首页> 外国专利> SIGNED GROUP CRITERIA

SIGNED GROUP CRITERIA

机译:签署的集团标准

摘要

A method and apparatus for identifying an applicant as a member of a group without explicitly listing all possible applicants. A test is defined which specifies the criteria for group membership. The test definition (100) and an optional group identifier code are supplied to a criterion generator (102). The criterion generator (10) generates an authenticated message (108) based, at least in part, upon said test definition (100). The authenticated message (108) is delivered (112) to one or more criterion evaluators (18) that verify the authenticated message (122). In one embodiment, once the authenticated message has been verified (124), the applicant for access to a resource presents a credential (132) to the criterion evaluator (18). If the credential satisfies the test definition (100), the applicant is granted access (134) to the specified resource and denied access (136) if the credential does not satisfy the test definition. In another embodiment, upon presentation of a suitable credential to the criterion evaluator (18), the criterion evaluator (18) produces a group membership credential (32) that may be presented to an actuator (34) that is not in communication with the criterion evaluator (18). If the actuator determines that the group membership credential is authentic, the applicant is granted access to the resource.
机译:在不明确列出所有可能的申请人的情况下,将申请人标识为组成员的方法和装置。定义了一个测试,该测试指定了组成员资格的标准。测试定义(100)和可选的组标识符代码被提供给标准生成器(102)。标准生成器(10)至少部分地基于所述测试定义(100)来生成认证消息(108)。认证消息(108)被传送(112)到验证认证消息(122)的一个或多个标准评估器(18)。在一个实施例中,一旦已经验证了认证消息(124),则访问资源的申请人向标准评估器(18)提供凭证(132)。如果证书满足测试定义(100),则如果证书不满足测试定义,则向申请人授予对指定资源的访问(134),并拒绝该访问(136)。在另一实施例中,在向标准评估器(18)呈现合适的凭证后,标准评估器(18)产生可以被提供给不与该标准通信的致动器(34)的组成员资格凭证(32)。评估员(18)。如果执行器确定组成员身份凭证是真实的,则将授予申请人访问资源的权限。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号