Tuomas Aura. On the structure of delegation networks. Research Report A48, Helsinki University of Technology, Department of Computer Science and Engineering, Digital Systems Laboratory, Espoo, Finland, December 1997.
In new distributed, key-oriented access control systems access rights are delegated by a freely formed network of certificates. For example, the SPKI public-key infrastructure is being designed for this kind of distributed trust management on the Internet. We formalize the concept of a delegation network and present a formal semantics for the delegation of access rights with certificates. The certificates can have multiple subjects who must jointly use the authority. Some fundamental properties of the system are proven, alternative techniques for authorization decisions are compared and their equivalence is shown rigorously. In particular, we prove that certificate reduction is a sound and complete decision technique. We also suggest a new type of threshold certificates and prove its properties. The formal model is used to develop efficient algorithms for access control decisions from a database of certificates.
certificates, delegation network, access control, formal model of distributed trust management.
Suggested BibTeX entry:
address = {Espoo, Finland},
author = {Tuomas Aura},
institution = {Helsinki University of Technology, Department of Computer Science and Engineering, Digital Systems Laboratory},
month = {December},
number = {A48},
pages = {53},
title = {On the Structure of Delegation Networks},
type = {Research Report},
year = {1997},