首页> 外国专利> Method and system for automatic generation of cache directives for security policy

Method and system for automatic generation of cache directives for security policy

机译:自动生成用于安全策略的缓存指令的方法和系统

摘要

An authorization method is implemented in an authorization engine external to an authorization server. The authorization server includes a cache. The external authorization engine comprises an authorization decision engine, and a policy analytics engine. The method begins when the authorization decision engine receives a request for an authorization decision. The request is generated (at the authorization server) following receipt of a client request for which an authorization decision is not then available at the server. The authorization decision engine determines an authorization policy to apply to the client request, applies the policy, and generates an authorization decision. The authorization decision is then provided to the policy analytics engine, which stores previously-generated potential cache directives that may be applied to the authorization decision. Preferably, the cache directives are generated in an off-line manner (e.g., during initialization) by examining each security policy and extracting one or more cache dimensions associated with each such policy. The policy analytics engine determines an applicable cache directive, and the decision is augmented to include that cache directive. The decision (including the cache directive) is then returned to the authorization server, where the decision is applied to process the client request. The cache directive is then cached for re-use at the authorization server.
机译:授权方法是在授权服务器外部的授权引擎中实现的。授权服务器包括一个缓存。外部授权引擎包括授权决策引擎和策略分析引擎。当授权决策引擎接收到对授权决策的请求时,该方法开始。该请求是在接收到客户端请求之后生成的(在授权服务器上),该客户端请求随后在服务器上无法获得授权决策。授权决策引擎确定要应用于客户端请求的授权策略,应用该策略,并生成授权决策。然后,将授权决策提供给策略分析引擎,该策略分析引擎存储可以应用于授权决策的先前生成的潜在缓存指令。优选地,通过检查每个安全策略并提取与每个这样的策略相关联的一个或多个高速缓存维度,以离线方式(例如,在初始化期间)生成高速缓存指令。策略分析引擎确定适用的缓存指令,并将决策扩展为包括该缓存指令。然后将决策(包括缓存指令)返回到授权服务器,在此将决策应用于处理客户端请求。然后,将高速缓存指令高速缓存以在授权服务器上重新使用。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号