Resource based dynamic security authorization
    1.
    发明授权
    Resource based dynamic security authorization 有权
    基于资源的动态安全授权

    公开(公告)号:US08245270B2

    公开(公告)日:2012-08-14

    申请号:US11217748

    申请日:2005-09-01

    IPC分类号: G06F21/00

    CPC分类号: G06F21/53

    摘要: Access to a resource by sandboxed code is dynamically authorized by a client security system based on a resource based policy. A sandboxed application running on a client is granted access to a resource based on a resource based policy despite denial of the access based on a static policy associated with the client security system. The granting of access coincides with the determination that the threat to a user or the user's information is not increased should the access be granted.

    摘要翻译: 通过沙盒代码访问资源由客户端安全系统基于资源的策略动态授权。 在客户机上运行的沙盒应用程序被授予对基于资源的策略的资源访问,尽管基于与客户端安全系统相关联的静态策略拒绝访问。 准予访问与确定对用户的威胁或用户的信息没有增加的确定是一致的。

    Evidence-based application security
    5.
    发明授权
    Evidence-based application security 有权
    循证应用安全

    公开(公告)号:US07669238B2

    公开(公告)日:2010-02-23

    申请号:US10705756

    申请日:2003-11-10

    IPC分类号: H04L9/00

    CPC分类号: G06F21/51 G06F21/53

    摘要: Evidence-based application security may be implemented at the application and/or application group levels. A manifest may be provided defining at least one trust condition for the application or application group. A policy manager evaluates application evidence (e.g., an XrML license) for an application or group of applications relative to the manifest. The application is only granted permissions on the computer system if the application evidence indicates that the application is trusted. Similarly, a group of applications are only granted permissions on the computer system if the evidence indicates that the group of applications is trusted. If the application evidence satisfies the at least one trust condition defined by the manifest, the policy manager generates a permission grant set for each code assembly that is a member of the at least one application. Evidence may be further evaluated for code assemblies that are members of the trusted application or application group.

    摘要翻译: 基于证据的应用程序安全性可以在应用程序和/或应用程序组级别实现。 可以提供清单来为应用或应用组定义至少一个信任条件。 策略管理员针对相对于清单的应用程序或应用程序组来评估应用程序证据(例如,XrML许可证)。 如果应用程序的证据表明应用程序是可信任的,则该应用程序仅被授予计算机系统的权限。 类似地,如果证据表明应用程序组是可信任的,则一组应用程序仅被授予计算机系统的权限。 如果应用证据满足由清单定义的至少一个信任条件,则策略管理器为作为至少一个应用的成员的每个代码集合生成许可授权集合。 可以对作为可信应用程序或应用程序组成员的代码程序集进一步评估证据。

    Delegation in logic-based access control
    6.
    发明授权
    Delegation in logic-based access control 有权
    基于逻辑的访问控制委托

    公开(公告)号:US08607311B2

    公开(公告)日:2013-12-10

    申请号:US11962761

    申请日:2007-12-21

    CPC分类号: G06F21/6218

    摘要: Access to a resource may be controlled by a policy, such that a request to access the resource is either granted or denied based on what assertions have been made by various principals. To find the assertions that support a grant of access to the resource, a template may be created that defines the nature of assertions that would cause access to succeed. Assertions may be stored in the form of tokens. The template may be used to search an existing token store to find assertions that have been made, and/or to generate assertions that have not been found in the token store and that would satisfy the template. The assertions in the template may be created by performing an abductive reasoning process on an access query.

    摘要翻译: 可以通过策略来控制对资源的访问,使得根据各个主体所做的断言来授予或拒绝访问资源的请求。 要查找支持资源访问权限的断言,可以创建一个模板,该模板定义了导致访问成功的断言的性质。 断言可以以令牌的形式存储。 该模板可以用于搜索现有的令牌存储以找到已经做出的断言和/或生成在令牌存储器中尚未发现并且将满足模板的断言。 可以通过在访问查询上执行引用推理过程来创建模板中的断言。

    Methods and systems for batch processing in an on-demand service environment
    7.
    发明授权
    Methods and systems for batch processing in an on-demand service environment 有权
    在按需服务环境中批量处理的方法和系统

