发明名称 POLICY SEPARATION
摘要 The present invention relates to a policy decision point for interacting with a computer system comprising a plurality of resources, to which subjects' access is controlled by corresponding policy enforcement points. The PDP comprises: a memory storing at least two policy packages, each controlling access rights to resources, and a connection table associating each policy package with an end point address; a network interface operable to communicate with the PEPs, wherein the network interface obtains access requests from a PEP and returns access decisions to the PEP, each access request comprising an end point address for directing the access request to the PDP; and a processor operable to: analyze an access request and determine, based on the end point address receiving the access request, an associated policy package; and evaluate the access request against the policy package thus determined.
申请公布号 US2016234253(A1) 申请公布日期 2016.08.11
申请号 US201615016667 申请日期 2016.02.05
申请人 Axiomatics AB 发明人 Rissanen Erik
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A policy decision point, PDP for interacting with a computer system comprising a plurality of resources, to which subjects' access is controlled by corresponding policy enforcement points, PEPs, the PDP comprising: a memory configured to store at least two distinct policy packages, each controlling access rights to one or more of the resources in the computer system, and a connection table associating each of said at least two policy packages with one or more end point addresses; a network interface operable to communicate with at least two of the PEPs, wherein the network interface is arranged to obtain one or more access requests from a PEP and return one or more access decisions to a requesting PEP, each access request comprising an end point address associated with the PDP for directing the access request to the PDP; and a processor operable to: analyze an access request obtained by the network interface and determine, based on the end point address receiving the access request, an associated one of said at least two policy packages; andevaluate the access request against the policy package thus determined, thereby obtaining an access decision to be returned to and enforced by the PEP.
地址 Stockholm SE