发明名称 Method, system, and computer program product for facilitating communication in an interoperability network
摘要 Methods and apparatus are described for facilitating communication among a plurality of entities via an interoperability network. Each entity has policy data corresponding thereto governing interaction with the entity via the interoperability network. A message is transmitted from a first one of the entities to a second one of the entities. The first entity has first policy data corresponding thereto and the second entity has second policy data corresponding thereto. The transmitted message was handled in the network according to combined policy data representing a combination of the first and second policy data.
申请公布号 US8966577(B2) 申请公布日期 2015.02.24
申请号 US201314055817 申请日期 2013.10.16
申请人 salesforce.com, inc. 发明人 Lerner Alexander;Dewey Michael K.
分类号 G06F17/00;H04L29/06;G06F9/54;G06F21/62;H04L29/08 主分类号 G06F17/00
代理机构 Zilka-Kotab, PC 代理人 Zilka-Kotab, PC
主权项 1. A computer program product, comprising a non-transitory computer usable medium having a computer readable program code embodied therein, the computer readable program code adapted to be executed to implement a method, the method comprising: storing policy data for a plurality of entities, including: storing first policy data corresponding to a first one of the entities, the first one of the entities including a first role associated with a user used to control access to information, andstoring second policy data of a second one of the entities, the second one of the entities including a group defined by a second role, the group including the user, where the second policy data is used for authorization of the user; receiving a message from the user for being transmitted in a network, the message for accessing by the user the information; in response to the receipt of the message, identifying the first policy data of the first role and the second policy data of the group; in response to the receipt of the message, merging the first policy data of the first role and the second policy data of the group to produce a combined policy; evaluating the combined policy with respect to the received message; determining whether the message is associated with a policy violation, based on the evaluation of the combined policy; allowing the user to access the information when the determination is that the message is not associated with the policy violation; and denying the user access to the information when the determination is that the message is associated with the policy violation.
地址 San Francisco CA US