Baruzzi, Giovanni A.Roßnagel, HeikoSchunck, Christian H.Mödersheim, SebastianHühnlein, Detlef2020-05-272020-05-272020978-3-88579-699-2https://dl.gi.de/handle/20.500.12116/33175A secure, scalable, fine grained and flexible access control is extremely important for the digital society. The approaches used until now (RBAC, Groups in an LDAP Directory, XACML) alone may not be able to deliver to this challenge. Building from past experiences in the Industry, we propose an Access Management Framework where the central role is played by a token containing all the information needed to implement fine grained access control. This Authorization Token should be signed by the approver and embedded into a “claim” to the application at session time. The application, after checking the validity of the token will control access to the desired resource. In this way we can achieve fine granular access control, scalability and independence from network topologies.enAccess ControlTokenFine-grained AccessAuthorizationClaim.Token Based AuthorizationText/Conference Paper10.18420/ois2020_161617-5468