Policy resolution in an entitlement management system
    1.
    发明授权
    Policy resolution in an entitlement management system 有权
    授权管理系统中的政策解决

    公开(公告)号:US08010991B2

    公开(公告)日:2011-08-30

    申请号:US12018103

    申请日:2008-01-22

    IPC分类号: H04L29/06 G06F17/30

    摘要: An externalized entitlement management system comprises a policy administration point that is configured to receive one or more definitions or updates of entitlement policies specifying subjects, actions, and resources, and to update a first entitlement repository coupled to the policy administration point with the definitions or updates in response to receiving the definitions or updates; one or more policy decision points that are coupled to the policy administration point over a network; one or more policy enforcement points that are integrated into one or more respective first application programs, wherein each of the policy enforcement points is coupled to one of the policy decision points; and one or more action handlers in the policy administration point, wherein each of the action handlers is configured to intercept a particular action represented in an update to an entitlement policy, to transform the action into an entitlement update in a form compatible with a native entitlement mechanism of a second application program that does not have one of the policy enforcement points, to send the transformed entitlement update to the second application program, and to cause a rollback of the update of the first entitlement repository if the second application program fails to implement the entitlement update in the native entitlement mechanism.

    摘要翻译: 外部化权利管理系统包括被配置为接收指定主题,动作和资源的授权策略的一个或多个定义或更新的策略管理点,并且利用定义或更新来更新耦合到策略管理点的第一授权存储库 响应于接收定义或更新; 通过网络耦合到策略管理点的一个或多个策略决策点; 一个或多个策略执行点被集成到一个或多个相应的第一应用程序中,其中每个策略执行点被耦合到策略决策点之一; 以及策略管理点中的一个或多个动作处理程序,其中每个动作处理程序被配置为拦截在授权策略的更新中表示的特定动作,以将操作转换为与本机授权相兼容的形式的授权更新 第二应用程序的机制,其不具有策略执行点之一,将转换的授权更新发送到第二应用程序,并且如果第二应用程序未能实现,则导致第一授权库的更新的回滚 本机授权机制中的权利更新。

    Integration of context-sensitive run-time metrics into integrated development environments
    2.
    发明申请
    Integration of context-sensitive run-time metrics into integrated development environments 有权
    将上下文相关的运行时指标集成到集成开发环境中

    公开(公告)号:US20070168913A1

    公开(公告)日:2007-07-19

    申请号:US10751333

    申请日:2004-01-02

    IPC分类号: G06F9/44

    摘要: An integrated development environment (IDE) includes a runtime environment and user interface. A user of the IDE specifies an application component to be monitored, and metrics for the specified application component are transmitted by the IDE runtime environment to a data collector belonging to the IDE user interface for display to the user. In addition, support is offered for the separation of operational concerns from business logic, allowing developers to control the operational aspects from a policy manager of the IDE user interface. Using the policy manager, developers invoke policy agents to add predefined code segments to applications, saving the developer from having to recode the same operational logic each time an application is updated to contain a new policy related to business logic.

    摘要翻译: 集成开发环境(IDE)包括运行时环境和用户界面。 IDE的用户指定要监视的应用程序组件,并且指定应用程序组件的度量由IDE运行时环境传输到属于IDE用户界面的数据收集器,以显示给用户。 此外,还提供了将业务问题与业务逻辑分开的支持,允许开发人员从IDE用户界面的策略管理器控制操作方面。 使用策略管理器,开发人员调用策略代理程序将预定义的代码段添加到应用程序中,从而节省开发人员在每次更新应用程序时重新编码相同的操作逻辑,以包含与业务逻辑相关的新策略。

    POLICY RESOLUTION IN AN ENTITLEMENT MANAGEMENT SYSTEM
    3.
    发明申请
    POLICY RESOLUTION IN AN ENTITLEMENT MANAGEMENT SYSTEM 有权
    实施管理体系中的政策决策

