Authentication and Authorization

Authentication: reference monitor verifies the identity of the principal making the request.

Authorization: reference monitor decides whether access is granted or denied.