Skip to content
Open access

Two-Point Authorization Engine with Revocable Sharing for Multitenant Environments

Aug 2026 · Information Technologies and Systems (Інформаційні технології та системи) · 0 citations · 21 references

TL;DR

The access-kit is presented, an in-process authorization engine for the .NET platform built on an explicit model: principals, “area:verb” actions, composable deny-wins policy statements with inheritance, and a resource hierarchy, and an analytic cost model and an evaluation measured on PostgreSQL.

Abstract

Multi-tenant software-as-a-service (SaaS) platforms that contain tenant-partitioned data require authorization systems which cover scenarios where classic flat role-based access control (RBAC) fails. Specifically, these systems need to provide access to individual resources rather than whole sets of resources, controlled cross-tenant sharing, and account-less share links which can be revoked at any time. We present access-kit, an in-process authorization engine for the .NET platform built on an explicit model: principals, “area:verb” actions, composable deny-wins policy statements with inheritance, and a resource hierarchy. Enforcement is a co-designed pair of mechanisms which consist of an application-pipeline gate that rejects unauthorized actions outright and an object-relational mapper (ORM) row filter that filters the data to only include rows which are permitted to the current principal. The gate publishes per-request scope which is consumed by row filter, and this scope keeps the two mechanisms in agreement and therefore keeping error reporting consistent. As a result, a write on a readable-but-not-writable resource is refused as a forbidden action rather than disguised as a missing resource, preventing the existence of the resource from being leaked. In the developed framework, each request acts in a single active tenant, so access resolves to one flat statement set. Cross-tenant access is achieved by pulling the grants the active tenant owns, and a caller switches workspace (re-minting its token) to act in another permitted tenant. Account-less sharing is implemented by issuing a revocable, table-backed capability token. We give an analytic cost model and an evaluation measured on PostgreSQL: a batch chain-walk resolves effective access in a number of database round trips that is independent of how many grants a principal holds, and we compare it with a naive baseline and a single-query recursive-CTE alternative. The per-request cost is dominated by this resolution, while the in-memory gate adds negligible overhead; the cost model and measurements are given in Section 5. The engine is implemented as a generalized reference implementation with adapters for Entity Framework Core, MediatR, and ASP.NET Core.

Read PDF

Similar papers

#artificial intelligence Review Sep 2026

Zero-Trust Authorization and Discovery for Enterprise MCP

LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain effective even when an agent is prompt-injected or adversarially steered. The Model Context Protocol (MCP) has become a widely adopted interface for this boundary, yet its...

Huang-Jian Li, Yu-Wei Wang, Srinivasan Manoharan · 1 citation
#large language models Open access Sep 2026

ARES: Securing Agents for Computer Use Through Endpoint Resource Mediation and Behavioral Guardrails

Large language model (LLM)-based agents are evolving into agents for computer use (ACUs) that read files, invoke applications, communicate over networks, and operate graphical interfaces, moving the effective security boundary from model inputs and outputs to autonomous actions that alter endpoint state. Conventional i...

Changhee Kim, Seong-je Cho · 0 citations
Preprint Sep 2026

SADRA: Sound Capability-based Access Control System for Resource-Disaggregated Architectures

Resource disaggregation separates memory and accelerators from compute nodes and makes them remotely accessible. This improves resource sharing, but also removes the local kernel from the resource-access path. Under an untrusted host, compromised host software may use stale authority, exceed delegated authority, or reu...

H. Rasifard, Amirabbas Khojasteh, Hamed Nemati et al. · 0 citations
Open access Aug 2026

Q-LEASE: Lifecycle-bound zero-trust authorization for HPC-to-QPU job handoffs

Background Zero-Trust access control for cloud APIs is well established, but hybrid High-Performance Computing (HPC)-to-Quantum Processing Unit (QPU) workflows have a lifecycle existing mechanisms were not built for: a job queues for minutes to days, is dispatched, executes, and only then releases results, while identi...

Fouad Ailabouni, Jesús-Ángel Román-Gallego · 0 citations
Preprint Sep 2026

Verifiable Computation with Trusted Execution Environments and On-Chain Digital Rights Tokens

We present an architecture that enables data owners to combine private data into data pools using Trusted Execution Environments (TEEs) and manage these pools by issuing narrowly scoped computational rights, encoded as Digital Rights Tokens (DRTs), to third-party data analysts. Each DRT binds specific open-source code...

B. Kruger, Co-Pierre Georg · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.