Cross-Domain Access Control via PKI
 by Dr. Grit Denker, J. Millen & Y. Miyake.

From Policies for Distributed Systems and Networks.
IEEE Computer Society.
June, 2002.
Pages 202–205.

In this note we consider how role-based access control can be managed on a large scale over the Internet and across organizational boundaries. We take a PKI approach, in which users are identified using public key certificates, as are the servers. The main features of our approach are: access control by (client, role) pair; implied revocation based on the role hierarchy; automatic generation of certificate validity tickets; and certificate chains to prove a client role hierarchy to a server.
