Invention Grant
US09401930B2 System and method for using partial evaluation for efficient remote attribute retrieval 有权
用于部分评估的高效远程属性检索的系统和方法

System and method for using partial evaluation for efficient remote attribute retrieval
Abstract:
An attribute-based policy defining subjects' access to resources is enforced by a computer system. A processing means (PDP) in the system communicates with a nearby attribute value source and at least one remote attribute value source and is adapted to evaluate the policy for an access request containing one or more explicit attribute values, which together with the policy define at least one implicit reference to a further attribute value, which is retrievable from one of said attribute value sources. The processing means reduces the policy by substituting attribute values for attributes in the policy if they are contained in the request or retrievable from the nearby source. References to further attributes retrievable from a remote source only are cached together with intermediate results. All attribute values from a given remote source are retrieved on one occasion, and the intermediate results are used to terminate the evaluation.
Information query
Patent Agency Ranking
0/0