Local Versus Remote Optimization in Encrypted Query Processing
    2.
    发明申请
    Local Versus Remote Optimization in Encrypted Query Processing 审中-公开
    本地与加密查询处理中的远程优化

    公开(公告)号:US20150039586A1

    公开(公告)日:2015-02-05

    申请号:US13955691

    申请日:2013-07-31

    IPC分类号: G06F17/30

    CPC分类号: G06F17/30463

    摘要: Methods, systems, and computer-readable storage media for optimizing query processing in encrypted databases. In some implementations, actions include receiving a query that is to be used to query an encrypted database, generating a plurality of query plans based on the query, each query plan including a local query and one or more remote queries, the local query being executable at a client-side and the one or more remote queries being executable at a server-side, selecting an optimal query plan from the plurality of query plans, providing one or more remote queries of the optimal query plan to the server-side for execution, receiving one or more remote results, and processing a local query of the optimal query plan and the one or more remote results to provide a final query result.

    摘要翻译: 用于优化加密数据库中查询处理的方法,系统和计算机可读存储介质。 在一些实现中,动作包括接收用于查询加密数据库的查询,基于查询生成多个查询计划,每个查询计划包括本地查询和一个或多个远程查询,本地查询是可执行的 在客户端,并且所述一个或多个远程查询可在服务器端执行,从所述多个查询计划中选择最佳查询计划,向所述服务器端提供所述最佳查询计划的一个或多个远程查询用于执行 接收一个或多个远程结果,以及处理最佳查询计划的本地查询和一个或多个远程结果以提供最终查询结果。

    Real-time Provisioning of Actuarial Data
    3.
    发明申请
    Real-time Provisioning of Actuarial Data 审中-公开
    实时提供精算数据

    公开(公告)号:US20140081671A1

    公开(公告)日:2014-03-20

    申请号:US13618998

    申请日:2012-09-14

    申请人: Andreas Schaad

    发明人: Andreas Schaad

    IPC分类号: G06Q40/08

    CPC分类号: G06Q40/08

    摘要: Implementations of the present disclosure include methods, systems, and computer-readable storage mediums for providing insurance information for one or more platforms, each platform hosting at least one computer-implemented service. Implementations include actions of identifying one or more risks associated with the at least one computer-implemented service, identifying one or more mitigation mechanisms associated with at least one risk of the one or more risks, providing actuarial data based on the one or more mitigations mechanisms and the at least one risk, transmitting the actuarial data to one or more insurance providers, and receiving insurance premium data, the insurance premium data being provided based on the actuarial data.

    摘要翻译: 本公开的实现包括用于为一个或多个平台提供保险信息的方法,系统和计算机可读存储介质,每个平台承载至少一个计算机实现的服务。 实施包括确定与所述至少一个计算机实现的服务相关联的一个或多个风险的动作,识别与所述一个或多个风险的至少一个风险相关联的一个或多个缓解机制,基于所述一个或多个缓解机制提供精算数据 以及至少一个风险,将精算数据传送给一个或多个保险提供者,并接收保险费数据,该保险费数据是根据精算数据提供的。

    PARTIAL AND RISK-BASED DATA FLOW CONTROL IN CLOUD ENVIRONMENTS
    4.
    发明申请
    PARTIAL AND RISK-BASED DATA FLOW CONTROL IN CLOUD ENVIRONMENTS 审中-公开
    云环境中的部分和基于风险的数据流控制

    公开(公告)号:US20140068696A1

    公开(公告)日:2014-03-06

    申请号:US13598916

    申请日:2012-08-30

    申请人: Andreas Schaad

    发明人: Andreas Schaad

    IPC分类号: G06F21/00 G06F15/16

    CPC分类号: G06F9/54 H04L63/10

    摘要: Implementations of the present disclosure include methods, systems, and computer-readable storage mediums for risk-based data flow control in a cloud environment. Implementations include actions of intercepting first data transmitted from a first application to a second application before receipt of the first data at the second application, the first application and the second application being hosted within the cloud environment, processing the first data to provide a first risk factor, the first risk factor reflecting a degree of risk if the first data is received by the second application, generating first sanitized data based on the first data, the first risk factor and a first access control policy associated with the first data and transmitting the first sanitized data to the second application.

    摘要翻译: 本公开的实现包括用于云环境中用于基于风险的数据流控制的方法,系统和计算机可读存储介质。 实现包括在第二应用接收到第一数据之前拦截从第一应用发送到第二应用的第一数据的动作,第一应用和第二应用被托管在云环境内,处理第一数据以提供第一风险 因素,如果第二应用接收到第一数据,则反映一定程度的风险的第一风险因素,基于与第一数据相关联的第一数据,第一风险因子和第一访问控制策略生成第一消毒数据并发送 首先将数据清理到第二个应用程序。

    Access control system, a rule engine adaptor, a rule-based enforcement platform and a method for performing access control
    5.
    发明申请
    Access control system, a rule engine adaptor, a rule-based enforcement platform and a method for performing access control 有权
    访问控制系统,规则引擎适配器,基于规则的执行平台和执行访问控制的方法

    公开(公告)号:US20070203881A1

    公开(公告)日:2007-08-30

    申请号:US11712280

    申请日:2007-02-27

    IPC分类号: G06F17/30

    摘要: An access control system provides access control to at least one information resource associated with at least one application within a computer network. The system comprises a plurality of context sources being relevant for the at least one application and providing context information, a constraint specification console providing an interface to specify application specific constraints based on the context sources, a rule engine capable of handling facts and applying inference rules on those facts, an application specific constraint enforcement point configured for receiving access requests, hence querying facts and further being responsible for making access decisions regarding the information resource based on those facts and on application specific constraints and a rule engine adaptor acting as intermediary in communication of the rule engine with the context sources, the constraint specification console and the enforcement point, respectively, so as to allow access control to the at least one information resource based on specified application specific constraints with regard to context information originating from the context sources.

