Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

An access-control system decides which subject can perform which operation on which resource under a policy. An access control protocol is not the name of one universal standard: depending on context, it may mean a message exchange that supports access, a policy language, or a mechanism for enforcing permissions. To be precise, name the protocol or policy specification involved.

What does “access control protocol” mean?

The phrase is ambiguous because access control involves several distinct tasks. A protocol defines how components exchange messages; an authorization method or policy determines which requested actions are allowed. An authentication protocol can support an access-control workflow, but proving an identity claim does not by itself define that identity’s permissions.

NIST’s current digital identity guidelines frame authentication around determining whether a claimant controls authenticators associated with a claimed digital identity. The guidelines cover identity proofing, authentication, and federation. NIST states in its federation guidance that “The details of authorization and access control are outside of the scope of these guidelines.” (NIST SP 800-63C)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How authentication differs from authorization

Task Question it answers What it does
Authentication Can the claimant demonstrate control of the claimed identity’s authenticator? Checks identity evidence through a defined process or message exchange.
Authorization (access control) May this subject perform this operation on this resource under the applicable policy? Evaluates permissions and determines whether to allow or deny the requested action.

NIST’s earlier SP 800-63-3 wording defines an authentication protocol as “A defined sequence of messages between a claimant and a verifier that demonstrates that the claimant has possession and control of one or more valid authenticators to establish their identity, and, optionally, demonstrates that the claimant is communicating with the intended verifier.” This is the definition from SP 800-63-3, not the wording of the current SP 800-63-4 series. (NIST SP 800-63-3)

In practice, successful authentication may be a prerequisite for requesting a protected action. A separate access-control policy still determines whether that action is permitted.

How common access-control terms differ

Term Role What it does not establish by itself
Authentication protocol Defines message exchanges used to demonstrate control of authenticators, and may help establish that the intended verifier is involved. Which operations the authenticated subject is allowed to perform.
ABAC An authorization method that evaluates attributes of the subject, resource (object), requested operation, and sometimes the environment against policy, rules, or relationships. A single message-exchange protocol or universal policy.
XACML 3.0 An OASIS specification for expressing and processing access-control policies, including decision and enforcement roles. The identity proof used to authenticate a claimant.
OAuth access token A token that can convey delegated application access to services on a subscriber’s behalf after an authentication event. A complete authorization policy for every resource and action.

NIST describes ABAC as authorization based on evaluating attributes against policy, rules, or relationships. This can make decisions responsive to context—for example, who is making a request, what resource is involved, which operation is requested, and relevant environmental conditions. (NIST SP 800-162)

XACML is a policy language and processing specification, rather than an authentication protocol. Its roles help distinguish a component that evaluates a request against policy from one that enforces the resulting decision. (OASIS XACML 3.0)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST gives OAuth access tokens as an example of tokens used to permit an application to access services on a subscriber’s behalf after authentication. That delegated-access role should not be confused with the full policy decision about every operation on every resource.

How to identify the right mechanism for a system

There is no single protocol prescribed for every access-control system. When evaluating a design, identify these separate choices:

  • Identity evidence: What authenticator or other evidence must a claimant demonstrate, and which authentication exchange is used?
  • Permission representation: Are permissions expressed as roles, attributes, relationships, or another policy form?
  • Decision inputs: Does the decision depend on the subject, resource, requested action, or changing environmental context?
  • Decision and enforcement: Which component evaluates the policy, and which component applies the allow-or-deny result?
  • Trust boundaries: What trust exists between the identity provider, policy decision component, application, and enforcement point?
  • Cloud service model: Which components are being protected in an IaaS, PaaS, or SaaS environment?

NIST’s cloud guidance notes that “Different service delivery models require managing different types of access on offered service components.” It discusses access across IaaS, PaaS, and SaaS, with service models arranged hierarchically; lower-level guidance may apply at higher levels, while each model retains its own focus. It does not prescribe one protocol for every cloud system. (NIST SP 800-210)

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to call it when precision matters

Use the specific name that matches the system’s role: an authentication protocol for the identity-verification message exchange, an authorization policy or access-control model for the permission rules, and a named specification such as XACML when discussing policy expression and processing. This avoids suggesting that one protocol alone authenticates users, defines permissions, and enforces every decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.