Invention Grant
US09231974B2 Dynamic policy-based entitlements from external data repositories
有权
来自外部数据存储库的动态基于策略的权利
- Patent Title: Dynamic policy-based entitlements from external data repositories
- Patent Title (中): 来自外部数据存储库的动态基于策略的权利
-
Application No.: US13839798Application Date: 2013-03-15
-
Publication No.: US09231974B2Publication Date: 2016-01-05
- Inventor: Miguel Pedroza , Craig Robert William Forster , Umesh Prithviraj Adtani , Yogesh Suresh Shukla
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. Labaw; David H. Judson
- Main IPC: G06F17/00
- IPC: G06F17/00 ; H04L29/06

Abstract:
A machine-implemented method for evaluating a context-based (e.g., XACML) policy having a set of attributes formulates a search against one or more existing external repositories using a query that is dynamically-generated based on the security policy being evaluated. The approach shifts the building of a candidate set of potentially-allowable resources to the authorization engine (e.g., a Policy Decision Point (PDP)). In operation, an application calls the PDP using an entitlement request and, in response, the PDP builds the candidate set of values based on the defined security policy by generating a query to an external data repository and receiving the results of that query. This approach enables a policy-driven entitlement query at runtime.
Public/Granted literature
- US20140282831A1 Dynamic policy-based entitlements from external data repositories Public/Granted day:2014-09-18
Information query