发明名称 Query interface to policy server
摘要 A scalable access filter that is used together with others like it in a virtual private network to control access by users at clients in the network to information resources provided by servers in the network. Each access filter uses a local copy of an access control data base to determine whether an access request is made by a user. Each user belongs to one or more user groups and each information resource belongs to one or more information sets. Access is permitted or denied according to access policies which define access in terms of the user groups and information sets. The first access filter in the path performs the access check, encrypts and authenticates the request; the other access filters in the path do not repeat the access check. The interface used by applications to determine whether a user has access to an entity is now an SQL entity. The policy server assembles the information needed for the response to the query from various information sources, including source external to the policy server.
申请公布号 US9154489(B2) 申请公布日期 2015.10.06
申请号 US201313967207 申请日期 2013.08.14
申请人 Dell Software Inc. 发明人 Hannel Clifford Lee;May Anthony
分类号 G06F17/30;H04L29/06;G06F21/62 主分类号 G06F17/30
代理机构 Lewis Roca Rothgerber LLP 代理人 Lewis Roca Rothgerber LLP
主权项 1. A method for custom authentication, the method comprising: storing information in memory regarding a plurality of custom-authenticated user groups, wherein each custom-authenticated user group has a dossier, wherein membership of each custom-authenticated user group is determined based on a user dossier and the dossier of the custom-authenticated user group, and wherein the user dossier and the dossier of the custom-authenticated user group are a list of attribute-value pairs; receiving an access request sent over a communication network from a user of a client device, wherein the access request includes authentication information from the user dossier, and wherein the access request is a SQL (structured query language) query; identifying that the access request is associated with a custom-authenticated user group; evaluating the access request with the dossier of the requested customer-authenticated user group; determining that the authentication information in the access request does not meet the requirements of the dossier associated with the requested customer-authenticated user group, wherein the requirements of the dossier associated with the requested custom-authenticated user group includes additional information not provided by the user in the access request; generating a query to one or more databases to obtain additional information to complete the dossier for the user, wherein the completed dossier for the user satisfies the requirements associated with the dossier of the requested customer-authenticated user group; and assigning an access status for the user based on the completed dossier for the user.
地址 Round Rock TX US