首页> 外国专利> EVIDENCE-BASED SECURITY POLICY MANAGER

EVIDENCE-BASED SECURITY POLICY MANAGER

机译:基于证据的安全策略管理器

摘要

An evidence-based policy manager generates a permission grant set for a code assembly received from a resource location. The policy manager executes in a computer system (e.g., a Web client or server) in combination with the verification module and class loader of the run-time environment. The permission grant set generated for a code assembly is applied in the run-time call stack to help the system determine whether a given system operation by the code assembly is authorized. Both code assemblies and evidence may be received from a local origin or from a remote resource location via a network (e.g., the Internet). The policy manager may comprise execution modules for parsing a security policy specification, generating a one or more code hierarchies, evaluating membership of the received code assembly in one or more code groups, and generating a permission grant set based upon this membership evaluation. The policy manager may generate multiple policy-levels in accordance with a security policy definition specified in a security policy specification. Permission sets from each policy level may be merged to generated a permission grant set associated with the code assembly and applied in the run-time call stack of the execution thread.
机译:基于证据的策略管理器为从资源位置接收的代码汇编生成权限授予集。策略管理器在计算机系统(例如,Web客户端或服务器)中与运行时环境的验证模块和类加载器结合执行。为代码程序集生成的权限授予集将应用到运行时调用堆栈中,以帮助系统确定代码程序集的给定系统操作是否得到授权。可以经由网络(例如,互联网)从本地来源或从远程资源位置接收代码汇编和证据。策略管理器可以包括执行模块,该执行模块用于解析安全策略规范,生成一个或多个代码层次结构,评估一个或多个代码组中所接收的代码汇编的成员资格,以及基于该成员资格评估来生成许可授予集。策略管理器可以根据安全策略规范中指定的安全策略定义来生成多个策略级别。来自每个策略级别的权限集可以合并以生成与代码程序集关联的权限授予集,并应用于执行线程的运行时调用堆栈中。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号