Invention Grant
- Patent Title: Provisioning system-level permissions using attribute-based access control policies
-
Application No.: US15400388Application Date: 2017-01-06
-
Publication No.: US09973509B2Publication Date: 2018-05-15
- Inventor: Andres Martinelli
- Applicant: AXIOMATICS AB
- Applicant Address: SE Stockholm
- Assignee: AXIOMATICS AB
- Current Assignee: AXIOMATICS AB
- Current Assignee Address: SE Stockholm
- Agency: Buchanan Ingersoll & Rooney P.C.
- Priority: EP14183845 20140905
- Main IPC: G06F17/00
- IPC: G06F17/00 ; H04L29/06 ; G06F21/60

Abstract:
A permissions provisioning module includes a data adapter and a permissions calculator associated with a policy evaluator operable to evaluate an ABAC policy. The module is adapted to interact with a computer system including resources, metadata and an access control mechanism enforcing, in respect of each resource, an access control list associated with the resource. In operation, the data adapter receives metadata for said computer system and assigns values to attributes in the policy based on the metadata. The permissions calculator queries the policy evaluator on combinations of resources and principals of the system using the attribute values thus assigned, and returns permission data. The data adapter formats said permission data into ACLs, for deployment in the computer system.
Public/Granted literature
- US20170126687A1 PROVISIONING SYSTEM-LEVEL PERMISSIONS USING ATTRIBUTE-BASED ACCESS CONTROL POLICIES Public/Granted day:2017-05-04
Information query