ABSTRACT

The concepts of digital authentication and delegation-developed in the previous two chapters-are essential for analyzing networks, both public (such as the world wide web) and private (such as those used by financial institutions). With networks, the tasks of authenticating principals and authorizing access requests are made more difficult by the lack of locality among the policy makers (i.e., authorities), the access controllers (i.e., reference monitors), and the originators of requests.