    公开(公告)号:US20080184336A1

    公开(公告)日:2008-07-31

    申请号:US12018103

    申请日:2008-01-22

    IPC分类号: G06F21/00

    摘要: An externalized entitlement management system comprises a policy administration point that is configured to receive one or more definitions or updates of entitlement policies specifying subjects, actions, and resources, and to update a first entitlement repository coupled to the policy administration point with the definitions or updates in response to receiving the definitions or updates; one or more policy decision points that are coupled to the policy administration point over a network; one or more policy enforcement points that are integrated into one or more respective first application programs, wherein each of the policy enforcement points is coupled to one of the policy decision points; and one or more action handlers in the policy administration point, wherein each of the action handlers is configured to intercept a particular action represented in an update to an entitlement policy, to transform the action into an entitlement update in a form compatible with a native entitlement mechanism of a second application program that does not have one of the policy enforcement points, to send the transformed entitlement update to the second application program, and to cause a rollback of the update of the first entitlement repository if the second application program fails to implement the entitlement update in the native entitlement mechanism.

    摘要翻译: 外部化权利管理系统包括被配置为接收指定主题,动作和资源的授权策略的一个或多个定义或更新的策略管理点,并且利用定义或更新来更新耦合到策略管理点的第一授权存储库 响应于接收定义或更新; 通过网络耦合到策略管理点的一个或多个策略决策点; 一个或多个策略执行点被集成到一个或多个相应的第一应用程序中,其中每个策略执行点被耦合到策略决策点之一; 以及策略管理点中的一个或多个动作处理程序,其中每个动作处理程序被配置为拦截在授权策略的更新中表示的特定动作,以将操作转换为与本机授权相兼容的形式的授权更新 第二应用程序的机制,其不具有策略执行点之一,将转换的授权更新发送到第二应用程序,并且如果第二应用程序未能实现,则导致第一授权库的更新的回滚 本机授权机制中的权利更新。

    Integration of context-sensitive runtime metrics into integrated development environments
    4.
    发明授权
    Integration of context-sensitive runtime metrics into integrated development environments 有权
    将上下文相关的运行时指标集成到集成开发环境中

    公开(公告)号:US07802234B2

    公开(公告)日:2010-09-21

    申请号:US10751333

    申请日:2004-01-02

    IPC分类号: G06F9/44

    摘要: An integrated development environment (IDE) includes a runtime environment and user interface. A user of the IDE specifies an application component to be monitored, and metrics for the specified application component are transmitted by the IDE runtime environment to a data collector belonging to the IDE user interface for display to the user. In addition, support is offered for the separation of operational concerns from business logic, allowing developers to control the operational aspects from a policy manager of the IDE user interface. Using the policy manager, developers invoke policy agents to add predefined code segments to applications, saving the developer from having to recode the same operational logic each time an application is updated to contain a new policy related to business logic.

    摘要翻译: 集成开发环境(IDE)包括运行时环境和用户界面。 IDE的用户指定要监视的应用程序组件,并且指定应用程序组件的度量由IDE运行时环境传输到属于IDE用户界面的数据收集器,以显示给用户。 此外,还提供了将业务问题与业务逻辑分开的支持,允许开发人员从IDE用户界面的策略管理器控制操作方面。 使用策略管理器,开发人员调用策略代理程序将预定义的代码段添加到应用程序中,从而节省开发人员在每次更新应用程序时重新编码相同的操作逻辑,以包含与业务逻辑相关的新策略。

    Policy based service management
    5.
    发明申请
    Policy based service management 有权
    基于策略的服务管理

    公开(公告)号:US20070124797A1

    公开(公告)日:2007-05-31

    申请号:US10866508

    申请日:2004-06-12

    IPC分类号: H04L9/00

    摘要: A system and a method for policy management in a web services environment includes a policy design tool, a policy storage and a policy manager controller. The policy design tool creates (or updates) a policy for association with a web service. The policy storage stores the policy. The policy manager controller provides an interface for transmission of the policy to a policy enforcement tool and also receives messages relating to the policy from the policy enforcement tool. In addition, a system and method for policy enforcement in a web services environment includes a policy enforcement controller, a policy enforcement repository, an enforcer, a policy enforcement framework, and a policy container. The policy enforcement controller receives and commits a policy and the policy enforcement repository stores the committed policy. The enforcer module receives a request to invoke the policy and the policy enforcement framework determines whether the requested policy is committed in the policy enforcement repository and whether the policy is instantiated. The policy container determines whether the policy is enforceable.

