首页> 外国专利> Method and system for advanced role-based access control in distributed and centralized computer systems

Method and system for advanced role-based access control in distributed and centralized computer systems

机译:分布式和集中式计算机系统中基于角色的高级访问控制的方法和系统

摘要

A method and system for registration, authorization, and control of access rights in a computer system. Access rights of subjects on objects in a computer system are controlled using parameterized role types that can be instantiated into role instances equivalent to roles or groups. The required parameters are provided by the subject of the computer system, e.g. by a person, a job position, or an organization unit. Furthermore, relative resource sets are instantiated into concrete resource sets and individual resources by using the same parameter values as for instantiating the role types. Authorization and control of access rights include capability lists providing the access rights of the subjects on the objects of a computer system on a per subject basis. Furthermore, access control lists are derived from capability lists, so that access rights of the subjects on the respective objects are provided.
机译:一种用于在计算机系统中注册,授权和控制访问权限的方法和系统。使用参数化的角色类型控制对象对计算机系统中对象的访问权限,这些角色类型可以实例化为等效于角色或组的角色实例。所需的参数是由计算机系统的主体提供的,例如。由一个人,一个职位或一个组织单位。此外,通过使用与实例化角色类型相同的参数值,将相对资源集实例化为具体资源集和单个资源。访问权限的授权和控制包括功能列表,该功能列表提供了基于每个主题的主题对计算机系统对象的访问权限。此外,访问控制列表是从能力列表派生的,从而提供了对象在各个对象上的访问权限。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号