Access to protected resource is controlled by PAC and by an Access Control List (ACL) similar to the NPAC Grading System. |
PAC protection is provided by temporary secret cryptographic keys shared pairwise between the participants. |
SESAME supports Certification Authorities, X.509 Directory user certificates. |
SESAME supports delegation, i.e., an application act on user's behalf. |
SESAME security structure is explained at |
http://www.esat.kuleuven.ac.be/cosic/sesame/relat/ecma-219.ps.Z |