DOC PREVIEW
SJSU CS 265 - Akenti

This preview shows page 1-2-3-4-5-6 out of 17 pages.

Save
View full document
View full document
Premium Document
Do you want full access? Go Premium and unlock all 17 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 17 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 17 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 17 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 17 pages.
Access to all documents
Download any document
Ad free experience
View full document
Premium Document
Do you want full access? Go Premium and unlock all 17 pages.
Access to all documents
Download any document
Ad free experience
Premium Document
Do you want full access? Go Premium and unlock all 17 pages.
Access to all documents
Download any document
Ad free experience

Unformatted text preview:

Akenti Distributed Access Control ApplicationOverviewBackgroundGoalsAkenti High Level Diagram (Credit JISC)Akenti at a Closer ViewAkenti specific certificatesAkenti specific certificates (2)Entities in this exerciseAkenti Engine – Case Study IAkenti Engine – Case Study IIAkenti Engine – Case Study IIIAkenti Engine – Case Study IVUsageConclusionReferencesQuestionsAkenti Distributed Access Control ApplicationByJiewei LinOverview•Background•Design goals•Akenti specific certificates•Akenti engine•Akenti in use•Conclusion•ReferencesBackground•Started at Lawrence Berkeley National Lab in 1998•Designed to solve problem of multiple resource and multiple owners•Used in a public-key environmentGoals•Allow different owner requirements•Take immediate effect of owner requirements•Support high level of integrity and non-repudiationAkenti High Level Diagram (Credit JISC)Akenti at a Closer ViewAkenti specific certificates•Policy certificates•Use Condition certificates•Attribute certificates•Capability certificatesAkenti specific certificates (2)•Shown an exampleEntities in this exercise•CA I •CA IA (ca of Stake Holder I, and User I.)•Stake Holder I•User I (has Attribute Cert: ou=sjsu && job=student, and cn=User I)Akenti Engine – Case Study I•Resource: R1•Policy Cert.: trusted CA = CAI•Use Cond.: ou=sjsu && job=student scope=local critical=true actions=read Permission Granted: action=readAkenti Engine – Case Study II•Resource: R2•Policy Cert.: trusted CA = CAI•Use Cond.: ou=sjsu && job=student scope=subtree critical=true actions=read Permission Granted: action=readAkenti Engine – Case Study III•Resource: R2/S1•Policy Cert.: trusted CA = CA I•Use Cond.: cn=User I scope=local critical=false actions=write, execute Permission Granted: action=read, write, executeAkenti Engine – Case Study IV•Resource: R3•Policy Cert.: trusted CA = CA I•Use Cond.: ou=sjsu && job=student scope=local critical=true actions=read•Use Cond.: time>10:00 && time <12:00 scope=local critical=true actions=write, executePermission Granted: action=read action=write, execute if time>10:00 && time <12:00Usage•As a function•As an access control using Apache module in a web serverConclusion•Mature and sophisticated authorization app.•Uses flexible access control policies•A useful toolReferences•[AK] http://www-itg.lbl.gov/security/Akenti/ •[JISC] http://umbriel.dcs.gla.ac.uk/NeSC/general/talks/140/7.ppt •[SURA] http://www.dpo.uab.edu/sura/Security/sld001.htmQuestions


View Full Document

SJSU CS 265 - Akenti

Documents in this Course
Stem

Stem

9 pages

WinZip

WinZip

6 pages

Rsync

Rsync

7 pages

Hunter

Hunter

11 pages

SSH

SSH

16 pages

RSA

RSA

7 pages

Blunders

Blunders

51 pages

Captcha

Captcha

6 pages

Radius

Radius

8 pages

Firewall

Firewall

10 pages

SAP

SAP

6 pages

SECURITY

SECURITY

19 pages

Rsync

Rsync

18 pages

MDSD

MDSD

9 pages

honeypots

honeypots

15 pages

VPN

VPN

6 pages

Wang

Wang

18 pages

TKIP

TKIP

6 pages

ESP

ESP

6 pages

Dai

Dai

5 pages

Load more
Download Akenti
Our administrator received your request to download this document. We will send you the file to your email shortly.
Loading Unlocking...
Login

Join to view Akenti and access 3M+ class-specific study document.

or
We will never post anything without your permission.
Don't have an account?
Sign Up

Join to view Akenti 2 2 and access 3M+ class-specific study document.

or

By creating an account you agree to our Privacy Policy and Terms Of Use

Already a member?