ABSTRACTION OF SECURITY POLICY FROM ACCESS CONTROL PROCEDURES AND TRANSFORMING SUCH PROCEDURES INTO OWN REPRESENTATIONS Russian patent published in 2012 - IPC G06F21/00 

Abstract RU 2447497 C2

FIELD: information technology.

SUBSTANCE: method for implementation of access to computer resources control policy contains steps in which: access control policy is accepted which policy includes policy statements, where policy statements are represented in policy language that abstracts the policy from at least one access verification procedure; predicates are described in policy statements to characterise primitives of access verification procedure, and from predicates, permissions are computed the format of which is proprietary for access verification procedure; access verification procedure configuration is set on the basis of computed permissions, and this configuration provides the access verification procedure with possibility to specify when to grant access; request for access to resources is accepted; and request results are submitted together with reasons - according to access control policy - for which these specific results have been submitted, where reasons are constructed form access control policy itself irrespective to access verification procedure.

EFFECT: more flexible configuration of access verification procedures.

9 cl, 7 dwg

Similar patents RU2447497C2

Title Year Author Number
SYSTEM AND METHOD FOR FORMING A SECURITY MONITOR 2021
  • Kulagin Dmitrii Aleksandrovich
  • Burenkov Vladimir Sergeevich
  • Bondarenko Aleksandr Aleksandrovich
RU2773108C1
INTEGRATED ACCESS AUTHORISATION 2005
  • Golan Gilad
  • Vajman Mark
RU2405198C2
DETECTABILITY AND LISTING MECHANISM IN HIERARCHICALLY PROTECTED DATA STORAGE SYSTEM 2006
  • Khanter Dzhejson T.
  • Dubkhashi Kedarnatkh A.
  • Skaria Sajmon
RU2408070C2
SYSTEM AND METHOD FOR CONTROLLING THE DELIVERY OF MESSAGES TRANSMITTED BETWEEN PROCESSES FROM DIFFERENT OPERATING SYSTEMS 2021
  • Simanovskii Andrei Iurevich
  • Rogachev Sergei Viktorovich
  • Pinchuk Stanislav Iurevich
RU2777302C1
UNSEALING DATA WITH SEALING ENCLAVE 2017
  • Costa, Manuel
RU2759331C2
NETWORK GATEWAY AND METHOD FOR TRANSFERRING DATA FROM A FIRST NETWORK TO A SECOND NETWORK 2021
  • Vereshchagin Aleksei Georgievich
  • Kashitsyn Denis Sergeevich
  • Dontsov Maksim Andreevich
  • Morozov Ruslan Iurevich
  • Lukiian Dmitrii Sergeevich
RU2770458C1
DATA ACCESS CONTROL SYSTEM AND METHOD 2021
  • Vereshchagin Aleksei Georgievich
  • Kashitsyn Denis Sergeevich
  • Dontsov Maksim Andreevich
  • Morozov Ruslan Iurevich
  • Lukiian Dmitrii Sergeevich
RU2790338C1
SYSTEMS AND METHODS FOR NETWORK ANALYSIS AND REPORTING 2015
  • Rieke, Malcolm
RU2677378C2
AUTOMATION ARCHITECTURE OF AUTOMATED SYSTEMS 2015
  • Dukhvalov Andrej Petrovich
  • Dyakin Pavel Vladimirovich
  • Kulagin Dmitrij Aleksandrovich
  • Lungu Sergej Borisovich
  • Moiseev Stanislav Vladimirovich
RU2714726C2
POLICY-CONTROLLED DELEGATION OF ACCOUNT DATA FOR SINGLE REGISTRATION IN NETWORK AND SECURED ACCESS TO NETWORK RESOURCES 2007
  • Medvinskij Gennadij
  • Ilak Kristian
  • Khagiu Kostin
  • Parsonz Dzhon Eh.
  • Fatkhalla Mokhamed Ehmad Ehl' Din
  • Lich Pol Dzh.
  • Kamel' Tarek Bukhaa Ehl'-Din Makhmud
RU2439692C2

RU 2 447 497 C2

Authors

Paramasivam Mutkhukrishnan

Rouz Iii Charl'Z F.

Makferson Dehjv M.

Perumal Radzha Pashanivel

Natkh Sat'Jadzhit

Lich Pol Dzh.

Pand'Ja Ravindra Natkh

Dates

2012-04-10Published

2007-05-31Filed