首页> 外国专利> RESOURCE-DRIVEN DYNAMIC AUTHORIZATION FRAMEWORK

RESOURCE-DRIVEN DYNAMIC AUTHORIZATION FRAMEWORK

机译:资源驱动的动态授权框架

摘要

Embodiments concern a dynamic authorization framework. Security Classification Process (SCP) is the process of classifying raw data, information extracted from raw data, content or code from security-value perspective. Security Achievability Determination Process (SADP) is a process based on a SV/SC that has been assigned, the RHE may determine the Security Requirements and how the security requirements may be achieved. During the Security Achievability Listing Process (SALP), the RHE uploads onto the Resource Listing Entity (RLE) the URI of the resource, the SAM associated with the resource and optionally a digital certificate associated with the resource. During the SAM Assessment Process (SAMAP) process, a Client evaluates the security mechanisms that must be carried out in order to meet the SAM that was provided as part of the Discovery Process (DP). Based on the SAM obtained from the RLE, the Client may initiate a Security Achievability Enabling Process (SAEP). The Client may be required to initiate an Authentication, Authorization, Payment and obtain an assertion of secure behavior from a Security-Achievability Enabler Function (SAEF), which may be a trusted third-party Function or Entity.
机译:实施例涉及动态授权框架。安全分类过程(SCP)是从安全值的角度对原始数据,从原始数据中提取的信息,内容或代码进行分类的过程。安全可实现性确定过程(SADP)是基于已分配的SV / SC的过程,RHE可以确定安全性要求以及如何实现安全性要求。在安全性可实现性列表过程(SALP)期间,RHE将资源的URI,与资源关联的SAM以及可选的与资源关联的数字证书上载到资源列表实体(RLE)。在SAM评估流程(SAMAP)流程中,客户端评估必须执行的安全机制,才能满足作为发现流程(DP)一部分提供的SAM。基于从RLE获得的SAM,客户端可以启动安全可实现性启用过程(SAEP)。可能要求客户从安全可实现使能器功能(SAEF)发起身份验证,授权,付款并获得对安全行为的声明,该功能可以是受信任的第三方功能或实体。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号