首页> 外国专利> Apparatus, methods and computer program products for secure distributed data processing using user-specific service access managers and propagated security identifications

Apparatus, methods and computer program products for secure distributed data processing using user-specific service access managers and propagated security identifications

机译:使用特定于用户的服务访问管理器和传播的安全标识进行安全的分布式数据处理的设备,方法和计算机程序产品

摘要

A user-specific Service Access Manager object is instantiated at a computer in response to a request for access for a user at a client, e.g., an object or other process resident at a second computer. The Service Access Manager object includes a first security identification, e.g., a Security Certificate object, which is specific to the user. A reference for the Service Access Manager object is returned to the client. A service request method call requesting a service is performed to the Service Access Manager object from the client. A user-specific Service object is instantiated at the computer if the first security identification identifies a user authorized to invoke a constructor method of the Service object's class, the Service object including a second security identification specific to the user identified in the first security identification. A reference for the user-specific Service object is returned to the client, which may then perform an operation request method call to the Service object, the operation request method call requesting an operation by the Service object. The operation is conditionally performed based on whether the user identified in the second security identification is authorized to invoke the operation request method. Responses to the service request and operation request methods calls preferably are conditioned upon validation calls to a Security Manager object that checks a security identification and a required method invocation right against an access control list. Related systems and computer program products are discussed.
机译:响应于客户机上的用户对访问的请求,例如驻留在第二计算机上的对象或其他进程,在计算机上实例化特定于用户的服务访问管理器对象。服务访问管理器对象包括特定于用户的第一安全标识,例如安全证书对象。服务访问管理器对象的引用返回给客户端。从客户端对服务访问管理器对象执行请求服务的服务请求方法调用。如果第一安全标识识别出有权调用该服务对象的类的构造方法的用户,则在计算机上实例化特定于用户的Service对象,该Service对象包括特定于在第一安全标识中标识的用户的第二安全标识。特定于用户的Service对象的引用返回给客户端,然后客户端可以执行对Service对象的操作请求方法调用,该操作请求方法调用请求Service对象进行操作。基于在第二安全标识中标识的用户是否被授权调用操作请求方法,有条件地执行该操作。对服务请求和操作请求方法调用的响应最好以对安全管理器对象的验证调用为条件,该对象根据访问控制列表检查安全性标识和所需的方法调用权限。讨论了相关的系统和计算机程序产品。

著录项

  • 公开/公告号AU4040500A

    专利类型

  • 公开/公告日2000-10-23

    原文格式PDF

  • 申请/专利权人 POWERWARE CORPORATION;

    申请/专利号AU20000040405

  • 发明设计人 TIMOTHY A. LOWERY;VINCENT A. GEORGE;

    申请日2000-03-28

  • 分类号G06F9/00;

  • 国家 AU

  • 入库时间 2022-08-22 01:51:48

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号