    摘要翻译: 用于Web服务环境中的策略管理的系统和方法包括策略设计工具,策略存储和策略管理器控制器。 策略设计工具创建(或更新)与Web服务关联的策略。 策略存储存储策略。 策略管理器控制器提供用于将策略传输到策略执行工具的接口,并且还从策略执行工具接收与该策略相关的消息。 另外,用于web服务环境中的策略执行的系统和方法包括策略执行控制器,策略实施库,执行器,策略实施框架和策略容器。 策略执行控制器接收并提交策略,策略执行库存储所承诺的策略。 执行者模块接收到调用策略的请求,策略执行框架确定策略执行库中是否提交了请求的策略,以及策略是否被实例化。 策略容器确定策略是否可执行。

    High definition scintillation detector for medicine, homeland security and non-destructive evaluation
    6.
    发明授权
    High definition scintillation detector for medicine, homeland security and non-destructive evaluation 有权
    高清晰度闪烁检测仪,用于医药,国土安全和无损评估

    公开(公告)号:US08477906B2

    公开(公告)日:2013-07-02

    申请号:US12529867

    申请日:2008-03-05

    IPC分类号: G01T1/203 H05G1/64

    CPC分类号: G01T1/201 G01T1/16

    摘要: A bundle of drawn fibers that have X-ray scintillating unagglommerated nanocrystallite particles in plastic or glass cores of down to 0.1 micron spacing and claddings of X-ray absorbing compounds in the cladding composition. Optional is a cover to the bundle that blocks light from leaving the bundle at the X-ray side while allowing X-rays to pass into the cores. To image the light exiting the fiber bundle at the sub-micron level, light expansion is preferable using either a lens system or a fiber bundle expander.

    摘要翻译: 一束拉伸纤维,其在包层组合物中具有低至0.1微米间距的塑料或玻璃芯中具有X射线闪烁的未散射的纳米晶粒和X射线吸收化合物的包层。 可选的是捆绑的封面,阻止光线在X射线侧离开束,同时允许X射线进入核心。 为了在亚微米级别对离开纤维束的光进行成像,使用透镜系统或纤维束扩张器优选进行光膨胀。

    Look-ahead load pre-fetch in a processor
    7.
    发明授权
    Look-ahead load pre-fetch in a processor 有权
    在处理器中预先加载预取

    公开(公告)号:US08171266B2

    公开(公告)日:2012-05-01

    申请号:US09922551

    申请日:2001-08-02

    IPC分类号: G06F12/00

    CPC分类号: G06F9/3842 G06F9/383

    摘要: A method for look-ahead load pre-fetching that reduces the effects of instruction stalls caused by high latency instructions. Look-ahead load pre-fetching is accomplished by searching an instruction stream for load memory instructions while the instruction stream is stalled waiting for completion of a previous instruction in the instruction stream. A pre-fetch operation is issued for each load memory instruction found. The pre-fetch operations cause data for the corresponding load memory instructions to be copied to a cache, thereby avoiding long latencies in the subsequent execution of the load memory instructions.

    摘要翻译: 一种用于预先加载预取的方法,可减少由高延迟指令引起的指令停顿的影响。 通过在指令流停止等待指令流中的先前指令的完成的情况下,通过搜索指令流来执行加载存储器指令来实现预先加载预取。 为发现的每个加载存储器指令发出预取操作。 预取操作导致相应的加载存储器指令的数据被复制到高速缓存,从而避免后续执行加载存储器指令的长时间延迟。

    Method and apparatus for characterizing the temporal resolution of an imaging device
    8.
    发明授权
    Method and apparatus for characterizing the temporal resolution of an imaging device 有权
    用于表征成像装置的时间分辨率的方法和装置

    公开(公告)号:US07863897B2

    公开(公告)日:2011-01-04

    申请号:US12206279

    申请日:2008-09-08

    IPC分类号: G01V3/00

    摘要: A system and method for determining the temporal resolution of a tomographic imaging device uses an apparatus to drive one or more dynamic phantoms composed of multiple materials. The apparatus is placed at or near the isocenter of the imaging device and the one or more phantoms are moved to produce a plurality of dynamic features, each having a specified frequency. The dynamic features are imaged with the device and the acquired image data corresponding to the dynamic features is analyzed to determine a temporal modulation transfer value at each of the known specified frequencies. The temporal resolution of the imaging device is determined using these temporal modulation transfer values.

