Publication
S&P 2000
Conference paper
Access control meets public key infrastructure, or: assigning roles to strangers
Abstract
Existing role-based access control mechanisms are extended to provide a simple, modular architecture and easy migration from existing systems. The resulting system automatically collects missing certificates from peer servers. An implementation that can be used as an extension of a web server or as a separate server with interface to applications is discussed.