首页> 外国专利> DYNAMIC RULES-BASED SECURE DATA ACCESS SYSTEM FOR BUSINESS COMPUTER PLATFORMS

DYNAMIC RULES-BASED SECURE DATA ACCESS SYSTEM FOR BUSINESS COMPUTER PLATFORMS

机译:基于动态规则的商业计算机平台安全数据访问系统

摘要

The invention provides a dynamic rules-based secure data access system that may be used in a variety of applications that include a requirement for controlled secure access to a database (100). The rules-based access system has several features. One of these is that each user be assigned a role, either as an individual or as part of the group (120). Access rights may be assigned based one roles, but these can be modified within the system by individual users, that have authority to do so. Further, the data resources that each user is allowed to access (130), based on his or her role, and the extent of viewing and of data manipulation allowed, is further controlled based on assigned 'rights and privileges' (210). Another feature is that the database may be viewed as structured and organized into 'business functions', which are useful in business enterprises, such as sales, marketing, customer supports, etc (200). Users may be restricted to only certain functions, based on their roles (160). Within the business function units, the resources may be regarded as are further subdivided into several hierarchy levels; such as business objects, and instances of these objects (190). Users may be allowed access to only a specific business function, and only specific levels within that functional unit, based on role (220). Further, data may be restricted within each of the hierarchy levels, so that a user with access may not be allowed to see or manipulate all resources on a particular level within the hierarchy.
机译:本发明提供了一种基于动态规则的安全数据访问系统,该系统可用于包括要求对数据库(100)进行受控安全访问的各种应用中。基于规则的访问系统具有多个功能。其中之一是为每个用户分配一个角色,既可以作为个人,也可以作为组的一部分(120)。可以基于一个角色来分配访问权限,但是可以由有权这样做的单个用户在系统内对其进行修改。此外,基于所分配的“权利和特权”,进一步基于每个用户的角色以及所允许的查看和数据操纵的程度来控制每个用户被访问的数据资源(130)(210)。另一个特征是该数据库可以被看作是结构化的和组织成“业务功能”的,在商业企业中非常有用,例如销售,市场营销,客户支持等(200)。根据用户的角色,可以将他们限制为仅使用某些功能(160)。在业务功能单元内,可以将资源视为进一步细分为几个层次结构级别;例如业务对象,以及这些对象的实例(190)。基于角色(220),可以仅允许用户访问特定的业务功能,以及该功能单元内的特定级别。此外,可以将数据限制在每个层次结构级别之内,从而可能不允许具有访问权限的用户查看或操纵层次结构内特定级别的所有资源。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号