Invention Grant
- Patent Title: Delegation-based authorization
- Patent Title (中): 基于授权的授权
-
Application No.: US12789277Application Date: 2010-05-27
-
Publication No.: US09160738B2Publication Date: 2015-10-13
- Inventor: Moritz Becker
- Applicant: Moritz Becker
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agent Steve Wight; Judy Yee; Micky Minhas
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Delegation-based authorization is described. In one example, a reference monitor receives from a first entity a request and a credential statement comprising a delegation of authority over a fact to a further entity. An authorization node then determines whether the further entity consents to provide the fact to the first entity and evaluates the request in accordance with an authorization policy and the credential statement. In another example, an assertion comprising a statement delegating authority over a fact to a further entity is received at an authorization node from a first entity. An authorization policy is then used to determine that the first entity vouches for the fact if each of these conditions are met: i) the first entity consents to import the fact from the further entity, ii) the further entity consents to export the fact to the first entity, and iii) the further entity asserts the fact.
Public/Granted literature
- US20110296497A1 Delegation-Based Authorization Public/Granted day:2011-12-01
Information query