Re: Outreach via wikipedia articles on authentication and authorization

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD53E6B8194@G4W3222.americas.hpqcorp.net>
I have some stuff on slides I used for an RSA talk that talks about access control having four steps.

1. Identification - knowing who to throw in jail.  Well, OK, just knowing who to hold responsible.  It's what we do when setting up an account for a new user.

2. Authentication - what a process must do to be able to use the privileges assigned to an identified individual

3. Authorization - granting a right to be associated with a particular authentication, e.g., adding an entry in an ACL

4. Access decision - deciding whether or not to honor a request

By the way, the statement about authentication is imprecise in a significant way.  Authentication only proves that you possess specific credentials.  It only specifies who you are (identification) if those credentials were not shared either intentionally or unintentionally.

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.