Authentication - Authorization


The process of authorization is distinct from that of authentication. Whereas authentication is the process of verifying that "you are who you say you are", authorization is the process of verifying that "you are permitted to do what you are trying to do". Authorization thus presupposes authentication.

For example, a client showing proper identification credentials to a bank teller is asking to be authenticated to act on behalf of the account holder. A client whose authentication request is approved becomes authorized to access the accounts of that account holder, but no others.

Even though authorization cannot occur without authentication, the former term is sometimes used to mean the combination of both.

To distinguish "authentication" from the closely related "authorization", the short-hand notations A1 (authentication), A2 (authorization) as well as AuthN / AuthZ (AuthR) or Au / Az are used in some communities.

Normally delegation was considered to be a part of authorization domain. Recently authentication is also used for various type of delegation tasks. Delegation in IT network is also a new but evolving field.

Read more about this topic:  Authentication

Other articles related to "authorization":

L-2 Visa - Change From H-4 To L-2 Status To Get Work Authorization
... To obtain work authorization, submit Form I-765, Application for Employment Authorization, together with Form I-539, Application for Change or Extension of Status ...
Spring Security - Key Authorization Features
... AspectJ method invocation authorization ... HTTP authorization of web request URLs using a choice of Apache Ant paths or regular expressions ...
Authorization Bill
... In the United States Congress, an authorization bill is a proposed public law that permits the federal government to carry out various functions and ... Authorization bills are generally contrasted with appropriations bills, which are laws that provide funding for discretionary programs that are already authorized for the federal government to legally ...
Enterprise Privacy Authorization Language
... Enterprise Privacy Authorization Language (EPAL) is a formal language for writing enterprise privacy policies to govern data handling practices in IT systems according to fine-grained positive and negative ...
L-2 Visa - Employment Authorization Is Not Received Within 90 Days
... option to submit a new Form I-765, Application for Employment Authorization, along with copies of the required supporting documents and the receipt for the original application at the ... Based on this, the applicant will receive an Employment Authorization document which is valid for 240 days while the USCIS processes the two year employment authorization document ...