Access Control and Identity Management

Access Control Process

There are three steps to the access control process:

  1. Identification—The process by which a subject identifies itself to the access control system
  2. Authentication—Verification of the subject’s identity
  3. Authorization—The decision to allow or deny access to an object

The second step usually happens behind the scenes, so the subject is really only aware of two stages: He or she enters credentials and is either given or denied access to a resource. FIGURE 1-1 illustrates the access control process using human interaction as an example.

Three illustrations represent the three parts of the access control process of identification, authentication, and authorization.

FIGURE 1-1 The access control process.

Get Access Control and Identity Management, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.