Distributed knowledge access control
    13.
    发明申请
    Distributed knowledge access control 审中-公开
    分布式知识访问控制

    公开(公告)号:US20080301758A1

    公开(公告)日:2008-12-04

    申请号:US11809856

    申请日:2007-05-31

    IPC分类号: H04L9/00

    CPC分类号: G06F21/604

    摘要: Techniques for distributed knowledge access control are disclosed herein. These techniques may enable access control information to be provided in the form of a statement that includes an assertion and a construct that targets the assertion to one or more intended entities. By targeting the statement to intended entities, the construct may help protect resources from unauthorized use and may also help protect the issuer of the statement from accountability resulting from misuse of the statement.

    摘要翻译: 本文公开了用于分布式知识访问控制的技术。 这些技术可以使访问控制信息能够以声明的形式提供,该语句包括断言和针对一个或多个预期实体的断言的构造。 通过将该声明定位到预期实体,该构造可以帮助保护资源免遭未经授权的使用,并且还可以帮助保护声明的发行者不被滥用声明所导致的问题。

    Translating role-based access control policy to resource authorization policy
    14.
    发明申请
    Translating role-based access control policy to resource authorization policy 有权
    将基于角色的访问控制策略转换为资源授权策略

    公开(公告)号:US20070283443A1

    公开(公告)日:2007-12-06

    申请号:US11443638

    申请日:2006-05-30

    CPC分类号: G06F21/6218

    摘要: Translation of role-based authoring models for managing RBAC “roles” to resource authorization policy (RAP), such as ACL-based applications, is provided. A generic RBAC system is defined from which mappings to other authorization enforcement mechanism make possible the translation of RBAC “roles” to resource authorization policies applied to resources managed by a resource manager, e.g., a file system resource manager. An implementation is described that uses Windows Authorization Manager as a storage mechanism and object model to manage object types and relationships translated from an RBAC system.

    摘要翻译: 提供了基于角色的创作模式,用于将RBAC“角色”转换为资源授权策略(RAP),如基于ACL的应用程序。 定义了一个通用的RBAC系统,其中与其他授权执行机制的映射使RBAC“角色”能够应用于资源管理器(例如,文件系统资源管理器)管理的资源的资源授权策略成为可能。 描述了使用Windows Authorization Manager作为存储机制和对象模型来管理从RBAC系统转换的对象类型和关系的实现。