Authors
Joon S Park, Ravi Sandhu, Gail-Joon Ahn
Publication date
2001/2/1
Journal
ACM Transactions on Information and System Security (TISSEC)
Volume
4
Issue
1
Pages
37-71
Publisher
ACM
Description
Current approaches to access control on the Web servers do not scale to enterprise-wide systems because they are mostly based on individual user identities. Hence we were motivated by the need to manage and enforce the strong and efficient RBAC access control technology in large-scale Web environments. To satisfy this requirement, we identify two different architectures for RBAC on the Web, called user-pull and server-pull. To demonstrate feasibility, we implement each architecture by integrating and extending well-known technologies such as cookies, X.509, SSL, and LDAP, providing compatibility with current web technologies. We describe the technologies we use to implement RBAC on the Web in different architectures. Based on our experience, we also compare the tradeoffs of the different approaches.
Total citations
200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024715353026442823302421189181661410633453
Scholar articles
JS Park, R Sandhu, GJ Ahn - ACM Transactions on Information and System Security …, 2001