AUTHORIZATION POLICY ANALYSIS
    2.
    发明公开

    公开(公告)号:US20240179188A1

    公开(公告)日:2024-05-30

    申请号:US18070371

    申请日:2022-11-28

    CPC classification number: H04L63/205 H04L63/104

    Abstract: A system and method for authorization policy analysis. A policy analyzer answers first-order questions about authorization policies by reducing the policies to Satisfiability modulo theories (SMT). Input to the analyzer includes a policy to be analyzed and a schema for that policy. If the policy passes strict validation against the schema, then the analyzer symbolically evaluates the policy to encode its semantics as an SMT expression. The SMT expression is used for formulate a desired query about policy behavior such as, for example, if there is any input on which two policies both evaluate to true. The reduction to SMT produces a quantifier-free formula in a combination of decidable theories to support large scale deployments. This reduction is achieved by focusing the analysis on policies that pass strict validation, rather than attempting to analyze arbitrary policies.

Patent Agency Ranking