Our State of Authorization: AI Edition is now available Get it now »

Performance can make or break an authorization project. Here’s why.

Learn how the three pillars of performance helps you deploy with confidence and with compliance and user experience in mind.

Authorization is not just about access control; it’s about performance. In fact, performance is a critical component of your entire access strategy, and something every organization must tailor to its unique needs. Performance isn’t just a single variable, but an equation involving different factors that must be carefully balanced and tuned.

But before we jump into performance, let’s first align specifically on what we are measuring as “authorization” can mean different things to different audiences.

For the purposes of this article, let’s look at performance through the lens of runtime authorization with an externalized architecture. With this design pattern, the focus is on dynamically managing access control—whether for a user or a machine – for an identity seeking access to a specific resource, such as an application. Within this application, there are layers upon layers of access, from conditional access to the application itself down to accessing specific pages and data within those pages.

At the heart of this system is the policy enforcement point (PEP), which could take the form of an API, an API gateway, a microservice, or a service mesh. The PEP is responsible for sending user or machine information to the policy decision point (PDP) and receiving a response, which could be a permit, deny, or advice with obligations.

The PDP plays a pivotal role in evaluating what actions a user or machine can perform based on established policies and dynamic attributes within the organization. These attributes provide the context needed to make accurate decisions at the right time.

The three pillars of performance

With authorization central to access, speed of access is critical. Whether it is an employee (or machine) requiring access to information to get a job done, or a customer requesting access to their personal information, the expectation is wirespeed performance.

To meet the expectation of millisecond response times, you must focus on three key areas:

1. Policy Decision Point (PDP)

The PDP must be capable of processing thousands of authorization decisions per second per core. It’s essential that your PDP aligns with your performance expectations and is built on reliable standards.

2. Policy Structure

Policies can be structured flatly or hierarchically. A hierarchical structure allows for quicker decision-making as it avoids evaluating every policy for each decision. This is particularly beneficial for enterprises with complex rules and compliance requirements.

3. Attribute Management

Attributes are the details about users or machines that inform the PDP’s decisions. Efficient attribute management, often achieved through caching, ensures the PDP can quickly access necessary information without constant queries to the attribute source.

Authorization performance pitfalls

When evaluating performance for any architecture, there are a number of considerations including latency and fault tolerance that if improperly implemented lead to poor performance.

However, when it comes to authorization, here are some specific pitfalls to consider:

  1. QA does not reflect production infrastructure: Because a key consideration for performance is attribute location, if the testing infrastructure fails to properly reflect production’s setup, you may be setting incorrect performance expectations with stakeholders. As a result, do everything you can to have your QA environment mimic production infrastructure including the location of attribute sources as well as security policies.
  2. Unnecessary policy complexity: Building complex policies is actually easy to do. Building complex policies that are still performant requires focus and dedication to continuously evaluating whether a particular rule or check is required. While making policies hierarchical is a great first step, challenging complexity is critical to achieving great performance.
  3. “Big bang” deployments: Though software best practices clearly state that this is not a good approach in general; big bang deployments will not bode well for authorization performance. In contrast, think of deployments more like a hockey stick that will see a gradual ramp as you dial in your key performance variables (policies, attributes and infrastructure).

What’s next?

A well-structured authorization strategy is key to achieving high performance. By focusing on the PDP, policy structure, and attribute management, organizations can ensure a seamless and secure user experience.

Want to know more? Check out these additional articles:

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About Axiomatics

The world’s largest enterprises and government agencies continually depend on Axiomatics’ award-winning authorization platform to share sensitive, valuable and regulated digital assets – but only to authorized users and in the right context.