首页> 外国专利> method and system for enhanced access control based on roles in distributed and centralized computer systems

method and system for enhanced access control based on roles in distributed and centralized computer systems

机译:分布式和集中式计算机系统中基于角色的增强访问控制的方法和系统

摘要

A method and system for registration, authorization, and control of access rights in a computer system are disclosed in the present invention. The inventive method for controlling access rights of subjects (1) on objects (4) in a computer system uses parameterized role types (2) that can be instantiated into role instances (4) equivalent to roles or groups as known from the prior art. The required parameters are provided by the subject (1) of the computer system, e.g. by a person (5), a job position (6) or an organization unit (7). Furthermore, the inventive method provides relative resource sets (8) which are instantiated into concrete resource sets (9) and individual resources (10) by using the same parameter values as for instantiating the role types. The inventive system for authorization and control of access rights as disclosed in the present invention comprises capability lists (30) providing the access rights of the subjects (1) on the objects (4) of a computer system on a per-subject basis. Furthermore, the inventive system comprises means for deriving (32) access control lists (31) from capability lists (30), wherein said access rights of the subjects (1) on the respective objects (4) are provided. MATH
机译:在本发明中公开了一种用于在计算机系统中注册,授权和控制访问权限的方法和系统。在计算机系统中用于控制对象(1)对对象(4)的访问权限的本发明方法使用参数化的角色类型(2),该角色类型可以实例化为等效于现有技术中已知的角色或组的角色实例(4)。所需的参数由计算机系统的主题(1)提供,例如由人员(5),职位(6)或组织单位(7)组成。此外,本发明的方法提供了相对资源集(8),其通过使用与用于实例化角色类型相同的参数值实例化为具体资源集(9)和单个资源(10)。如本发明中所公开的用于授权和控制访问权限的本发明的系统包括能力列表(30),该能力列表(30)按对象在计算机系统的对象(4)上提供对象(1)的访问权限。此外,本发明的系统包括用于从能力列表(30)导出(32)访问控制列表(31)的装置,其中提供了对象(1)在各个对象(4)上的所述访问权限。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号