Macaroons¶
Birgisson, A., Politz, J. G., Erlingsson, Ú., Taly, A., Vrable, M., & Lentczner, M. (2014). Macaroons: Cookies with Contextual Caveats for Decentralized Authorization in the Cloud. Network and Distributed System Security Symposium.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Signed Delegation Token
- Contained, short-lived, narrowly-scoped tokens turn "trust the calling service" into "verify the caller's authorization," and designs like macaroons show scopes can even be attenuated — narrowed but never widened — as the token is passed along.
This sourceMacaroons use chained caveats to delegate authorization while adding contextual, temporal, and purpose restrictions that attenuate authority.
- Contained, short-lived, narrowly-scoped tokens turn "trust the calling service" into "verify the caller's authorization," and designs like macaroons show scopes can even be attenuated — narrowed but never widened — as the token is passed along.
Verification¶
Does it exist? Confirmed. This work's DOI resolves to a registered record, which fixes its identity. That is all it fixes.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Was it audited? Yes. A second, independent pass read the citation against the article text and recorded a verdict.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:139adde4cb61 · see in the full table