首页> 外国专利> APPLICATIONS OF SECURED MEMORY AREAS AND SECURE ENVIRONMENTS IN POLICY-BASED ACCESS CONTROL SYSTEMS FOR MOBILE COMPUTING DEVICES

APPLICATIONS OF SECURED MEMORY AREAS AND SECURE ENVIRONMENTS IN POLICY-BASED ACCESS CONTROL SYSTEMS FOR MOBILE COMPUTING DEVICES

机译:安全存储区和安全环境在基于策略的移动计算设备访问控制系统中的应用

摘要

Systems and methods are described for utilizing a secure environment on a mobile computing device for applying policy-based decision management in response to access requests from untrusted areas. A policy decision processor (PDP) within the secure environment provides a policy decision in response to an access query. A decision cache within the secure environment can be used to store policy decisions for faster resolution of access requests. Policy enforcement points (PEPs) are placed between external devices that are trying to access the device and the secured environment, where the PEPs are used to enforce the policy-based decision, and can be located either inside or outside the secure environment. Decision certificates can be formulated using validity information and timestamps, and used for validation policy certificates. Memory in non-secure areas can also be marked (colored) for use in performing trusted operations in order to optimize system resource usage.
机译:描述了用于利用移动计算设备上的安全环境来响应于来自不受信任区域的访问请求而应用基于策略的决策管理的系统和方法。安全环境中的策略决策处理器(PDP)响应于访问查询提供策略决策。安全环境中的决策缓存可用于存储策略决策,以更快地解决访问请求。策略执行点(PEP)放置在尝试访问该设备的外部设备与安全环境之间,其中PEP用于执行基于策略的决策,并且可以位于安全环境内部或外部。可以使用有效性信息和时间戳来制定决策证书,并将其用于验证策略证书。也可以标记(非彩色)非安全区域中的内存以用于执行受信任的操作,以优化系统资源的使用。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号