<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.infra-repository.org/oiar-2013/index.php?action=history&amp;feed=atom&amp;title=PAT.Authentication%2BAuthorization</id>
	<title>PAT.Authentication+Authorization - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.infra-repository.org/oiar-2013/index.php?action=history&amp;feed=atom&amp;title=PAT.Authentication%2BAuthorization"/>
	<link rel="alternate" type="text/html" href="https://www.infra-repository.org/oiar-2013/index.php?title=PAT.Authentication%2BAuthorization&amp;action=history"/>
	<updated>2026-05-06T16:32:23Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.40.0</generator>
	<entry>
		<id>https://www.infra-repository.org/oiar-2013/index.php?title=PAT.Authentication%2BAuthorization&amp;diff=540&amp;oldid=prev</id>
		<title>Daniel Jumelet at 23:22, 11 November 2012</title>
		<link rel="alternate" type="text/html" href="https://www.infra-repository.org/oiar-2013/index.php?title=PAT.Authentication%2BAuthorization&amp;diff=540&amp;oldid=prev"/>
		<updated>2012-11-11T23:22:21Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Maturity|3}}&lt;br /&gt;
{{Pageheaderbox4PatternType&lt;br /&gt;
|PATname=Authentication &amp;amp; Authorization&lt;br /&gt;
|summary=Secures usage of facilities and applications by validating identities and permissions&lt;br /&gt;
|version=0.1&lt;br /&gt;
|owner=J.A.H. Schoonderbeek&lt;br /&gt;
|sector=Infrastructure Sector Core&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
In fact Authentication and Authorization are functions that are carried out by human beings. Authentication is done when someone wants to make sure - to a certain extend - that a claim about a subject is true. A special form of authentication is identification, which is a check of the identity of a subject. Authorizations is the process of granting rights to a subject to use a certain resource. &lt;br /&gt;
&lt;br /&gt;
When it comes down to the use of automated systems and data, a process is needed to check if someone is entitled to this use. This means that records are made of authorizations (permissions), that need to be validated if someone is issuing rights (Permission Validation). To identify a digital user as a real world person or system, the digital identity (a digital representation of the real world identity) claim is validated by means of comparing one or more credentials that are provided during the validation with credentials that were stored earlier when the digital identity was created and administered (e.g. password hashes, biometric hashes, tokens, certificates). Thus, the Identity Validation function is an automated rematch of the real identity with the digital identity of a user. The Permission Validation function is an automated check whether a user has the right permissions to use a certain resource or data&lt;br /&gt;
&lt;br /&gt;
===Further notices===&lt;br /&gt;
* It is a good practice to limit digital identities to Natural Persons and Physical Systems. In that case, the validation of this type of digital identities (and it&amp;#039;s logging) does have meaning in a legal context. &lt;br /&gt;
* Identity Validation can also be used in conjunction with logging, which makes the process of Auditing possible in a way that does have meaning in a legal context, if digital identities are limited to Natural Persons and Physical Systems.&lt;br /&gt;
&lt;br /&gt;
{{PAgraphic&lt;br /&gt;
|graphic=PAT.Authentication+Authorization.png&lt;br /&gt;
|source=Pattern Types.vsd&lt;br /&gt;
|size=500px&lt;br /&gt;
|title=Authentication &amp;amp; Authorization Pattern&lt;br /&gt;
|kind=Type&lt;br /&gt;
}}&lt;br /&gt;
{{Pattern Type Composition}}&lt;br /&gt;
{{Pattern Type Composition Row&lt;br /&gt;
|facility=BT.Identity Validation&lt;br /&gt;
|choice=must&lt;br /&gt;
|reason=This facility delivers the functionality of validating a digital identity.&lt;br /&gt;
}}&lt;br /&gt;
{{Pattern Type Composition Row&lt;br /&gt;
|facility=BT.Identity Store&lt;br /&gt;
|choice=must&lt;br /&gt;
|reason=This facility is required because it offers the Identity Validation the data it needs to perform the validation.&lt;br /&gt;
}}&lt;br /&gt;
{{Pattern Type Composition Row&lt;br /&gt;
|facility=BT.Permission Validation&lt;br /&gt;
|choice=may&lt;br /&gt;
|reason=If authorization is needed, then this facility will provide it. Note that it requires access to a Permission Register, but most likely also to an Identity Store, since many permissions are granted based on identity attributes like user ID, group membership or (for example) Job Title.&lt;br /&gt;
}}&lt;br /&gt;
{{Pattern Type Composition Row&lt;br /&gt;
|facility=BT.Permission Register&lt;br /&gt;
|choice=may&lt;br /&gt;
|reason=This facility provides Permission Validation with the ability to retrieve the current valid (set of) permissions. Note that the permissions themselves likely have a relation with a (particular) Identity Store, since many permissions are granted based on identity attributes like user ID, group membership or (for example) Job Title.&lt;br /&gt;
}}&lt;br /&gt;
{{Pattern Type Composition Row&lt;br /&gt;
|facility=BT.Control Interface&lt;br /&gt;
|choice=may&lt;br /&gt;
|reason=The purpose of this facility within the Pattern is to focus the attention on the security aspects of an available means to read and/or alter the content of either the Identity Store or the Permission Register.&lt;br /&gt;
}}&lt;br /&gt;
{{Table Ending}}&lt;br /&gt;
{{Pattern Type Neighbors}}&lt;br /&gt;
{{Pattern_Type_Adjacent_PAT_Row&lt;br /&gt;
|pattern=PAT.Identity+Permission_Management&lt;br /&gt;
|choice=may&lt;br /&gt;
|reason=To maintain the information in the Identity Store and Permission Register (if present), the Identity &amp;amp; Permission Management Pattern is required. It provisions accounts, ensures information is kept correct and current, and makes auditing possible, both on granted permissions and on changes in identity and/or permission information itself.&lt;br /&gt;
}}&lt;br /&gt;
{{Table Ending}}&lt;br /&gt;
{{PATfooter}}&lt;/div&gt;</summary>
		<author><name>Daniel Jumelet</name></author>
	</entry>
</feed>