发明名称 |
A SYSTEM AND METHOD FOR USING PARTIAL EVALUATION FOR EFFICIENT REMOTE ATTRIBUTE RETRIEVAL |
摘要 |
An attribute-based policy defining subjects' access to resources is enforced by a computer system. A processing means (PDP) in the system communicates with a nearby attribute value source and at least one remote attribute value source and is adapted to evaluate the policy for an access request containing one or more explicit attribute values, which together with the policy define at least one implicit reference to a further attribute value, which is retrievable from one of said attribute value sources. The processing means reduces the policy by substituting attribute values for attributes in the policy if they are contained in the request or retrievable from the nearby source. References to further attributes retrievable from a remote source only are cached together with intermediate results. All attribute values from a given remote source are retrieved on one occasion, and the intermediate results are used to terminate the evaluation. |
申请公布号 |
EP2659412(B1) |
申请公布日期 |
2015.11.25 |
申请号 |
EP20110770576 |
申请日期 |
2011.07.07 |
申请人 |
AXIOMATICS AB |
发明人 |
GIAMBIAGI, PABLO EDUARDO;RISSANEN, ERIK |
分类号 |
G06F21/60;G06F21/62;H04L29/06 |
主分类号 |
G06F21/60 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|