首页> 外国专利> System for providing user access control within a distributed data processing system having multiple resource managers

System for providing user access control within a distributed data processing system having multiple resource managers

机译:用于在具有多个资源管理器的分布式数据处理系统中提供用户访问控制的系统

摘要

The method of the present invention may be utilized to provide user access control for a plurality of resource objects within a distributed data processing system having a plurality of resource managers. A reference monitor service is established and a plurality of access control profiles are stored therein. Thereafter, selected access control profile information may be communicated between the reference monitor service and a resource manager in response to an attempted access of a particular resource object controlled by that resource manager. A resource manager may utilize this communication technique to retrieve, modify, or delete a selected access control profile, as desired. Further, the resource manager may utilize this communication technique to control access to a resource object by utilizing the information contained within the access control profile to determine if the requester is authorized to access the resource object and whether or not the requester has been granted sufficient authority to take selected actions with respect to that resource object. In a preferred embodiment of the present invention, each access control profile may include access control information relating to a selected user; a selected resource object; a selected group of users; a specified level of authority associated with a selected user; a selected set of resource objects; or, a predetermined set of resource objects and a selected list of users each authorized to access at least a portion of said predetermined set of resource objects.
机译:本发明的方法可以用于为具有多个资源管理器的分布式数据处理系统内的多个资源对象提供用户访问控制。建立参考监视服务,并在其中存储多个访问控制配置文件。此后,可以响应于由该资源管理器控制的特定资源对象的尝试访问,在参考监视器服务和资源管理器之间传送所选的访问控制简档信息。资源管理器可以根据需要利用此通信技术来检索,修改或删除所选的访问控制配置文件。此外,资源管理器可以利用访问控制配置文件中包含的信息来确定请求者是否被授权访问资源对象,以及是否已授予请求者足够的权限,从而利用该通信技术来控制对资源对象的访问。针对该资源对象采取选定的操作。在本发明的优选实施例中,每个访问控制简档可以包括与所选择的用户有关的访问控制信息。选定的资源对象;选定的用户组;与所选用户相关联的指定权限级别;一组选定的资源对象;或者,资源对象的预定集合和每个用户被授权访问所述资源对象的预定集合的至少一部分的用户的选定列表。

著录项

  • 公开/公告号US5263165A

    专利类型

  • 公开/公告日1993-11-16

    原文格式PDF

  • 申请/专利权人 INTERNATIONAL BUSINESS MACHINES CORPORATION;

    申请/专利号US19900480442

  • 发明设计人 FREDERICK L. JANIS;

    申请日1990-02-15

  • 分类号G06F12/00;

  • 国家 US

  • 入库时间 2022-08-22 04:32:40

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号