6: Authentication and Authorization
-
Published:2020
Kathleen M. Moriarty, 2020. "Authentication and Authorization", Transforming Information Security: Optimizing Five Concurrent Data Trends to Reduce Resource Drain, Kathleen M. Moriarty
Download citation file:
Authentication and authorization are critical security controls that must be evaluated to meet the requirements of a system considering ease of management and use for end users.
This chapter discusses the progression of authentication and authorization options aligned to technology trends for future network and security architectures. In some cases, the evolution of authentication methods is tied to solving a security consideration, in others, favoring ease of use. A book could easily be dedicated to this topic, as no single solution covers all use cases. Instead a condensed, broad overview with recommendations including references is provided as a starting point. Authentication is a critical security control that remains a difficult area with the proliferation of options and no organized way to assess by those implementing or developing solutions. Not only that, enabling single or reduced sign-on may require several protocols combined, leading to resource intensive management. The aim of this chapter is not to provide a detailed overview of all possible technologies, but rather to categorize the types of protocols available with a few high-level considerations for each. The trends of strong transport encryption, data-centric security models, and ensuring user ownership of data rely upon strong authentication and authorization. As new architectural patterns emerge, it is important to consider the long-term direction of authentication and authorization, how they evolve, and to plan for alignment in terms of product support to ease integration and management for product consumers.
