首页> 外国专利> Method for automatic permission management in role-based access control systems

Method for automatic permission management in role-based access control systems

机译:基于角色的访问控制系统中自动权限管理的方法

摘要

A method for automatic permission management in centralized and distributed operating systems using role-based access control that supports selective and multiple instantiations of roles, multiple inheritance of permission and membership, and provides scalable and efficient distribution, review, and revocation of permissions and access authorization. The present invention provides, in a further aspect, automatic propagation of updates of role-permission hierarchies to the access control lists of all objects affected by such updates. The present invention provides, in yet a further aspect, per-role and per user review of permissions and requires neither redundant storage and additional administrative actions nor exhaustive searches of system resources. This invention makes use, in yet a further aspect, of both local and global groups for the instantiation of roles on multiple computer hosts, to implement nested groups and to enable the integration of extant host computers, which include local user accounts and groups defined on independent servers and workstations, within large distributed operating systems. In yet a further aspect, this invention provides the transition from an extant system state to an RBAC system state whereby permissions of users and groups to objects are managed centrally and automatically using roles, and removes the redundant user permissions to objects of a given state in the transition to the RBAC state.
机译:一种使用基于角色的访问控制在集中式和分布式操作系统中进行自动权限管理的方法,该方法支持角色的选择性和多个实例化,权限和成员资格的多重继承,并提供可扩展且高效的权限和访问授权的分发,查看和吊销。在另一方面,本发明提供了将角色权限层次结构的更新自动传播到受这种更新影响的所有对象的访问控制列表中。在另一方面,本发明提供了权限的每个角色和每个用户的审查,并且既不需要冗余存储和附加管理动作,也不需要详尽地搜索系统资源。在又一方面,本发明利用本地和全局组来实例化多个计算机主机上的角色,以实现嵌套组并实现现有主机的集成,这些主机包括本地用户帐户和在其上定义的组。大型分布式操作系统中的独立服务器和工作站。在另一方面,本发明提供了从现存系统状态到RBAC系统状态的过渡,由此用户和组对对象的许可通过使用角色进行集中和自动地管理,并消除了对给定状态的对象的冗余用户许可。过渡到RBAC状态。

著录项

  • 公开/公告号US2002026592A1

    专利类型

  • 公开/公告日2002-02-28

    原文格式PDF

  • 申请/专利权人 VDG INC.;

    申请/专利号US20010880024

  • 发明设计人 SERBAN I. GAVRILA;VIRGIL DORIN GLIGOR;

    申请日2001-06-14

  • 分类号H04L12/22;G06F11/30;

  • 国家 US

  • 入库时间 2022-08-22 00:49:08

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号