An extensible and decoupled architectural model for authorization frameworks

4Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Existing access control frameworks fall short on offering comprehensive and general solutions in application development, often limited to role-based access control policies. This leads developers to craft solutions when it is necessary to implement complex access control policies, causing tangling of business and authorization concerns. In this context, framework extensibility and technology independence are also important to enable its adaptation to a wide range of applications. In order to widen the scope of authorization solutions, this research proposes an architectural model for frameworks, extensible to various access control models. The Esfinge Guardian framework, an implementation of the architectural model, is presented, with usage scenarios and a brief tutorial. Finally, a comparative analysis is presented between Esfinge Guardian and the main authorization framework providers, showing that the Esfinge Guardian is indeed more extensible and decoupled than the compared solutions. © 2013 Springer-Verlag Berlin Heidelberg.

Cite

CITATION STYLE

APA

Silva, J. O., Guerra, E. M., & Fernandes, C. T. (2013). An extensible and decoupled architectural model for authorization frameworks. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 7974 LNCS, pp. 614–628). Springer Verlag. https://doi.org/10.1007/978-3-642-39649-6_44

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free