首页> 外国专利> Tailorable access privileges for services based on session access characteristics

Tailorable access privileges for services based on session access characteristics

机译:基于会话访问特征的服务可定制的访问特权

摘要

Method and apparatus that provide tailorable access privileges for services based on session access characteristics. In a session between a user and a software application that provides one or more services, there are various access characteristics that describe the security of the session, for example, user authentication and encryption. Various combinations of access characteristics are defined and security levels are associated with the combinations. Each of the available services also has an associated security level. Access characteristics of a session are established after a user logs in to establish a session and the user is authenticated. When a service request is received, the session's access characteristics are used to determine the session's security level. If the session's security level satisfies the security level required by the requested service, access to the service is granted. Otherwise, access is denied. Since the access characteristics are determined when a session is established, and the security levels are tailorable, services can be provided via different channels and devices without compromising security.
机译:根据会话访问特征为服务提供可定制的访问特权的方法和装置。在用户和提供一个或多个服务的软件应用程序之间的会话中,存在描述该会话安全性的各种访问特征,例如,用户身份验证和加密。定义了访问特征的各种组合,并将安全级别与这些组合相关联。每个可用服务还具有关联的安全级别。在用户登录以建立会话并认证用户之后,将建立会话的访问特征。收到服务请求时,会话的访问特征用于确定会话的安全级别。如果会话的安全级别满足请求的服务所需的安全级别,则将授予对该服务的访问权限。否则,访问将被拒绝。由于访问特性是在建立会话时确定的,并且安全级别是可定制的,因此可以通过不同的通道和设备提供服务,而不会影响安全性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号