Announcement of a special issue of Code of Architecture about authorization on the ReBAC model (aka Google Zanzibar)
In last Discussion of a Distributed System Book n (Distributed Systems) We talked about security issues and briefly discussed authorization. It seemed to us that the authors of the book missed a rather important model called ReBAC (Relationship-Based Access Control). The popularity of this model came after Google 2019 I published a white paper this year.Zanzibar: Google’s Consistent, Global Authorization System" In this paper, the authors talked about how to configure the authorization model, how to express relationships in the form of triplets and how to actually check the presence or absence of rights. It should be noted separately that with 2019 Several companies have made commercial and open source implementations of this model. SpiceDBThis allows people to use this approach in their projects. As a result, in this issue we will talk about the problems of authorization in more depth and further discuss the model. ReBACImmersed in a white paper about Zanzibar and a bit of an open source implementation. SpiceDB.
There will be two guests in the show: Sergey Klimenko is the head of the department responsible for authentication and authorization in Tinkoff, in particular, the Tinkoff ID service, and also deals with the development of the ecosystem Daniil Kuleshov, architect of a new authorization system for Tinkoff clients
Connect on Monday. 20 March 18:00 in Moscow for the broadcast on YouTube-channel IT's Tinkoff.
#CoA #SystemDesign #DistributedSystems #Authz #WhitePaper