We present an integrated secure group access control tool to support workgroups on the World-Wide Web. The system enables user authentication, encrypted communication and fine-grained group access control. The tool comprises two proxies: one running on the server side and the other one on the client side. Typically the browser sends a query to the client side proxy which contacts the server side proxy for authentication, session key exchange and checking of access rights. The server side proxy finally forwards the request to the HTTP server. Our tool is completely transparent to the user and compatible with any Web server and browser. It can also become part of a firewall configuration.
Fabien A. P. Petitcolas, Kan Zhang