| • Science | • People | • Locations | • Timeline |
to use a service or a resource that the issuer controls or has access to use.
The permission can be delegated.
Please see SPKI/SDSI Certificate Documention for an example.
This solution prevents the service or resource host from having to use large access control lists. It is similar to the idea of capabilities: store the permission (or permissions) with a protected pointer to the object but not with the object itself.