CN101366040A - 用户对于对象的访问的管理 - Google Patents
用户对于对象的访问的管理 Download PDFInfo
- Publication number
- CN101366040A CN101366040A CNA2007800019129A CN200780001912A CN101366040A CN 101366040 A CN101366040 A CN 101366040A CN A2007800019129 A CNA2007800019129 A CN A2007800019129A CN 200780001912 A CN200780001912 A CN 200780001912A CN 101366040 A CN101366040 A CN 101366040A
- Authority
- CN
- China
- Prior art keywords
- user
- server
- access
- access right
- strategy
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F17/00—Digital computing or data processing equipment or methods, specially adapted for specific functions
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2141—Access rights, e.g. capability lists, access control lists, access tables, access matrices
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Physics & Mathematics (AREA)
- Databases & Information Systems (AREA)
- Software Systems (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Data Mining & Analysis (AREA)
- Mathematical Physics (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (20)
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US11/325,930 | 2006-01-05 | ||
US11/325,930 US20070156691A1 (en) | 2006-01-05 | 2006-01-05 | Management of user access to objects |
PCT/US2007/000247 WO2007081785A1 (en) | 2006-01-05 | 2007-01-04 | Management of user access to objects |
Publications (2)
Publication Number | Publication Date |
---|---|
CN101366040A true CN101366040A (zh) | 2009-02-11 |
CN101366040B CN101366040B (zh) | 2010-12-01 |
Family
ID=38225843
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN2007800019129A Expired - Fee Related CN101366040B (zh) | 2006-01-05 | 2007-01-04 | 用于管理用户对于包含对象的服务器的访问的方法和系统 |
Country Status (7)
Country | Link |
---|---|
US (1) | US20070156691A1 (zh) |
EP (1) | EP1974311A4 (zh) |
JP (1) | JP2009522694A (zh) |
KR (1) | KR20080083131A (zh) |
CN (1) | CN101366040B (zh) |
RU (1) | RU2430413C2 (zh) |
WO (1) | WO2007081785A1 (zh) |
Cited By (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102771086A (zh) * | 2009-12-23 | 2012-11-07 | 思杰系统有限公司 | 用于设备的虚拟服务器的侦听策略的系统和方法 |
CN107636666A (zh) * | 2015-07-08 | 2018-01-26 | 谷歌有限责任公司 | 用于控制对于计算设备上的应用的准许请求的方法和系统 |
CN108628879A (zh) * | 2017-03-19 | 2018-10-09 | 上海格尔安全科技有限公司 | 一种带优先级策略的访问控制构造的检索方法 |
Families Citing this family (27)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20080228700A1 (en) | 2007-03-16 | 2008-09-18 | Expanse Networks, Inc. | Attribute Combination Discovery |
NO326590B1 (no) * | 2007-04-16 | 2009-01-19 | Kubekit As | Fremgangsmate og anordning for verifikasjon av informasjonstilgang i IKT-system med flere sikkerhetsdimensjoner og sikkerhetsniva. |
US20090157686A1 (en) * | 2007-12-13 | 2009-06-18 | Oracle International Corporation | Method and apparatus for efficiently caching a system-wide access control list |
US9172707B2 (en) * | 2007-12-19 | 2015-10-27 | Microsoft Technology Licensing, Llc | Reducing cross-site scripting attacks by segregating HTTP resources by subdomain |
US9047485B2 (en) * | 2008-03-12 | 2015-06-02 | International Business Machines Corporation | Integrated masking for viewing of data |
EP2304578A4 (en) * | 2008-06-13 | 2012-08-29 | Hewlett Packard Development Co | HIERARCHICAL POLICY MANAGEMENT |
US8990896B2 (en) * | 2008-06-24 | 2015-03-24 | Microsoft Technology Licensing, Llc | Extensible mechanism for securing objects using claims |
FR2934392B1 (fr) * | 2008-07-22 | 2010-08-13 | Jean Patrice Glafkides | Procede pour gerer des objets accessibles a des utilisateurs et dispositif informatique implique par la mise en oeuvre du procede |
US8689289B2 (en) * | 2008-10-02 | 2014-04-01 | Microsoft Corporation | Global object access auditing |
US8108406B2 (en) * | 2008-12-30 | 2012-01-31 | Expanse Networks, Inc. | Pangenetic web user behavior prediction system |
WO2010077336A1 (en) | 2008-12-31 | 2010-07-08 | 23Andme, Inc. | Finding relatives in a database |
US8689004B2 (en) | 2010-11-05 | 2014-04-01 | Microsoft Corporation | Pluggable claim providers |
EP2466853B1 (en) * | 2010-12-17 | 2014-10-08 | Alcatel Lucent | Control of connection between devices for controlling the initiation, routing and security of connections between devices |
