发明授权
- 专利标题: Data access security
- 专利标题(中): 数据访问安全
-
申请号: US13525105申请日: 2012-06-15
-
公开(公告)号: US08788845B1公开(公告)日: 2014-07-22
- 发明人: Sourabh Satish
- 申请人: Sourabh Satish
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: Fenwick & West LLP
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; G06F21/54 ; G06F21/62 ; H04L9/32
摘要:
An execution environment of a computer computes an initial effective permissions set for managed code based on user identity evidence, code evidence and/or a security policy and executes the code with this permissions set. If the managed code requests a data access, the execution environment considers data evidence that indicates the trustworthiness of the requested data. The data evidence can be based on the source of the data, the location of the data, the content of the data itself, or other factors. The execution environment computes a new effective permissions set for the managed code based on the data evidence and the security policy. This new effective permissions set is applied to the managed code while the code accesses the data. The execution environment restores the initial permissions set once the managed code completes the data access.
信息查询