Invention Grant
US07752439B2 Method and apparatus for providing process-based access controls on computer resources
失效
用于在计算机资源上提供基于过程的访问控制的方法和装置
- Patent Title: Method and apparatus for providing process-based access controls on computer resources
- Patent Title (中): 用于在计算机资源上提供基于过程的访问控制的方法和装置
-
Application No.: US12025867Application Date: 2008-02-05
-
Publication No.: US07752439B2Publication Date: 2010-07-06
- Inventor: Mounir Emil Basibes , Julianne Frances Haugh
- Applicant: Mounir Emil Basibes , Julianne Frances Haugh
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Yee & Associates, P.C.
- Agent Matthew W. Baca
- Main IPC: H04L9/00
- IPC: H04L9/00 ; G06F21/00

Abstract:
A method, apparatus, and computer instructions for process-based access controls on computer resources to processes. An access mechanism is provided in which a specific invoker obtains an object access identity (ACI). Another mechanism is provided in which a specific object, such as a file system resource, requires a specific object access identity to obtain one of the forms of access denoted by an access control list. A process may “grant” an identifier that is later “required” for a system resource access. Objects may specify their own access requirements and permitted access modes. The granted identifier, ACI, is stored in the process's credentials once these credentials match a specific “grant” entry in the access control list. This identifier has no meaning outside of being used to make an access decision for a specific resource. When a process tries to access the object, the object's access control list is scanned for “required” entries. If a match occurs between the “required” entry's identifier and the ACI stored, access to the object is granted with access rights specified in the “require” entries.
Public/Granted literature
- US20080289034A1 METHOD AND APPARATUS FOR PROVIDING PROCESS-BASED ACCESS CONTROLS ON COMPUTER RESOURCES Public/Granted day:2008-11-20
Information query