Patent attributes
One embodiment of the present invention provides a system for distributing an access control service to local nodes. During operation, the system receives, at a node in a network, a policy file comprising access policies for resources in the network, wherein the access policies are associated with attributes of profiles, and wherein the profiles are associated with clients. Next, the system compiles, at the node, the policy file into an optimized data structure. Finally, the system stores, at the node, the optimized data structure in memory to facilitate subsequent local lookups of permissions associated with the attributes and the resources.