Invention Grant
- Patent Title: Evaluating detectability of information in authorization policies
- Patent Title (中): 评估授权策略中信息的可检测性
-
Application No.: US13194349Application Date: 2011-07-29
-
Publication No.: US09251342B2Publication Date: 2016-02-02
- Inventor: Moritz Becker
- Applicant: Moritz Becker
- Applicant Address: US WA Remond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Remond
- Agent Steve Wight; Judy Yee; Micky Minhas
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/57 ; H04L29/06 ; G06F21/60

Abstract:
Techniques for evaluating detectablity of confidential information stored in authorization policies are described. In an example, an authorization policy has a confidential property. The confidential property is defined by whether application of a test probe to the authorization policy results in the grant of access to a resource. A processor automatically determines whether at least one witness policy can be generated that is observationally equivalent to the authorization policy from the perspective of a potential attacker, but the application of the test probe to the witness policy generates an access denial result. In the case that such a witness policy can be generated, an indication that the confidential property cannot be detected using the test probe is output. In the case that such a witness policy cannot be generated, an indication that the confidential property can be detected using the test probe is output.
Public/Granted literature
- US20130031596A1 Evaluating Detectability of Information in Authorization Policies Public/Granted day:2013-01-31
Information query