    摘要翻译: 访问控制系统向与计算机网络内的至少一个应用相关联的至少一个信息资源提供访问控制。 所述系统包括与所述至少一个应用程序相关的多个上下文源并提供上下文信息,约束规范控制台,其提供基于上下文源指定应用特定约束的接口,能够处理事实并应用推理规则的规则引擎 根据这些事实,配置用于接收访问请求的应用程序特定的约束执行点,从而根据这些事实和应用程序特定的约束来查询事实并进一步负责关于信息资源的访问决定,以及充当通信中介的规则引擎适配器 规则引擎分别与上下文源,约束规范控制台和执行点相关联,以便允许基于从上下文引发的上下文信息的指定应用特定约束对至少一个信息资源进行访问控制 小便

    Automatically generate attributes and access policies for securely processing outsourced audit data using attribute-based encryption
    8.
    发明授权
    Automatically generate attributes and access policies for securely processing outsourced audit data using attribute-based encryption 有权
    自动生成属性和访问策略,以使用基于属性的加密来安全地处理外包的审计数据

    公开(公告)号:US09495545B2

    公开(公告)日:2016-11-15

    申请号:US14540205

    申请日:2014-11-13

    申请人: Andreas Schaad

    发明人: Andreas Schaad

    摘要: Methods, systems, and computer-readable storage media for secure storage of and selective access to encrypted audit data. Implementations include actions of receiving a set of audit data in response to occurrence of an incident, determining a set of static audit data and a set of dynamic audit data based on the set of audit data, encrypting items in the set of static audit data using a first attribute-based encryption scheme to provide a set of encrypted static audit data, and items in the set of dynamic audit data using a second attribute-based encryption scheme to provide a set of encrypted dynamic audit data, and transmitting the set of encrypted static audit data and the set of encrypted dynamic audit data to an off-premise database for storage and selective access.

    摘要翻译: 用于安全存储和选择性访问加密审核数据的方法,系统和计算机可读存储介质。 实施包括响应于事件发生而接收一组审计数据的操作,基于该组审计数据确定一组静态审计数据和一组动态审计数据,使用该集合的静态审计数据加密项目 第一基于属性的加密方案,用于提供一组加密的静态审核数据,以及使用第二基于属性的加密方案来提供一组加密的动态审核数据的动态审核数据集中的项目,以及发送加密的 静态审核数据和一组加密的动态审核数据到外部数据库进行存储和选择性访问。

    AUTOMATICALLY GENERATE ATTRIBUTES AND ACCESS POLICIES FOR SECURELY PROCESSING OUTSOURCED AUDIT DATA USING ATTRIBUTE-BASED ENCRYPTION
    9.
    发明申请
    AUTOMATICALLY GENERATE ATTRIBUTES AND ACCESS POLICIES FOR SECURELY PROCESSING OUTSOURCED AUDIT DATA USING ATTRIBUTE-BASED ENCRYPTION 有权
    使用基于属性的加密自动生成属性和访问策略以安全地处理外部审计数据

    公开(公告)号:US20160140347A1

    公开(公告)日:2016-05-19

    申请号:US14540205

    申请日:2014-11-13

    申请人: Andreas Schaad

    发明人: Andreas Schaad

    IPC分类号: G06F21/60 G06F21/62

    摘要: Methods, systems, and computer-readable storage media for secure storage of and selective access to encrypted audit data. Implementations include actions of receiving a set of audit data in response to occurrence of an incident, determining a set of static audit data and a set of dynamic audit data based on the set of audit data, encrypting items in the set of static audit data using a first attribute-based encryption scheme to provide a set of encrypted static audit data, and items in the set of dynamic audit data using a second attribute-based encryption scheme to provide a set of encrypted dynamic audit data, and transmitting the set of encrypted static audit data and the set of encrypted dynamic audit data to an off-premise database for storage and selective access.

    摘要翻译: 用于安全存储和选择性访问加密审核数据的方法,系统和计算机可读存储介质。 实施包括响应于事件发生而接收一组审计数据的操作,基于该组审计数据确定一组静态审计数据和一组动态审计数据,使用该集合的静态审计数据加密项目 第一基于属性的加密方案,用于提供一组加密的静态审核数据,以及使用第二基于属性的加密方案来提供一组加密的动态审核数据的动态审核数据集中的项目,以及发送加密的 静态审核数据和一组加密的动态审核数据到外部数据库进行存储和选择性访问。