Computer-implemented method for role discovery in access control systems
    1.
    发明授权
    Computer-implemented method for role discovery in access control systems 有权
    用于访问控制系统中角色发现的计算机实现方法

    公开(公告)号:US09405921B1

    公开(公告)日:2016-08-02

    申请号:US11888381

    申请日:2007-07-31

    IPC分类号: G06F21/62

    摘要: One embodiment relates to a computer-implemented method for role discovery in access control systems. User accounts are selected according to a predetermined algorithm. For each selected user account, a new role is created covering a set of permissions including all permissions which the user account needs but is not yet covered by another role that the user account has. The new role is given to the user account so that all permissions needed by the user account are covered. Any additional user accounts which still need the set of permissions covered by the new role are also found, and the new role is given to these additional user accounts, if any. Other features, aspects and embodiments are also disclosed.

    摘要翻译: 一个实施例涉及用于访问控制系统中角色发现的计算机实现的方法。 根据预定算法选择用户账户。 对于每个选定的用户帐户,创建一个新角色,覆盖一组权限,包括用户帐户所需的所有权限,但尚未被用户帐户所具有的其他角色覆盖。 给用户帐户赋予新角色,以覆盖用户帐户所需的所有权限。 还会找到仍然需要新角色所涵盖的一组权限的任何其他用户帐户,并将新角色授予这些其他用户帐户(如果有)。 还公开了其它特征,方面和实施例。

    Auditing Data Integrity
    2.
    发明申请
    Auditing Data Integrity 有权
    审计数据完整性

    公开(公告)号:US20100080391A1

    公开(公告)日:2010-04-01

    申请号:US12240742

    申请日:2008-09-29

    IPC分类号: G06F17/30 H04L9/00

    摘要: Various approaches are described for auditing integrity of stored data. In one approach, a data set is provided from a client to a storage provider, and the data set is stored at a first storage arrangement by the storage provider. An auditor determines whether the data set stored at the first storage arrangement is corrupt without reliance on any part of the data set and any derivative of any part of the data set stored by the client. While the auditor is determining whether the data set stored at the first storage arrangement is corrupt, the auditor is prevented from being exposed to information specified by the data set. The auditor outputs data indicative of data corruption in response to determining that the data set stored at the first storage arrangement is corrupt.

    摘要翻译: 描述了各种方法来审计存储数据的完整性。 在一种方法中,从客户端向存储提供者提供数据集,并且数据集由存储提供商存储在第一存储装置中。 审核员确定存储在第一存储装置中的数据集是否破坏而不依赖于数据集的任何部分以及由客户机存储的数据集的任何部分的任何导数。 虽然审核员正在确定存储在第一存储装置中的数据集是否损坏,但是防止了审核员暴露于由数据集指定的信息。 响应于确定存储在第一存储装置处的数据集已损坏,审计员输出指示数据损坏的数据。

    Auditing data integrity
    3.
    发明授权
    Auditing data integrity 有权
    审计数据完整性

    公开(公告)号:US08392708B2

    公开(公告)日:2013-03-05

    申请号:US12240742

    申请日:2008-09-29

    IPC分类号: H04L9/32

    摘要: Various approaches are described for auditing integrity of stored data. In one approach, a data set is provided from a client to a storage provider, and the data set is stored at a first storage arrangement by the storage provider. An auditor determines whether the data set stored at the first storage arrangement is corrupt without reliance on any part of the data set and any derivative of any part of the data set stored by the client. While the auditor is determining whether the data set stored at the first storage arrangement is corrupt, the auditor is prevented from being exposed to information specified by the data set. The auditor outputs data indicative of data corruption in response to determining that the data set stored at the first storage arrangement is corrupt.

