首页> 外国专利> Anti-tamper mechanism revises access control list and user process access token to deny access to key resources associated with security application

Anti-tamper mechanism revises access control list and user process access token to deny access to key resources associated with security application

机译:防篡改机制修改访问控制列表和用户进程访问令牌,以拒绝访问与安全应用程序关联的关键资源

摘要

Computer resources include key resources 115 protected by access control list (ACL) 116 associated with security application 110. Security module 210 uses the ACL to control access to the key resources and may, on request from user process 120, grant the process privileged access rights to those resources by virtue of its access token 122a. However, anti-tamper mechanism 240 creates protection group 117 as a local security group and adds deny access control entry (ACE) 116a to the ACL to restrict access to the key resources by members of the group. The anti-tamper mechanism intercepts the user process access request, revises the processe access token to include the protection group and applies revised token 122b to the process. The security module matches the group in the revised token against the deny ACE in the ACL and restricts access to the key resources, despite access token 122a denoting such access rights.
机译:计算机资源包括受与安全应用程序110相关联的访问控制列表(ACL)116保护的密钥资源115。安全模块210使用ACL控制对密钥资源的访问,并可以应用户进程120的请求授予进程特权访问权限依靠其访问令牌122a访问这些资源。但是,防篡改机制240将保护组117创建为本地安全组,并向ACL添加拒绝访问控制项(ACE)116a,以限制该组成员对关键资源的访问。防篡改机制拦截用户进程访问请求,修改进程访问令牌以包括保护组,并将修改的令牌122b应用于进程。安全模块将修订令牌中的组与ACL中的拒绝ACE进行匹配,并限制对密钥资源的访问,尽管访问令牌122a表示了这种访问权限。

著录项

  • 公开/公告号GB2494391A

    专利类型

  • 公开/公告日2013-03-13

    原文格式PDF

  • 申请/专利权人 AVECTO LIMITED;

    申请/专利号GB20110015141

  • 发明设计人 MARK JAMES AUSTIN;

    申请日2011-09-02

  • 分类号G06F21/62;G06F21/00;G06F21/60;

  • 国家 GB

  • 入库时间 2022-08-21 16:20:22

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号