What is the architecture of DACS like?
The architecture of DACS reflects the observation that an effective security system must be powerful but also as simple as possible. For organizations and their system administrators to have confidence in a security system, they must understand how it works and have confidence in it. It is said that complexity is the enemy of security. Towards this end, the DACS architecture and implementation use mature, conservative, and standard technologies and algorithms. For instance, very simple XML documents are used for communication between DACS components. Most DACS web services are REST-oriented, meaning that they are easy to call from a browser or script. Rather than dictating policies, DACS’s goal is to provide secure, flexible, extensible, and highly available mechanisms. These mechanisms are themselves invoked as web services and allow each jurisdiction in a federation to determine its own authentication and access control policies. A DACS federation has a central, administrative author