DocumentCode :
2359939
Title :
The Authorization Service of Tivoli Policy Director
Author :
Karjoth, Günter
Author_Institution :
Zurich Res. Lab., IBM Res., Zurich, Switzerland
fYear :
2001
fDate :
10-14 Dec. 2001
Firstpage :
319
Lastpage :
328
Abstract :
This paper presents the Authorization Service provided by Tivoli Policy Director (PD) and its use by PD family members as well as third-party applications. Policies are defined over an object namespace and stored in a database, which is managed via a management console and accessed through an Authorization API. The object namespace abstracts from heterogeneous systems and thus enables the definition of consistent policies and their centralized management. ACL inheritance and delegated management allow these policies to be managed efficiently. The Authorization API allows applications with their own access control requirements to decouple authorization logic from application logic. By intercepting the traffic over well-defined communication protocols (TCP/IP HTTP IIOP and others), PD family members establish a single entry point to enforce enterprise policies that regulate access to corporate data.
Keywords :
Internet; application program interfaces; authorisation; ACL inheritance; Authorization APL; Authorization Service; HTTP; IIOP; IT infrastructure; Internet; PD family members; TCP/IP; Tivoli Policy Director; access control; authorization logic; corporate data; delegated management; enterprise policies; management console; object namespace; third-party applications; Access control; Access protocols; Authentication; Authorization; Logic; Protection; Resource management; Scalability; TCPIP; Web server;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 2001. ACSAC 2001. Proceedings 17th Annual
Print_ISBN :
0-7695-1405-7
Type :
conf
DOI :
10.1109/ACSAC.2001.991547
Filename :
991547
Link To Document :
بازگشت