发明名称 Provisioning authorization claims using attribute-based access-control policies
摘要 <p>Disclosed are methods and devices for provisioning authorization claims, which are enforced to control access of users to objects (resources) in a computer system (330), and which are to be equivalent to an attribute-based access control (ABAC) policy. A policy converter according to the invention includes a policy processor (310) processing the policy by partial evaluation against attribute values of the users, objects or permission levels in the system and outputting simplified policies, which are subject to reverse evaluation in a reverse policy evaluator (320), whereby users, objects and permission levels to be associated by way of a single authorization claim are obtained. Responsible for the defining of the authorization claim and its distribution in the computer system are an authorization claim generator (330) and an authorization claim distribution interface (340). The invention may be so configured as to return a single authorization claim for each combination of an object and a permission level.</p>
申请公布号 EP2631841(A2) 申请公布日期 2013.08.28
申请号 EP20130156731 申请日期 2013.02.26
申请人 AXIOMATICS AB 发明人 KARPINSKI, PETER;GIAMBIAGI, PABLO
分类号 G06F21/60;G06F21/62 主分类号 G06F21/60
代理机构 代理人
主权项
地址