Share on Facebook

If a computer user temporarily hand over his authorizations to another user then this process is called delegation.[1][2]

Popular Science  (June 1967) ...It Liberian delegation visits Fort Benning - 090806 President Sharif Afghanistan - March 2012 ...item 2.. Other views: It "It Rest Sierra Leone and Brig. Gen. Kabia: A progressive voice for African military women - ALFS 2010 Liberian delegation visits Fort Benning - 090806 DFM Ayalon meets delegation of Indonesian journalists 23Feb10 Delegation, including Phil Kapp, for the 1912 ILGWU convention Frankfurt US Delegation Seattle Delegation visits Montreal Seattle Delegation visits Montreal Seattle Delegation visits Montreal Seattle Delegation visits Montreal Pressers DUP Delegation meets PSNI over Rathcoole Riots Remains of a demolished home US Delegation Listens to Questions: Town Hall for Civil Society UPR Delegation Listens to an NGO Question at Town Hall IT delegation in Sofia PM Hatoyama, and a delegation of MPs from Japan  with Commissioner Georgieva The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The The IMF/EU Delegation Known As The Palestinian homes in East Jerusalem Angela Angela Palestinian homes in East Jerusalem Palestinian homes, many slated for demolition The apartheid wall, East Jerusalem The apartheid wall, East Jerusalem Angela The apartheid wall, East Jerusalem U.S. Delegation Members During the UPR HRC Delegations Raise Panels to Request the Floor at Interactive Dialogue with High Commissioner Pillay chitral photos and story of chitral delegation chitral photos and story of Chitral delegation chitral photos and story of Chitral delegation chitral photos and story of Chitral delegation chitral photos and story of Chitral delegation
Images Source: Flickr. Images licensed under the Creative Commons CC-BY-SA
From Wikipedia, the free encyclopedia
Jump to: navigation, search

If a computer user temporarily hand over his authorizations to another user then this process is called delegation.[1][2]

Contents

Types of Delegation in IT network [edit]

There are essentially two classes of delegation.

  1. Delegation at Authentication/Identity Level
  2. Delegation at Authorization/Access Control Level

Delegation at Authentication Level [edit]

It is defined as follows: If an authentication mechanism provides an effective identity different from the validated identity of the user then it is called identity delegation at the authentication level, provided the owner of the effective identity has previously authorized the owner of the validated identity to use his identity.[3]

The existing techniques of identity delegation using sudo or su commands of UNIX are very popular. To use sudo command, a person first has to start his session with his own original identity. It requires the delegated account password or explicit authorizations granted by the system administrator. The user login delegation described in the patent of Mercredi and Frey is also an identity delegation.[4]

Delegation at Access Control Level [edit]

The most common way of ensuring computer security is access control mechanisms provided by operating systems such as UNIX, Linux, Windows, Mac OS, etc.[5] If the delegation is fine grained, like Role-based access control (RBAC) delegation, then there is always a risk of under-delegation, i.e., the delegator does not delegate all the necessary permissions to perform a delegated job. This may cause the denial of service, which is very undesirable in some environments, such as in safety critical systems or in health care. In RBAC based delegation, one option to achieve delegation is by reassigning a set of permissions to the role of a delegatee, however, finding the relevant permissions for a particular job is not an easy task for large and complex systems. Moreover, by assigning these permissions to a delegatee role, all other users who are associated with that particular role get the delegated rights. If the delegation is achieved by assigning the roles of a delegator to a delegatee then it would not only be a case of over-delegation but also the problem that the delegator has to figure out what roles, in the complex hierarchy of RBAC, are necessary to perform a particular job. These types of problems are not present in identity delegation mechanism and normally the user interface is simpler. More details can be found in the literature of RBAC.

References [edit]

  1. ^ Barka, E., Sandhu, R.: A role-based delegation model and some extensions. In: Proceedings of 16th Annual Computer Security Application Conference, New Orleans, U.S.A. (December 2000)
  2. ^ A mechanism for identity delegation at authentication level, N Ahmed, CD Jensen - Proceedings of the 14th Nordic Conference …, 2009 - portal.acm.org, 2009
  3. ^ A mechanism for identity delegation at authentication level, N Ahmed, CD Jensen - Proceedings of the 14th Nordic Conference …, 2009 - portal.acm.org, 2009
  4. ^ Mercredi, Frey: User login delegation. United States Patent Application Publication, US 2004/0015702 A1 2004
  5. ^ Gollmann, D.: Computer Security 2e. John Wiley and Sons, Chichester (2005)
Wikipedia content is licensed under the GNU Free Document License or Creative Commons CC-BY-SA
Loading...
Loading...