Data source based application sandboxing
    1.
    发明授权
    Data source based application sandboxing 有权
    基于数据源的应用程序沙箱

    公开(公告)号:US09225727B2

    公开(公告)日:2015-12-29

    申请号:US13074136

    申请日:2011-03-29

    IPC分类号: G06F17/00 H04L29/06 G06F21/62

    摘要: A computing device and a method for a computing device to control access to data stored on a data store of the device. An access component of the device having control over access to the data. The access component being operative to receive a request for data from a requesting component, identify an assigned access domain of the requesting component and an assigned data domain of the requested data and determine whether the requesting component is authorized to access the data by comparing the assigned access domain and the data domain with permissions specified in a security policy. If the assigned access domain is authorized to access the data domain, the access component may provide access to the requested data.

    摘要翻译: 一种用于计算设备的计算设备和方法,用于控制对存储在设备的数据存储器上的数据的访问。 该设备的访问组件具有对数据访问的控制。 访问组件可操作以从请求组件接收对数据的请求,识别所分配的请求组件的接入域和所请求数据的分配的数据域,并且通过比较所分配的数据来确定请求组件是否被授权访问数据 访问域和具有在安全策略中指定的权限的数据域。 如果分配的访问域被授权访问数据域,则访问组件可以提供对所请求的数据的访问。

    DATA SOURCE BASED APPLICATION SANDBOXING
    2.
    发明申请
    DATA SOURCE BASED APPLICATION SANDBOXING 有权
    基于数据源的应用SANDBOXING

    公开(公告)号:US20120124640A1

    公开(公告)日:2012-05-17

    申请号:US13074136

    申请日:2011-03-29

    IPC分类号: G06F21/00

    摘要: A computing device and a method for a computing device to control access to data stored on a data store of the device. An access component of the device having control over access to the data. The access component being operative to receive a request for data from a requesting component, identify an assigned access domain of the requesting component and an assigned data domain of the requested data and determine whether the requesting component is authorized to access the data by comparing the assigned access domain and the data domain with permissions specified in a security policy. If the assigned access domain is authorized to access the data domain, the access component may provide access to the requested data.

    摘要翻译: 一种用于计算设备的计算设备和方法,用于控制对存储在设备的数据存储器上的数据的访问。 该设备的访问组件具有对数据访问的控制。 访问组件可操作以从请求组件接收对数据的请求,识别所分配的请求组件的接入域和所请求数据的分配的数据域,并且通过比较所分配的数据来确定请求组件是否被授权访问数据 访问域和具有在安全策略中指定的权限的数据域。 如果分配的访问域被授权访问数据域,则访问组件可以提供对所请求的数据的访问。