This paper presents the results of a survey of requirements for attribute aggregation in authorisation systems, gathered from an international community of security professionals. It then analyses these requirements against 4 generic models for attribute aggregation and makes some recommendations for future implementations.
David W. Chadwick