MODEL-BASED ACCESS CONTROL
    3.
    发明申请
    MODEL-BASED ACCESS CONTROL 审中-公开
    基于模型的访问控制

    公开(公告)号:US20080244736A1

    公开(公告)日:2008-10-02

    申请号:US11694014

    申请日:2007-03-30

    IPC分类号: G06F12/14

    CPC分类号: G06F21/604 G06F21/6218

    摘要: Access control as it relates to policies or permissions is provided based on a created model. A security policy is abstracted and can be independent of a mechanism used to protect resources. An asbstract model of a potential user, user role and/or resource is created without associating a specific individual and/or resource with a model. These abstract user models and abstract resource models can be used across applications or within disparate applications. The abstracted security policies can be selectively applied to the model. Specific users and/or resources can be associated with one or more abstract user model or abstract resource model. The models can be nested to provide configurations for larger systems.

    摘要翻译: 基于创建的模型提供与策略或权限相关的访问控制。 安全策略被抽象出来,可以独立于用于保护资源的机制。 创建潜在用户,用户角色和/或资源的抽象模型,而不将特定个人和/或资源与模型相关联。 这些抽象用户模型和抽象资源模型可以跨应用程序或不同的应用程序使用。 抽象的安全策略可以选择性地应用于模型。 特定用户和/或资源可以与一个或多个抽象用户模型或抽象资源模型相关联。 这些型号可以嵌套,以提供更大系统的配置。

    Distributed knowledge access control
    7.
    发明申请
    Distributed knowledge access control 审中-公开
    分布式知识访问控制

    公开(公告)号:US20080301758A1

    公开(公告)日:2008-12-04

    申请号:US11809856

    申请日:2007-05-31

    IPC分类号: H04L9/00

    CPC分类号: G06F21/604

    摘要: Techniques for distributed knowledge access control are disclosed herein. These techniques may enable access control information to be provided in the form of a statement that includes an assertion and a construct that targets the assertion to one or more intended entities. By targeting the statement to intended entities, the construct may help protect resources from unauthorized use and may also help protect the issuer of the statement from accountability resulting from misuse of the statement.

    摘要翻译: 本文公开了用于分布式知识访问控制的技术。 这些技术可以使访问控制信息能够以声明的形式提供,该语句包括断言和针对一个或多个预期实体的断言的构造。 通过将该声明定位到预期实体,该构造可以帮助保护资源免遭未经授权的使用,并且还可以帮助保护声明的发行者不被滥用声明所导致的问题。

    Flexible licensing architecture in content rights management systems
    9.
    发明申请
    Flexible licensing architecture in content rights management systems 有权
    内容权限管理系统中灵活的许可架构

    公开(公告)号:US20060173788A1

    公开(公告)日:2006-08-03

    申请号:US11048087

    申请日:2005-02-01

    IPC分类号: H04L9/00

    CPC分类号: G06F21/10

    摘要: A license is issued to a user as decryption and authorization portions. The decryption portion is accessible only by such user and has a decryption key (KD) for decrypting corresponding encrypted digital content and validating information including an identification of a root trust authority. The authorization portion sets forth rights granted in connection with the digital content and conditions that must be satisfied to exercise the rights granted, and has a digital signature that is validated according to the identified root trust authority in the decryption portion. The user issued accesses the decryption portion and employs the validation information therein to validate the digital signature of the authorization portion. If the conditions in the authorization portion so allow, the rights in the authorization portion are exercised by decrypting the encrypted content with the decryption key (KD) from the decryption portion and rendering the decrypted content.

    摘要翻译: 向用户颁发许可证作为解密和授权部分。 解密部分仅由该用户访问,并且具有用于解密对应的加密数字内容的解密密钥(KD)以及验证包括根信任授权的标识的信息。 授权部分列出与数字内容和条件相关的权利,该数字内容和条件必须满足以行使所授予的权利,并且具有根据所述解密部分中确定的根信任权限验证的数字签名。 用户发出访问解密部分并在其中采用验证信息来验证授权部分的数字签名。 如果授权部分中的条件允许,则通过使用来自解密部分的解密密钥(KD)解密加密内容并呈现解密内容来执行授权部分中的权限。