Invention Grant
- Patent Title: Evidence-based application security
- Patent Title (中): 循证应用安全
-
Application No.: US10705756Application Date: 2003-11-10
-
Publication No.: US07669238B2Publication Date: 2010-02-23
- Inventor: Gregory D. Fee , Aaron Goldfeder , John M. Hawkins , Jamie L. Cool , Sebastian Lange , Sergey Khorun
- Applicant: Gregory D. Fee , Aaron Goldfeder , John M. Hawkins , Jamie L. Cool , Sebastian Lange , Sergey Khorun
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agency: Lee & Hayes, PLLC
- Main IPC: H04L9/00
- IPC: H04L9/00

Abstract:
Evidence-based application security may be implemented at the application and/or application group levels. A manifest may be provided defining at least one trust condition for the application or application group. A policy manager evaluates application evidence (e.g., an XrML license) for an application or group of applications relative to the manifest. The application is only granted permissions on the computer system if the application evidence indicates that the application is trusted. Similarly, a group of applications are only granted permissions on the computer system if the evidence indicates that the group of applications is trusted. If the application evidence satisfies the at least one trust condition defined by the manifest, the policy manager generates a permission grant set for each code assembly that is a member of the at least one application. Evidence may be further evaluated for code assemblies that are members of the trusted application or application group.
Public/Granted literature
- US20040148514A1 Evidence-based application security Public/Granted day:2004-07-29
Information query