Methods and Apparatus for Role-Based Shared Access Control to a Protected System Using Reusable User Identifiers
    2.
    发明申请
    Methods and Apparatus for Role-Based Shared Access Control to a Protected System Using Reusable User Identifiers 审中-公开
    使用可重用的用户标识符对受保护系统进行基于角色的共享访问控制的方法和设备

    公开(公告)号:US20110247059A1

    公开(公告)日:2011-10-06

    申请号:US12751461

    申请日:2010-03-31

    IPC分类号: H04L9/32 G06F21/00

    CPC分类号: G06F21/62 G06F21/31

    摘要: Methods and apparatus are provided for role-based shared access control to a protected system using reusable user identifiers while maintaining individual accountability. Role-based access control is provided for a protected system by receiving a request from an end user to access a given protected system; determining a role of the end user for the access to the given protected system; receiving a privileged reusable user identifier and password for the given protected system and role; and providing the privileged reusable user identifier and password to the given protected system on behalf of the end user. Role-based access control is also provided for a protected system by receiving a request to verify an end user requesting access to a given protected system; determining a role of the end user for the access to the given protected system; and providing a privileged reusable user identifier and password for the given protected system and role. A status of the privileged reusable user identifier and password can optionally be maintained. One or more events associated with the privileged reusable user identifier and password can be logged and investigated.

    摘要翻译: 提供了方法和装置,用于基于角色的共享访问控制到使用可重用的用户标识符的受保护系统,同时保持个人的责任。 通过接收来自最终用户访问给定受保护系统的请求,为受保护的系统提供基于角色的访问控制; 确定最终用户对于给定的受保护系统的访问的作用; 为给定的受保护的系统和角色接收特权的可重复使用的用户标识符和密码; 以及代表最终用户向给定的受保护系统提供特权的可重复使用的用户标识符和密码。 还通过接收用于验证请求访问给定受保护系统的最终用户的请求来为受保护的系统提供基于角色的访问控制; 确定最终用户对于给定的受保护系统的访问的作用; 并为给定的受保护系统和角色提供特权可重用的用户标识符和密码。 可以可选地维护特权可重用用户标识符和密码的状态。 可以记录和调查与特权的可重用用户标识符和密码相关联的一个或多个事件。