Authentication vs AuhtorizationThis is a featured page

The problem of authorization is often thought to be identical to that of authentication; many widely adopted standard security protocols, obligatory regulations, and even statutes are based on this assumption.

However, more precise usage describes authentication as the process of verifying a claim made by a subject that it should be treated as acting on behalf of a given principal (person, computer, smart card, etc.), while authorization is the process of verifying that an authenticated subject has the authority to perform a certain operation. Authentication, therefore, must precede authorization.

For example, when you show proper identification to a bank teller, you could be authenticated by the teller as acting on behalf of a particular account holder, and you would be authorized to access information about the accounts of that account holder. You would not be authorized to access the accounts of other account holders.

Since authorization cannot occur without authentication, the former term is sometimes used to mean the combination of authentication and authorization.


gcraigburton
gcraigburton
Latest page update: made by gcraigburton , Apr 24 2009, 9:05 AM EDT (about this update About This Update gcraigburton Edited by gcraigburton


view changes

- complete history)
More Info: links to this page

Anonymous  (Get credit for your thread)


There are no threads for this page.  Be the first to start a new thread.

Related Content

  (what's this?Related ContentThanks to keyword tags, links to related pages and threads are added to the bottom of your pages. Up to 15 links are shown, determined by matching tags and by how recently the content was updated; keeping the most current at the top. Share your feedback on Wetpaint Central.)