发明名称 PROVISIONING USER PERMISSIONS USING ATTRIBUTE-BASED ACCESS-CONTROL POLICIES
摘要 An attribute-based access control policy (e.g., XACML policy) for a set of elements depends on attributes carried by elements in one of several predefined categories. In order to evaluate such policy for a set of elements, the invention provides a method including the steps of (I) selecting a primary category; (II) partitioning the elements in the primary category into equivalence classes with respect to their influence on the policy; and (III) using the equivalence classes to replace at least one policy evaluation by a deduction. The result of the evaluation may be represented as an access matrix in backward-compatible format. The efficiency of the policy evaluation may be further improved by applying partial policy evaluation at intermediate stages, by forming combined equivalence classes containing n-tuples of elements and/or by analyzing the influence of each element by extracting functional expressions of maximal length from the policy.
申请公布号 US2013081105(A1) 申请公布日期 2013.03.28
申请号 US201213621338 申请日期 2012.09.17
申请人 GIAMBIAGI PABLO;AXIOMATICS AB 发明人 GIAMBIAGI PABLO
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址