FIELD: physics.
SUBSTANCE: invention relates to computer engineering. Disclosed is a security architecture which implements authorization control, comprising: a computing device comprising at least one processor, input and output facilities interacting with at least one processor, and a storage medium comprising an operating system and a plurality of instructions executable on at least one processor; where the data medium also contains a security subsystem, executed by means of at least one processor, which during execution implements: a security server which enables to apply rules from a plurality of rules defined within one or more security policies, to parameters from the security context to make a verdict determining whether the action requested by the entity is allowed, where each security policy corresponds to a separate interface; multiple gateways intended for interaction with security server, where each gateway from a plurality of gateways corresponds to only one entity from a plurality of entities, and where a plurality of gateways enables to track requested actions on the side of corresponding entities, and for each requested action to determine a security context, determine an applicable security policy for the requested action based on a defined security context and request a verdict from the security server through an interface corresponding to the applicable security policy; and means of interaction of system components, connecting plurality of gateways and plurality of entities, designed to allow or prohibit the requested entity action based on the verdict received by the corresponding gateway from the security server.
EFFECT: technical result consists in improvement of information security of automated systems by dividing responsibility for calculating security verdict based on given policies and application of this verdict.
14 cl, 6 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR ACCESS CONTROL IN ELECTRONIC UNITS OF VEHICLE CONTROL | 2019 |
|
RU2750626C2 |
SYSTEM AND METHOD FOR ENSURING INTERPROCESS COMMUNICATION IN ELECTRONIC CONTROL UNITS OF VEHICLES | 2020 |
|
RU2749157C1 |
SYSTEM AND METHOD FOR FORMING A SECURITY MONITOR | 2021 |
|
RU2773108C1 |
NETWORK GATEWAY AND METHOD FOR TRANSFERRING DATA FROM A FIRST NETWORK TO A SECOND NETWORK | 2021 |
|
RU2770458C1 |
DATA ACCESS CONTROL SYSTEM AND METHOD | 2021 |
|
RU2790338C1 |
SYSTEM AND METHOD FOR CONTROLLING THE DELIVERY OF MESSAGES TRANSMITTED BETWEEN PROCESSES FROM DIFFERENT OPERATING SYSTEMS | 2021 |
|
RU2777302C1 |
CONFIGURATION OF ISOLATED EXTENSIONS AND DEVICE DRIVERS | 2006 |
|
RU2443012C2 |
SYSTEM AND METHOD OF PROTECTING AUTOMATED SYSTEMS USING GATEWAY | 2019 |
|
RU2724796C1 |
SYSTEM AND METHOD OF GATEWAY CONFIGURATION FOR AUTOMATED SYSTEMS PROTECTION | 2019 |
|
RU2746105C2 |
SYSTEM AND METHOD OF SELECTING SYNCHRONOUS OR ASYNCHRONOUS INTERPROCESS INTERACTION | 2013 |
|
RU2568292C2 |
Authors
Dates
2020-02-20—Published
2015-06-30—Filed