发明名称 Token-based access control
摘要 Systems and methods for enabling token-based access control to data are provided. In particular, some embodiments use a token-based access management system to allow or restrict an individual's ability to access data. The access management system uses tokens to define rules (e.g., a Boolean matching rule or algorithm that results in a true/false output indicating the decision) within the access management system to determine if the token is valid and if the individual should be granted access to the requested data. Tokens may further have tool constraints for controlling access. In some cases, the tokens may expire upon completion of a task or after a pre-set amount of time. A generic workflow utilizing tokens and at least one specific workflow showing employees utilizing tokens as part of performing a task responsive to a user.
申请公布号 US8887260(B2) 申请公布日期 2014.11.11
申请号 US201213660980 申请日期 2012.10.25
申请人 Facebook, Inc. 发明人 Marcotte Garrett
分类号 H04L29/06;G06F21/62 主分类号 H04L29/06
代理机构 Perkins Coie LLP 代理人 Perkins Coie LLP
主权项 1. A method, comprising: assigning a set of default tokens to a user that include a default set of permissions or restrictions for access the data; assigning, using a processor, a set of workflow specific tokens to the user in response to a workflow event, wherein the set of workflow specific tokens grant the user temporary access to a portion of data, wherein the set of workflow specific tokens and the default tokens include a cryptographic message authentication code (MAC); receiving a request from a workflow tool to allow the user to access data; and using the workflow specific tokens assigned to the user to determine which portion of the data can be accessed, wherein the set of workflow specific tokens includes two or more workflow tokens that each provides access to a different portion of data, and the workflow specific tokens and the set of default tokens each includes a matching rule.
地址 Menlo Park CA US