FIELD: information technology.
SUBSTANCE: method for implementation of access to computer resources control policy contains steps in which: access control policy is accepted which policy includes policy statements, where policy statements are represented in policy language that abstracts the policy from at least one access verification procedure; predicates are described in policy statements to characterise primitives of access verification procedure, and from predicates, permissions are computed the format of which is proprietary for access verification procedure; access verification procedure configuration is set on the basis of computed permissions, and this configuration provides the access verification procedure with possibility to specify when to grant access; request for access to resources is accepted; and request results are submitted together with reasons - according to access control policy - for which these specific results have been submitted, where reasons are constructed form access control policy itself irrespective to access verification procedure.
EFFECT: more flexible configuration of access verification procedures.
9 cl, 7 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR FORMING A SECURITY MONITOR | 2021 |
|
RU2773108C1 |
INTEGRATED ACCESS AUTHORISATION | 2005 |
|
RU2405198C2 |
DETECTABILITY AND LISTING MECHANISM IN HIERARCHICALLY PROTECTED DATA STORAGE SYSTEM | 2006 |
|
RU2408070C2 |
SYSTEM AND METHOD FOR CONTROLLING THE DELIVERY OF MESSAGES TRANSMITTED BETWEEN PROCESSES FROM DIFFERENT OPERATING SYSTEMS | 2021 |
|
RU2777302C1 |
UNSEALING DATA WITH SEALING ENCLAVE | 2017 |
|
RU2759331C2 |
NETWORK GATEWAY AND METHOD FOR TRANSFERRING DATA FROM A FIRST NETWORK TO A SECOND NETWORK | 2021 |
|
RU2770458C1 |
DATA ACCESS CONTROL SYSTEM AND METHOD | 2021 |
|
RU2790338C1 |
SYSTEMS AND METHODS FOR NETWORK ANALYSIS AND REPORTING | 2015 |
|
RU2677378C2 |
AUTOMATION ARCHITECTURE OF AUTOMATED SYSTEMS | 2015 |
|
RU2714726C2 |
POLICY-CONTROLLED DELEGATION OF ACCOUNT DATA FOR SINGLE REGISTRATION IN NETWORK AND SECURED ACCESS TO NETWORK RESOURCES | 2007 |
|
RU2439692C2 |
Authors
Dates
2012-04-10—Published
2007-05-31—Filed