US8429191B2 (en) * | 2011-01-14 | 2013-04-23 | International Business Machines Corporation | Domain based isolation of objects |
US8983985B2 (en) | 2011-01-28 | 2015-03-17 | International Business Machines Corporation | Masking sensitive data of table columns retrieved from a database |
US8930410B2 (en) | 2011-10-03 | 2015-01-06 | International Business Machines Corporation | Query transformation for masking data within database objects |
US8898593B2 (en) * | 2011-10-05 | 2014-11-25 | Microsoft Corporation | Identification of sharing level |
US9329784B2 (en) * | 2011-10-13 | 2016-05-03 | Microsoft Technology Licensing, Llc | Managing policies using a staging policy and a derived production policy |
US9189643B2 (en) | 2012-11-26 | 2015-11-17 | International Business Machines Corporation | Client based resource isolation with domains |
US9838424B2 (en) * | 2014-03-20 | 2017-12-05 | Microsoft Technology Licensing, Llc | Techniques to provide network security through just-in-time provisioned accounts |
RU2659743C1 (ru) * | 2017-02-08 | 2018-07-03 | Акционерное общество "Лаборатория Касперского" | Система и способ контроля доступа на основе ACL |
US10757128B2 (en) | 2017-06-29 | 2020-08-25 | Amazon Technologies, Inc. | Security policy analyzer service and satisfiability engine |
US10630695B2 (en) | 2017-06-29 | 2020-04-21 | Amazon Technologies, Inc. | Security policy monitoring service |
US10922423B1 (en) * | 2018-06-21 | 2021-02-16 | Amazon Technologies, Inc. | Request context generator for security policy validation service |
US11483317B1 (en) | 2018-11-30 | 2022-10-25 | Amazon Technologies, Inc. | Techniques for analyzing security in computing environments with privilege escalation |
US11627126B2 (en) * | 2020-08-20 | 2023-04-11 | Bank Of America Corporation | Expedited authorization and access management |
EP4092556A1 (en) * | 2021-05-20 | 2022-11-23 | Nordic Semiconductor ASA | Bus decoder |
Family Cites Families (20)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JPH087709B2 (ja) * | 1989-05-15 | 1996-01-29 | インターナシヨナル・ビジネス・マシーンズ・コーポレーシヨン | アクセス特権制御方法及びシステム |
JPH0771094B2 (ja) * | 1989-05-19 | 1995-07-31 | オムロン株式会社 | 通信ネットワークシステム |
US5187790A (en) * | 1989-06-29 | 1993-02-16 | Digital Equipment Corporation | Server impersonation of client processes in an object based computer operating system |
US5787427A (en) * | 1996-01-03 | 1998-07-28 | International Business Machines Corporation | Information handling system, method, and article of manufacture for efficient object security processing by grouping objects sharing common control access policies |
FR2745967B1 (fr) * | 1996-03-07 | 1998-04-17 | Bull Cp8 | Procede de securisation des acces d'une station a au moins un serveur et dispositif mettant en oeuvre le procede |
US5991879A (en) * | 1997-10-23 | 1999-11-23 | Bull Hn Information Systems Inc. | Method for gradual deployment of user-access security within a data processing system |
US6119153A (en) * | 1998-04-27 | 2000-09-12 | Microsoft Corporation | Accessing content via installable data sources |
US6832120B1 (en) * | 1998-05-15 | 2004-12-14 | Tridium, Inc. | System and methods for object-oriented control of diverse electromechanical systems using a computer network |
US6182142B1 (en) * | 1998-07-10 | 2001-01-30 | Encommerce, Inc. | Distributed access management of information resources |
WO2000004483A2 (en) * | 1998-07-15 | 2000-01-27 | Imation Corp. | Hierarchical data storage management |
US6785810B1 (en) * | 1999-08-31 | 2004-08-31 | Espoc, Inc. | System and method for providing secure transmission, search, and storage of data |
US6606659B1 (en) * | 2000-01-28 | 2003-08-12 | Websense, Inc. | System and method for controlling access to internet sites |
US6883101B1 (en) * | 2000-02-08 | 2005-04-19 | Harris Corporation | System and method for assessing the security posture of a network using goal oriented fuzzy logic decision rules |
US7096502B1 (en) * | 2000-02-08 | 2006-08-22 | Harris Corporation | System and method for assessing the security posture of a network |
US7260718B2 (en) * | 2001-04-26 | 2007-08-21 | International Business Machines Corporation | Method for adding external security to file system resources through symbolic link references |
