SYSTEM AND METHOD OF INTEGRATING MODULES FOR EXECUTION ON A COMPUTING DEVICE AND CONTROLLING DURING RUNTIME AN ABILITY OF A FIRST MODULE TO ACCESS A SERVICE PROVIDED BY A SECOND MODULE
    15.
    发明申请
    SYSTEM AND METHOD OF INTEGRATING MODULES FOR EXECUTION ON A COMPUTING DEVICE AND CONTROLLING DURING RUNTIME AN ABILITY OF A FIRST MODULE TO ACCESS A SERVICE PROVIDED BY A SECOND MODULE 有权
    用于在计算机设备上执行的模块的集成和在运行期间的控制的第一模块访问由第二模块提供的服务的能力的系统和方法

    公开(公告)号:US20140053282A1

    公开(公告)日:2014-02-20

    申请号:US14063172

    申请日:2013-10-25

    Inventor: Gary R. Court

    Abstract: A system for integrating modules of computer code may include a sandbox validator for receiving a first module and verifying that the first module complies with one or more sandbox constraints. A computing device may execute the first module within a runtime environment. A module integrator may operate within the runtime environment for receiving a request from the first module to access a service provided by a second module and only allowing the first module to access the service when the first module is authorized to access the service according to a service authorization table. The sandbox validator may ensure the first module correctly identifies itself when requesting a service provide by another module and that the first module includes runtime policing functions for non-deterministic operations. A service authorizer may generate an authorization policy for the first module, which is sent to the computing device along with the first module.

    Abstract translation: 用于集成计算机代码的模块的系统可以包括用于接收第一模块并验证第一模块符合一个或多个沙箱限制的沙盒验证器。 计算设备可以在运行时环境内执行第一模块。 模块集成器可以在运行时环境内运行,用于接收来自第一模块的访问由第二模块提供的服务的请求,并且仅当第一模块被授权根据服务访问服务时允许第一模块访问服务 授权表。 沙箱验证器可以确保第一模块在请求由另一个模块提供的服务时正确地识别自身,并且第一模块包括用于非确定性操作的运行时监管功能。 服务授权器可以为第一模块生成授权策略,该授权策略与第一模块一起被发送到计算设备。

    ALLOWING FIRST MODULE OF COMPUTER CODE TO MAKE USE OF SERVICE PROVIDED BY SECOND MODULE WHILE ENSURING SECURITY OF SYSTEM
    20.
    发明申请
    ALLOWING FIRST MODULE OF COMPUTER CODE TO MAKE USE OF SERVICE PROVIDED BY SECOND MODULE WHILE ENSURING SECURITY OF SYSTEM 有权
    使用计算机代码的第一个模块来实现第二个模块在保证系统安全的情况下提供的服务

    公开(公告)号:US20170034180A1

    公开(公告)日:2017-02-02

    申请号:US15290791

    申请日:2016-10-11

    Inventor: Gary R. Court

    Abstract: A system for integrating modules of computer code may include a sandbox validator for receiving a first module and verifying that the first module complies with one or more sandbox constraints. A computing device may execute the first module within a runtime environment. A module integrator may operate within the runtime environment for receiving a request from the first module to access a service provided by a second module and only allowing the first module to access the service when the first module is authorized to access the service according to a service authorization table. The sandbox validator may ensure the first module correctly identifies itself when requesting a service provide by another module and that the first module includes runtime policing functions for non-deterministic operations. A service authorizer may generate an authorization policy for the first module, which is sent to the computing device along with the first module.

    Abstract translation: 用于集成计算机代码的模块的系统可以包括用于接收第一模块并验证第一模块符合一个或多个沙箱限制的沙盒验证器。 计算设备可以在运行时环境内执行第一模块。 模块集成器可以在运行时环境内运行,用于接收来自第一模块的访问由第二模块提供的服务的请求,并且仅当第一模块被授权根据服务访问服务时允许第一模块访问服务 授权表。 沙箱验证器可以确保第一模块在请求由另一个模块提供的服务时正确地识别自身,并且第一模块包括用于非确定性操作的运行时监管功能。 服务授权器可以为第一模块生成授权策略,该授权策略与第一模块一起被发送到计算设备。

Patent Agency Ranking