首页> 外国专利> Provisioning authorization claims using attribute-based access-control policies

Provisioning authorization claims using attribute-based access-control policies

机译:使用基于属性的访问控制策略来配置授权声明

摘要

Disclosed are methods and devices for provisioning authorization claims, which are enforced to control access of users to objects (resources) in a computer system (330), and which are to be equivalent to an attribute-based access control (ABAC) policy. A policy converter according to the invention includes a policy processor (310) processing the policy by partial evaluation against attribute values of the users, objects or permission levels in the system and outputting simplified policies, which are subject to reverse evaluation in a reverse policy evaluator (320), whereby users, objects and permission levels to be associated by way of a single authorization claim are obtained. Responsible for the defining of the authorization claim and its distribution in the computer system are an authorization claim generator (330) and an authorization claim distribution interface (340). The invention may be so configured as to return a single authorization claim for each combination of an object and a permission level.
机译:公开了用于供应授权声明的方法和设备,其被强制执行以控制用户对计算机系统(330)中的对象(资源)的访问,并且等同于基于属性的访问控制(ABAC)策略。根据本发明的策略转换器包括策略处理器(310),该策略处理器通过针对系统中的用户,对象或许可级别的属性值进行部分评估来处理策略,并输出简化的策略,这些简化后的策略在反向策略评估器中进行反向评估。 (320),由此获得要通过单个授权声明关联的用户,对象和许可级别。负责授权声明的定义及其在计算机系统中的分发是授权声明生成器(330)和授权声明分发接口(340)。本发明可以被配置为针对对象和许可等级的每个组合返回单个授权声明。

著录项

  • 公开/公告号EP2631841B1

    专利类型

  • 公开/公告日2015-11-25

    原文格式PDF

  • 申请/专利权人 AXIOMATICS AB;

    申请/专利号EP20130156731

  • 发明设计人 KARPINSKI PETER;GIAMBIAGI PABLO;

    申请日2013-02-26

  • 分类号G06F21/60;G06F21/62;

  • 国家 EP

  • 入库时间 2022-08-21 14:50:21

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号