发明授权
US07752439B2 Method and apparatus for providing process-based access controls on computer resources
失效
用于在计算机资源上提供基于过程的访问控制的方法和装置
- 专利标题: Method and apparatus for providing process-based access controls on computer resources
- 专利标题(中): 用于在计算机资源上提供基于过程的访问控制的方法和装置
-
申请号: US12025867申请日: 2008-02-05
-
公开(公告)号: US07752439B2公开(公告)日: 2010-07-06
- 发明人: Mounir Emil Basibes , Julianne Frances Haugh
- 申请人: Mounir Emil Basibes , Julianne Frances Haugh
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Yee & Associates, P.C.
- 代理商 Matthew W. Baca
- 主分类号: H04L9/00
- IPC分类号: H04L9/00 ; G06F21/00
摘要:
A method, apparatus, and computer instructions for process-based access controls on computer resources to processes. An access mechanism is provided in which a specific invoker obtains an object access identity (ACI). Another mechanism is provided in which a specific object, such as a file system resource, requires a specific object access identity to obtain one of the forms of access denoted by an access control list. A process may “grant” an identifier that is later “required” for a system resource access. Objects may specify their own access requirements and permitted access modes. The granted identifier, ACI, is stored in the process's credentials once these credentials match a specific “grant” entry in the access control list. This identifier has no meaning outside of being used to make an access decision for a specific resource. When a process tries to access the object, the object's access control list is scanned for “required” entries. If a match occurs between the “required” entry's identifier and the ACI stored, access to the object is granted with access rights specified in the “require” entries.
公开/授权文献
信息查询