Implementing Granular Access Definitions in Log Records

Sandeep Jayashankar, Subin Thayyile Kandy · 2020

This document specifies a method of creation or generation of software logs that would further assist in building more granular access control definitions. The technique relies on including an authorization token within each log record, which is generated using a signed JSON Web Token (JWT). Each authorization token embeds all factual information that lets the log viewers set these access constraints, either using an external access control list or applying an access control list outlined in the log management platform.

Read the paper · More papers on PaperTik