Invention Grant
US08701163B2 Method and system for automatic generation of cache directives for security policy
有权
自动生成用于安全策略的缓存指令的方法和系统
- Patent Title: Method and system for automatic generation of cache directives for security policy
- Patent Title (中): 自动生成用于安全策略的缓存指令的方法和系统
-
Application No.: US13152943Application Date: 2011-06-03
-
Publication No.: US08701163B2Publication Date: 2014-04-15
- Inventor: Christopher John Hockings , Simon Gilbert Canning , Scott Anthony Exton , Neil Ian Readshaw
- Applicant: Christopher John Hockings , Simon Gilbert Canning , Scott Anthony Exton , Neil Ian Readshaw
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
An authorization method is implemented in an authorization engine external to an authorization server. The authorization server includes a cache. The external authorization engine comprises an authorization decision engine, and a policy analytics engine. The method begins when the authorization decision engine receives a request for an authorization decision. The request is generated (at the authorization server) following receipt of a client request for which an authorization decision is not then available at the server. The authorization decision engine determines an authorization policy to apply to the client request, applies the policy, and generates an authorization decision. The authorization decision is then provided to the policy analytics engine, which stores previously-generated potential cache directives that may be applied to the authorization decision. Preferably, the cache directives are generated in an off-line manner (e.g., during initialization) by examining each security policy and extracting one or more cache dimensions associated with each such policy. The policy analytics engine determines an applicable cache directive, and the decision is augmented to include that cache directive. The decision (including the cache directive) is then returned to the authorization server, where the decision is applied to process the client request. The cache directive is then cached for re-use at the authorization server.
Public/Granted literature
- US20120311674A1 Method and system for automatic generation of cache directives for security policy Public/Granted day:2012-12-06
Information query