Invention Grant
US08881226B2 Provisioning user permissions using attribute-based access-control policies
有权
使用基于属性的访问控制策略配置用户权限
- Patent Title: Provisioning user permissions using attribute-based access-control policies
- Patent Title (中): 使用基于属性的访问控制策略配置用户权限
-
Application No.: US13621338Application Date: 2012-09-17
-
Publication No.: US08881226B2Publication Date: 2014-11-04
- Inventor: Pablo Giambiagi
- Applicant: Pablo Giambiagi
- Applicant Address: SE Stockholm
- Assignee: Axiomatics AB
- Current Assignee: Axiomatics AB
- Current Assignee Address: SE Stockholm
- Agency: Nixon & Vanderhye P.C.
- Main IPC: G06F17/00
- IPC: G06F17/00 ; H04L29/06 ; G06F7/04 ; G06F12/14 ; G06F13/00 ; G06F17/30 ; G06F7/00

Abstract:
An attribute-based access control policy (e.g., XACML policy) for a set of elements depends on attributes carried by elements in one of several predefined categories. In order to evaluate such policy for a set of elements, the invention provides a method including the steps of (I) selecting a primary category; (II) partitioning the elements in the primary category into equivalence classes with respect to their influence on the policy; and (III) using the equivalence classes to replace at least one policy evaluation by a deduction. The result of the evaluation may be represented as an access matrix in backward-compatible format. The efficiency of the policy evaluation may be further improved by applying partial policy evaluation at intermediate stages, by forming combined equivalence classes containing n-tuples of elements and/or by analyzing the influence of each element by extracting functional expressions of maximal length from the policy.
Public/Granted literature
- US20130081105A1 PROVISIONING USER PERMISSIONS USING ATTRIBUTE-BASED ACCESS-CONTROL POLICIES Public/Granted day:2013-03-28
Information query