US20020184516A1 (en) * | 2001-05-29 | 2002-12-05 | Hale Douglas Lavell | Virtual object access control mediator |
US7401235B2 (en) * | 2002-05-10 | 2008-07-15 | Microsoft Corporation | Persistent authorization context based on external authentication |
CN100437550C (zh) * | 2002-09-24 | 2008-11-26 | 武汉邮电科学研究院 | 一种以太网认证接入的方法 |
US7243105B2 (en) * | 2002-12-31 | 2007-07-10 | British Telecommunications Public Limited Company | Method and apparatus for automatic updating of user profiles |
JP4368184B2 (ja) * | 2003-11-19 | 2009-11-18 | 株式会社日立製作所 | ブラックリストによる緊急アクセス遮断装置 |
-
2006
- 2006-01-05 US US11/325,930 patent/US20070156691A1/en not_active Abandoned
-
2007
- 2007-01-04 KR KR1020087016353A patent/KR20080083131A/ko not_active Application Discontinuation
- 2007-01-04 JP JP2008549568A patent/JP2009522694A/ja active Pending
- 2007-01-04 CN CN2007800019129A patent/CN101366040B/zh not_active Expired - Fee Related
- 2007-01-04 WO PCT/US2007/000247 patent/WO2007081785A1/en active Application Filing
- 2007-01-04 RU RU2008127360/08A patent/RU2430413C2/ru not_active IP Right Cessation
- 2007-01-04 EP EP07717902A patent/EP1974311A4/en not_active Ceased
Cited By (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102771086A (zh) * | 2009-12-23 | 2012-11-07 | 思杰系统有限公司 | 用于设备的虚拟服务器的侦听策略的系统和方法 |
CN102771086B (zh) * | 2009-12-23 | 2016-10-12 | 思杰系统有限公司 | 用于设备的虚拟服务器的侦听策略的系统和方法 |
CN107636666A (zh) * | 2015-07-08 | 2018-01-26 | 谷歌有限责任公司 | 用于控制对于计算设备上的应用的准许请求的方法和系统 |
CN107636666B (zh) * | 2015-07-08 | 2021-04-20 | 谷歌有限责任公司 | 用于控制对于计算设备上的应用的准许请求的方法和系统 |
CN108628879A (zh) * | 2017-03-19 | 2018-10-09 | 上海格尔安全科技有限公司 | 一种带优先级策略的访问控制构造的检索方法 |
CN108628879B (zh) * | 2017-03-19 | 2023-04-07 | 上海格尔安全科技有限公司 | 一种带优先级策略的访问控制构造的检索方法 |
Also Published As
Publication number | Publication date |
---|---|
EP1974311A4 (en) | 2010-04-07 |
KR20080083131A (ko) | 2008-09-16 |
US20070156691A1 (en) | 2007-07-05 |
WO2007081785A1 (en) | 2007-07-19 |
RU2430413C2 (ru) | 2011-09-27 |
EP1974311A1 (en) | 2008-10-01 |
JP2009522694A (ja) | 2009-06-11 |
RU2008127360A (ru) | 2010-01-10 |
CN101366040B (zh) | 2010-12-01 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101366040B (zh) | 用于管理用户对于包含对象的服务器的访问的方法和系统 | |
US20200228574A1 (en) | Policy management for data migration | |
CN102112990B (zh) | 为计算过程授予最小特权访问 | |
EP1946238B1 (en) | Operating system independent data management | |
US8984291B2 (en) | Access to a computing environment by computing devices | |
CN103597494B (zh) | 用于管理文档的数字使用权限的方法和设备 | |
WO2017054985A1 (en) | Access control | |
WO2017021154A1 (en) | Access control | |
EP3329408A1 (en) | Expendable access control | |
CN102667719A (zh) | 基于资源属性控制资源访问 | |
CN101411163A (zh) | 跟踪网格系统中的安全执行的系统和方法 | |
CN115552441A (zh) | 低信任特权访问管理 | |
EP3805962B1 (en) | Project-based permission system | |
JP2006107505A (ja) | アクセス認可のapi | |
JP3756397B2 (ja) | アクセス制御方法およびアクセス制御装置および記録媒体 | |
KR20010044823A (ko) | 컴퓨터에서 사용자 인증이 필요한 자료의 보호방법 및그에 관한 시스템 | |
JP2005258606A (ja) | 情報漏洩監査機能付きネットワークシステム | |
JP7388707B2 (ja) | 情報処理装置、情報処理システム、情報処理方法、及びプログラム | |
Peterkin et al. | Role based access control for uddi inquiries | |
WO2022240563A1 (en) | Abnormally permissive role definition detection systems | |
Jermyn et al. | Out of the Sandbox: Third Party Validation for Java Applications | |
TR2023006911T2 (tr) | Şi̇freli̇ dosya kontrolü | |
Arnab et al. | Investigation of a kernel level DRM implementation | |
Scabby et al. | Using Hashing to Maintain Data Integrity in Cloud Computing Systems |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
ASS | Succession or assignment of patent right |
Owner name: MICROSOFT TECHNOLOGY LICENSING LLC Free format text: FORMER OWNER: MICROSOFT CORP. Effective date: 20150514 |
|
C41 | Transfer of patent application or patent right or utility model | ||
TR01 | Transfer of patent right |
Effective date of registration: 20150514 Address after: Washington State Patentee after: Micro soft technique license Co., Ltd Address before: Washington State Patentee before: Microsoft Corp. |
|
CF01 | Termination of patent right due to non-payment of annual fee | ||
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20101201 Termination date: 20180104 |