and access control implementations is given, along with suggestions where future research and development is still needed.

Download publication 298 kbytes (PDF)

Bibtex Record

@article{2834,
author = {David W Chadwick and Gansen Zhao and Sassa Otenko and Romain Laborde and Linying Su and Tuan Anh Nguyen},
title = {{P}{E}{R}{M}{I}{S}: a modular authorization infrastructure},
month = {August},
year = {2008},
pages = {182-196},
keywords = {determinacy analysis, Craig interpolants},
note = {Online ISSN: 1532-0634},
doi = {10.1002/cpe.1313},
url = {http://www.cs.kent.ac.uk/pubs/2008/2834},
    publication_type = {article},
    submission_id = {16835_1225726698},
    ISSN = {1532-0626},
    journal = {Concurrency and Computation: Practice and Experience},
    volume = {20},
    number = {11},
}

School of Computing, University of Kent, Canterbury, Kent, CT2 7NF

Enquiries: +44 (0)1227 824180 or contact us.

Last Updated: 21/03/2014