    摘要翻译: 用于确定层析成像装置的时间分辨率的系统和方法使用装置来驱动由多种材料组成的一个或多个动态幻影。 该装置放置在成像装置的等角点处或附近,并且移动一个或多个幻影以产生多个具有指定频率的动态特征。 利用设备对动态特征进行成像,并分析对应于动态特征的获取的图像数据,以确定每个已知指定频率处的时间调制转移值。 使用这些时间调制转移值来确定成像装置的时间分辨率。

    Policy based service management
    9.
    发明授权
    Policy based service management 有权
    基于策略的服务管理

    公开(公告)号:US07757268B2

    公开(公告)日:2010-07-13

    申请号:US10866508

    申请日:2004-06-12

    IPC分类号: G06F17/00

    摘要: A system and a method for policy management in a web services environment includes a policy design tool, a policy storage and a policy manager controller. The policy design tool creates (or updates) a policy for association with a web service. The policy storage stores the policy. The policy manager controller provides an interface for transmission of the policy to a policy enforcement tool and also receives messages relating to the policy from the policy enforcement tool. In addition, a system and method for policy enforcement in a web services environment includes a policy enforcement controller, a policy enforcement repository, an enforcer, a policy enforcement framework, and a policy container. The policy enforcement controller receives and commits a policy and the policy enforcement repository stores the committed policy. The enforcer module receives a request to invoke the policy and the policy enforcement framework determines whether the requested policy is committed in the policy enforcement repository and whether the policy is instantiated. The policy container determines whether the policy is enforceable.

    摘要翻译: 用于Web服务环境中的策略管理的系统和方法包括策略设计工具,策略存储和策略管理器控制器。 策略设计工具创建(或更新)与Web服务关联的策略。 策略存储存储策略。 策略管理器控制器提供用于将策略传输到策略执行工具的接口,并且还从策略执行工具接收与该策略相关的消息。 另外,用于web服务环境中的策略执行的系统和方法包括策略执行控制器,策略实施库,执行器,策略实施框架和策略容器。 策略执行控制器接收并提交策略,策略执行库存储所承诺的策略。 执行者模块接收到调用策略的请求,策略执行框架确定策略执行库中是否提交了请求的策略,以及策略是否被实例化。 策略容器确定策略是否可执行。

    System and method for safely executing downloaded code on a computer system
    10.
    发明授权
    System and method for safely executing downloaded code on a computer system 有权
    在计算机系统上安全执行下载的代码的系统和方法

    公开(公告)号:US07596694B1

    公开(公告)日:2009-09-29

    申请号:US10796690

    申请日:2004-03-08

    IPC分类号: H04L29/06

    CPC分类号: H04L63/123 H04L67/34

    摘要: Embodiments of the present invention include a system and method for making it safe to execute downloaded code. The method includes accessing an application, the application making a system call to a library of a computer system for a resource, establishing a requesting thread. The method further includes the library sending a request message to a local security filter; the local security filter validating the requesting thread and returning a digital signature, that uniquely identifies the requesting thread, to the application. The application making a system call to a kernel of the computer system wherein the kernel uses the digital signature from the security filter to validate the requesting thread before allowing access to the requested resource.

    摘要翻译: 本发明的实施例包括用于执行下载代码的安全的系统和方法。 所述方法包括访问应用程序,所述应用程序对资源的计算机系统的库进行系统调用,建立请求线程。 该方法还包括库向本地安全过滤器发送请求消息; 本地安全过滤器验证请求线程并且向应用程序返回唯一地标识请求线程的数字签名。 所述应用程序对所述计算机系统的内核进行系统调用,其中所述内核使用来自所述安全过滤器的数字签名在允许访问所请求的资源之前验证所述请求线程。