|
| This Article | ||
| ||
| Share | ||
| Bibliographic References | ||
| Add to: | ||
| | ||
| Search | ||
| ||
DARPA Information Survivability Conference and Exposition - Volume II
Access Control on the Web Using Proof-carrying Authorization
Washington, DC
April 22-April 24
ISBN: 0-7695-1897-4
| ASCII Text | x | ||
| Lujo Bauer, Michael A. Schneider, Edward W. Felten, Andrew W. Appel, "Access Control on the Web Using Proof-carrying Authorization," DARPA Information Survivability Conference and Exposition,, vol. 2, pp. 117, DARPA Information Survivability Conference and Exposition - Volume II, 2003. | |||
| BibTex | x | ||
| @article{ 10.1109/DISCEX.2003.1194942, author = {Lujo Bauer and Michael A. Schneider and Edward W. Felten and Andrew W. Appel}, title = {Access Control on the Web Using Proof-carrying Authorization}, journal ={DARPA Information Survivability Conference and Exposition,}, volume = {2}, year = {2003}, issn = {2003102155}, pages = {117}, doi = {http://doi.ieeecomputersociety.org/10.1109/DISCEX.2003.1194942}, publisher = {IEEE Computer Society}, address = {Los Alamitos, CA, USA}, } | |||
| RefWorks Procite/RefMan/Endnote | x | ||
| TY - CONF JO - DARPA Information Survivability Conference and Exposition, TI - Access Control on the Web Using Proof-carrying Authorization SN - 2003102155 SP EP A1 - Lujo Bauer, A1 - Michael A. Schneider, A1 - Edward W. Felten, A1 - Andrew W. Appel, PY - 2003 KW - null VL - 2 JA - DARPA Information Survivability Conference and Exposition, ER - | |||
We describe a system for access control on the web that is based on the ideas of proof-carrying authorization (PCA). Our system is implemented as modules that extend a standard web server and web browser to use PCA to control access to web pages. The web browser generates proofs mechanically by iteratively fetching proof components until a proof can be constructed. We provide for iterative authorization, by which a server can require a browser to prove a series of challenges. Our implementation includes a series of optimizations, such as speculative proving, and modularizing and caching proofs, and demonstrates that the goals of generality, flexibility, and interoperability are compatible with reasonable performance.
Citation:
Lujo Bauer, Michael A. Schneider, Edward W. Felten, Andrew W. Appel, "Access Control on the Web Using Proof-carrying Authorization," discex, vol. 2, pp.117, DARPA Information Survivability Conference and Exposition - Volume II, 2003
Usage of this product signifies your acceptance of the Terms of Use.
