Invention Grant
US09251342B2 Evaluating detectability of information in authorization policies 有权
评估授权策略中信息的可检测性

Evaluating detectability of information in authorization policies
Abstract:
Techniques for evaluating detectablity of confidential information stored in authorization policies are described. In an example, an authorization policy has a confidential property. The confidential property is defined by whether application of a test probe to the authorization policy results in the grant of access to a resource. A processor automatically determines whether at least one witness policy can be generated that is observationally equivalent to the authorization policy from the perspective of a potential attacker, but the application of the test probe to the witness policy generates an access denial result. In the case that such a witness policy can be generated, an indication that the confidential property cannot be detected using the test probe is output. In the case that such a witness policy cannot be generated, an indication that the confidential property can be detected using the test probe is output.
Public/Granted literature
Information query
Patent Agency Ranking
0/0