Cryptographically enforced, multiple-role, policy-enabled object dissemination control mechanism
    2.
    发明申请
    Cryptographically enforced, multiple-role, policy-enabled object dissemination control mechanism 有权
    密码执法,多角色,有策略的对象传播控制机制

    公开(公告)号:US20050193196A1

    公开(公告)日:2005-09-01

    申请号:US10788151

    申请日:2004-02-26

    IPC分类号: G06F21/00 H04L9/00

    CPC分类号: G06F21/6218

    摘要: An apparatus to implement role based access control which reduces administrative expenses associated with managing access in accordance with policies and roles. The apparatus includes a memory storing a first role based access control condition associated with an action and a subsystem executing an enforcement entity and a decision entity. In one preferred form, the two entities are independent entities. The enforcement entity receives a request for the action from a requestor with a role. Additionally, the enforcement entity communicates the role and the request to the decision entity for the decision entity's decision of whether the role satisfies the first condition. The decision entity then communicates the decision to the enforcement entity. Accordingly, the enforcement entity allows or denies the requestor the action based on the decision made by the decision entity.

    摘要翻译: 实现基于角色的访问控制的装置,其减少与根据策略和角色管理访问相关联的管理费用。 该装置包括存储与动作相关联的第一基于角色的访问控制条件的存储器和执行执行实体和决策实体的子系统。 在一个优选形式中,两个实体是独立实体。 执行实体从具有角色的请求者接收到该操作的请求。 此外,执行实体将角色和请求传达给决策实体,以便决策实体决定角色是否满足第一个条件。 决策实体然后将决定传达给执行实体。 因此,执行实体根据决策实体作出的决定允许或拒绝请求者采取行动。