Policy inheritance through nested groups
    3.
    发明申请
    Policy inheritance through nested groups 有权
    通过嵌套组策略继承

    公开(公告)号:US20050097166A1

    公开(公告)日:2005-05-05

    申请号:US10962079

    申请日:2004-10-08

    CPC classification number: H04L63/20

    Abstract: A computer-implemented system and method for policy inheritance, comprising, defining a first group wherein the first group refers to at least one of: a user and a group different from the first group, defining a second group wherein the second group is nested within the first group, defining a first policy wherein the first policy includes a resource, a subject and one of, an action and a role, and wherein the subject includes the first group, inheriting the first policy by the second group, wherein the resource is part of a resource hierarchy, and wherein the first policy can be used to control access to the resource.

    Abstract translation: 一种用于策略继承的计算机实现的系统和方法,包括:定义第一组,其中所述第一组参考以下中的至少一个:与所述第一组不同的用户和组,定义第二组,其中所述第二组嵌套在 所述第一组定义第一策略,其中所述第一策略包括资源,主题以及动作和角色之一,并且其中所述对象包括所述第一组,由所述第二组继承所述第一策略,其中所述资源是 资源层次结构的一部分,并且其中第一策略可以用于控制对资源的访问。

    Distributed security system with security service providers
    6.
    发明申请
    Distributed security system with security service providers 审中-公开
    分布式安全系统与安全服务提供商

    公开(公告)号:US20050102535A1

    公开(公告)日:2005-05-12

    申请号:US10961351

    申请日:2004-10-08

    CPC classification number: G06F21/6218 H04L63/105 H04L63/20

    Abstract: A system and method distributed enterprise security, comprising, a security control module (SCM) operable to accept information, wherein the information include one or more of: a policy and configuration information at least one security service module (SSM) operable to accept the information from SCM at least one security service providers coupled to the at least one SSM, wherein the at least one security service providers is cable of at least one of, authentication of a user, determining if access to a resource is permitted based on the information, auditing of a security decision, and mapping an authenticated identity to a set of credentials to be used to authenticate a target resource, and wherein the information accepted by the SCM is relevant to one or more of the at least one SSMs.

    Abstract translation: 一种系统和方法分布式企业安全性,包括:可操作以接受信息的安全控制模块(SCM),其中所述信息包括以下各项中的一个或多个:策略和配置信息,至少一个安全服务模块(SSM),可操作以接受信息 所述至少一个安全服务提供者耦合到所述至少一个SSM,其中所述至少一个安全服务提供者是至少一个用户的认证,基于所述信息确定是否允许对资源的访问, 审核安全决策,以及将认证身份映射到要用于认证目标资源的一组凭证,并且其中由所述SCM接受的所述信息与所述至少一个SSM中的一个或多个相关。

    Distributed enterprise security system for a resource hierarchy
    7.
    发明申请
    Distributed enterprise security system for a resource hierarchy 审中-公开
    用于资源层次结构的分布式企业安全系统

    公开(公告)号:US20050102401A1

    公开(公告)日:2005-05-12

    申请号:US10961677

    申请日:2004-10-08

    CPC classification number: G06F21/6218 H04L63/105 H04L63/20

    Abstract: A system and method for a distributed system for controlling access to a first resource in a hierarchy of resources, comprising, a distributor located on a first server and capable of distributing to a second server a first policy for the first resource, a security service module (SSM) located on the second server and capable of managing based on the first policy conditions for access to at least one of: the first resource and a second resource that is hierarchically inferior to the first resource, and wherein the first policy can be overridden by a second policy wherein the second policy specifies conditions for access for a resource that is hierarchically inferior to the first resource.

    Abstract translation: 一种用于控制对资源层级中的第一资源的访问的分布式系统的系统和方法,包括位于第一服务器上并且能够向第二服务器分发第一资源的第一策略的分发器,安全服务模块 (SSM),其能够基于所述第一策略条件来管理以访问以下中的至少一个:所述第一资源和所述第一资源分级地劣于所述第一资源的第二资源,并且其中所述第一策略可以被重写 通过第二策略,其中所述第二策略指定对于与所述第一资源分级地劣化的资源的访问条件。

    Policy inheritance through nested groups
    9.
    发明授权
    Policy inheritance through nested groups 有权
    通过嵌套组策略继承

    公开(公告)号:US07644432B2

    公开(公告)日:2010-01-05

    申请号:US10962079

    申请日:2004-10-08

    CPC classification number: H04L63/20

    Abstract: A computer-implemented system and method for policy inheritance, comprising, defining a first group wherein the first group refers to at least one of: a user and a group different from the first group, defining a second group wherein the second group is nested within the first group, defining a first policy wherein the first policy includes a resource, a subject and one of, an action and a role, and wherein the subject includes the first group, inheriting the first policy by the second group, wherein the resource is part of a resource hierarchy, and wherein the first policy can be used to control access to the resource.

    Abstract translation: 一种用于策略继承的计算机实现的系统和方法,包括:定义第一组,其中所述第一组参考以下中的至少一个:与所述第一组不同的用户和组,定义第二组,其中所述第二组嵌套在 所述第一组定义第一策略,其中所述第一策略包括资源,主题以及动作和角色之一,并且其中所述对象包括所述第一组,由所述第二组继承所述第一策略,其中所述资源是 资源层次结构的一部分,并且其中第一策略可以用于控制对资源的访问。

    Security control module
    10.
    发明授权
    Security control module 有权
    安全控制模块

    公开(公告)号:US07603547B2

    公开(公告)日:2009-10-13

    申请号:US10961674

    申请日:2004-10-08

    CPC classification number: G06F21/6218 H04L63/105 H04L63/20

    Abstract: A system for distributing information from a first process to one or more security service modules. The system comprises a remote interface, capable of accepting first information from the first process, and a provisioning service provider (PSP) coupled to the remote interface. The PSP can obtain the first information from the remote interface, and also can provide second information to a local interface. The second information is based on the first information and is tailored for the one or more security service modules. The local interface can provide the second information to the one or more security service modules and the one or more security service modules can accept the second information and perform at least one of the following: adjust a configuration of the one or more security service modules to reflect the second information, and protect access to at least one resource based on the second information.

    Abstract translation: 一种用于将信息从第一进程分发到一个或多个安全服务模块的系统。 该系统包括能够接收来自第一进程的第一信息的远程接口和耦合到远程接口的供应服务提供商(PSP)。 PSP可以从远程接口获取第一条信息,并且可以向本地接口提供第二条信息。 第二信息基于第一信息,并针对一个或多个安全服务模块量身定制。 所述本地接口可以向所述一个或多个安全服务模块提供所述第二信息,并且所述一个或多个安全服务模块可以接受所述第二信息并且执行以下中的至少一个:将所述一个或多个安全服务模块的配置调整为 反映第二信息,并且基于第二信息保护对至少一个资源的访问。

Patent Agency Ranking