This page (revision-1) was last changed on 29-Nov-2024 16:16 by UnknownAuthor

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Page revision history

Version Date Modified Size Author Changes ... Change note

Page References

Incoming links Outgoing links
Authorization

Version management

Difference between version and

At line 1 added 47 lines
!!! Overview
[{$pagename}] ([AuthZ]) is the process where a [Trustor] [Delegates|Delegation] a [Permission] to a [Trustee] to perform a [privilege] against a [Target Resource]\\
or\\
Allowing an [Entity] to do something. ([Thing Explainer])
[{$pagename}] is a Facet Of Building [Trust]
[{$pagename}] is the process of determining whether the [Digital Identity] which has been through the [Authentication] process has the [Permission] to access a specific [Protected Resource] as requested.
[{$pagename}] enforcement is performed by [Access Control]
!! [{$pagename}] and [Authentication]
[{$pagename}] is usually only attempted following [authentication] so that the [Policy Enforcement Point] has some [Level Of Assurance] of the [Trustee] is attempting to access a [Protected Resource].
[{$pagename}] does not always imply [Authentication] as when [Bearer Tokens] are utilized. This is also true when a Hotel [Key Card] is utilized.
!! [Definition][2]
[{$pagename}]
noun\\
* the act of authorizing.
* [permission] or power granted by an authority; sanction.
* a legislative act authorizing money to be spent for government programs that specifies a maximum spending level without provision for actual funds.
In security engineering and computer security, authorization is the concept of allowing [access] to [Resources] only to those permitted to use them.[1]
A number of components are typically be involved in an authorization process, including:
* The [Access Control] system.
* The [Permission] system.
* The [Policy].
!! [Examples]
* Door [Key Card] is a [Bearer Token] which provides [{$pagename}] to a [Protected Door|Protected Resource] to any [Entity] which has possession.
!! [Consent vs Authorization]
Frankly, I can not determine a difference ([Consent vs Authorization]) in [{$pagename}] and __Authorized__, __Authorise__ or __[Authorization]__ other than the noun vs verb thing.
%%information
There maybe some narrow [legal] definitions (think [HIPAA]) that delineate differences between [consent] and [authorization] but in general, they are the same.
%%
!! More Information
There might be more information for this subject on one of the following:
[{ReferringPagesPlugin before='*' after='\n' }]
----
* [#1] - [Authorization|Wikipedia:Authorization|target='_blank'] - based on data observed:2010-05-18
* [#2] - [dictionary.com|http://dictionary.reference.com/browse/authorization?s=t|target='_blank'] - based on data observed:2010-05-18