首页> 外国专利> PROVISIONING USER PERMISSIONS ATTRIBUTE-BASED ACCESS-CONTROL POLICIES

PROVISIONING USER PERMISSIONS ATTRIBUTE-BASED ACCESS-CONTROL POLICIES

机译:提供基于用户权限的基于权限的访问控制策略

摘要

An attribute-based access control policy (e.g., XACML policy) for a set of elements depends on attributes carried by elements in one of several predefined categories. In order to evaluate such policy for a set of elements, the invention provides a method including the steps of (I) selecting a primary category; (II) partitioning the elements in the primary category into equivalence classes with respect to their influence on the policy; and (III) using the equivalence classes to replace at least one policy evaluation by a deduction. The result of the evaluation may be represented as an access matrix in backward-compatible format. The efficiency of the policy evaluation may be further improved by applying partial policy evaluation at intermediate stages, by forming combined equivalence classes containing n-tuples of elements and/or by analyzing the influence of each element by extracting functional expressions of maximal length from the policy.
机译:一组元素的基于属性的访问控制策略(例如XACML策略)取决于几个预定义类别之一中元素所携带的属性。为了评估一组元素的这种策略,本发明提供了一种方法,包括以下步骤:(I)选择主要类别; (二)根据对政策的影响,将主要类别的要素划分为等价类; (III)使用对等类别以扣除来替代至少一项政策评估。评估的结果可以表示为后向兼容格式的访问矩阵。通过在中间阶段应用部分策略评估,通过形成包含元素的n元组的组合等价类和/或通过从策略中提取最大长度的函数表达式来分析每个元素的影响,可以进一步提高策略评估的效率。

著录项

  • 公开/公告号US2015128210A1

    专利类型

  • 公开/公告日2015-05-07

    原文格式PDF

  • 申请/专利权人 AXIOMATICS AB;

    申请/专利号US201414522300

  • 发明设计人 PABLO GIAMBIAGI;

    申请日2014-10-23

  • 分类号G06F21/31;

  • 国家 US

  • 入库时间 2022-08-21 15:21:02

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号