    公开(公告)号:US08584124B2

    公开(公告)日:2013-11-12

    申请号:US13076794

    申请日:2011-03-31

    IPC分类号: G06F9/455 G06F7/00

    摘要: In accordance with embodiments disclosed herein, there are provided mechanisms and methods for batch processing in an on-demand service environment. For example, in one embodiment, mechanisms include receiving a processing request for a multi-tenant database, in which the processing request specifies processing logic and a processing target group within the multi-tenant database. Such an embodiment further includes dividing or chunking the processing target group into a plurality of processing target sub-groups, queuing the processing request with a batch processing queue for the multi-tenant database among a plurality of previously queued processing requests, and releasing each of the plurality of processing target sub-groups for processing in the multi-tenant database via the processing logic at one or more times specified by the batch processing queue.

    摘要翻译: 根据本文公开的实施例,提供了在按需服务环境中批量处理的机构和方法。 例如,在一个实施例中,机制包括接收对多租户数据库的处理请求,其中处理请求指定处理逻辑和多租户数据库内的处理目标组。 这样的实施例还包括将处理对象组划分或分块成多个处理对象子组,在多个先前排队的处理请求之间对多租户数据库的批处理队列进行排队处理请求, 多个处理目标子组,用于经由处理逻辑在多租户数据库中处理由批处理队列指定的一个或多个时间。

    METHODS AND SYSTEMS FOR BATCH PROCESSING IN AN ON-DEMAND SERVICE ENVIRONMENT
    8.
    发明申请
    METHODS AND SYSTEMS FOR BATCH PROCESSING IN AN ON-DEMAND SERVICE ENVIRONMENT 有权
    在需求服务环境中进行批处理的方法和系统

    公开(公告)号:US20130013577A1

    公开(公告)日:2013-01-10

    申请号:US13620147

    申请日:2012-09-14

    IPC分类号: G06F17/30

    摘要: In accordance with embodiments disclosed herein, there are provided mechanisms and methods for batch processing in an on-demand service environment. For example, in one embodiment, mechanisms include receiving a processing request for a multi-tenant database, in which the processing request specifies processing logic and a processing target group within the multi-tenant database. Such an embodiment further includes dividing or chunking the processing target group into a plurality of processing target sub-groups, queuing the processing request with a batch processing queue for the multi-tenant database among a plurality of previously queued processing requests, and releasing each of the plurality of processing target sub-groups for processing in the multi-tenant database via the processing logic at one or more times specified by the batch processing queue.

    摘要翻译: 根据本文公开的实施例,提供了在按需服务环境中批量处理的机构和方法。 例如,在一个实施例中,机制包括接收对多租户数据库的处理请求,其中处理请求指定处理逻辑和多租户数据库内的处理目标组。 这样的实施例还包括将处理对象组划分或分块成多个处理对象子组,在多个先前排队的处理请求之间对多租户数据库的批处理队列进行排队处理请求, 多个处理目标子组,用于经由处理逻辑在多租户数据库中处理由批处理队列指定的一个或多个时间。

    Hosted code runtime protection
    10.
    发明授权
    Hosted code runtime protection 有权
    托管代码运行时保护

    公开(公告)号:US07647629B2

    公开(公告)日:2010-01-12

    申请号:US10772205

    申请日:2004-02-03

    CPC分类号: G06F9/468

    摘要: A host operating in a managed environment intercepts a call from a managed caller to a particular callee and determines whether the call is permissible according to the host's prior configuration of a plurality of callees. The particular callee, which provides access to a resource that the host can be protecting, can have been previously configured by the host to always allow the call to be made, to never allow the call to be made, or to allow the call to be made based upon the degree to which the host trusts the managed caller.

    摘要翻译: 在受管环境中操作的主机拦截来自被管理的呼叫者到特定被叫方的呼叫,并根据主机先前配置多个被呼叫者确定该呼叫是否被允许。 提供对主机可以保护的资源的访问的特定被叫方可以先前由主机配置,以始终允许进行呼叫,从不允许进行呼叫,或允许呼叫成为 基于主机信任被管理的呼叫者的程度。