    摘要翻译: 描述了各种方法来审计存储数据的完整性。 在一种方法中,从客户端向存储提供者提供数据集,并且数据集由存储提供商存储在第一存储装置中。 审核员确定存储在第一存储装置中的数据集是否破坏而不依赖于数据集的任何部分以及由客户机存储的数据集的任何部分的任何导数。 虽然审核员正在确定存储在第一存储装置中的数据集是否损坏,但是防止了审核员暴露于由数据集指定的信息。 响应于确定存储在第一存储装置处的数据集已损坏,审计员输出指示数据损坏的数据。

    Methods and systems for loading data from memory
    5.
    发明授权
    Methods and systems for loading data from memory 有权
    从内存加载数据的方法和系统

    公开(公告)号:US07296136B1

    公开(公告)日:2007-11-13

    申请号:US10861710

    申请日:2004-06-04

    IPC分类号: G06F9/26 G06F9/34 G06F12/00

    摘要: According to an exemplary embodiment of the present invention, a method for loading data from at least one memory device includes the steps of loading a first value from a first memory location of the at least one memory device, determining a second memory location based on the first value and loading a second value from the second memory location of the at least one memory device, wherein the step of loading a first value is performed by a first processing unit and wherein the steps of determining a second memory location and loading a second value are performed by at least one other processing unit.

    摘要翻译: 根据本发明的示例性实施例,一种用于从至少一个存储设备加载数据的方法包括以下步骤:从所述至少一个存储器设备的第一存储器位置加载第一值,基于所述至少一个存储器设备确定第二存储器位置 第一值并从所述至少一个存储器件的第二存储器位置加载第二值,其中由第一处理单元执行加载第一值的步骤,并且其中确定第二存储器位置并加载第二值的步骤 由至少一个其他处理单元执行。

    Fair token arbitration systems and methods
    7.
    发明授权
    Fair token arbitration systems and methods 有权
    公平令牌仲裁系统和方法

    公开(公告)号:US08564867B2

    公开(公告)日:2013-10-22

    申请号:US13386382

    申请日:2009-12-10

    IPC分类号: G06E3/00 G02F3/00

    摘要: Various embodiments of the present invention are directed to arbitration systems and methods. In one embodiment, an arbitration system comprises a loop-shaped arbitration waveguide (602), a loop-shaped hungry waveguide (603), and a loop-shaped broadcast waveguide (604). The arbitration, hungry, and broadcast waveguides optically coupled to a home node and a number of requesting nodes. The arbitration waveguide transmits tokens injected by the home node. A token extracted by a requesting node grants the node access to a resource for the duration or length of the token. The hungry waveguide transmits light injected by the home node. A requesting node in a hungry state extracts the light from the hungry waveguide. The broadcast waveguide transmits light injected by the home node such that the light indicates to requesting nodes not in the hungry state to stop extracting tokens from the arbitration waveguide.

    摘要翻译: 本发明的各种实施例涉及仲裁系统和方法。 在一个实施例中,仲裁系统包括环形仲裁波导(602),环形饥饿波导(603)和环形广播波导(604)。 仲裁,饥饿和广播波导光耦合到家庭节点和多个请求节点。 仲裁波导传输由归属节点注入的令牌。 由请求节点提取的令牌在令牌的持续时间或长度内授予节点对资源的访问。 饥饿的波导传输由家庭节点注入的光。 饥饿状态下的请求节点从饥饿波导中提取光。 广播波导传输由家庭节点注入的光,使得光指向不处于饥饿状态的请求节点停止从仲裁波导提取令牌。

    Procedural concurrency graph generator
    10.
    发明授权
    Procedural concurrency graph generator 有权
    程序并发图生成器

    公开(公告)号:US09141359B2

    公开(公告)日:2015-09-22

    申请号:US12966867

    申请日:2010-12-13

    IPC分类号: G06F9/45

    CPC分类号: G06F8/45

    摘要: A parallel-code optimization system includes a Procedural Concurrency Graph (PCG) generator. The PCG generator produces an initial PCG of a computer program including parallel code, and determines a refined PCG from the initial PCG by applying concurrency-type refinements and interference-type refinements to the initial PCG. The initial PCG and the refined PCG include nodes and edges connecting pairs of the nodes. The nodes represent defined procedures in the parallel code, and each edge represents a may-happen-in-parallel relation, and is associated with a set of lvalues that represents the immediate interference between the corresponding pair of nodes.

    摘要翻译: 并行代码优化系统包括一个过程并发图(PCG)生成器。 PCG生成器产生包括并行代码的计算机程序的初始PCG,并且通过对初始PCG应用并发型改进和干扰类型细化来确定来自初始PCG的精细PCG。 初始PCG和精细PCG包括连接节点对的节点和边。 节点表示并行代码中的定义的过程,并且每个边表示可并发并行关系,并且与表示相应对节点之间的即时干扰的一组左值相关联。