发明名称 A SYSTEM AND METHOD FOR EVALUATING A REVERSE QUERY
摘要 <p>Disclosed are real-time techniques for determining all access requests to an attribute-based access control policy which evaluate to a given decision, permit or deny. The policy is enforced to control access to one or more resources in a computer network. In one embodiment, a method comprises: (i) receiving a reverse query and a set of admissible access requests, each of which comprises one or more attributes in the policy and values of these; (ii) extracting attributes to which all access requests in the set assign identical values; (iii) reducing the ABAC policy by substituting values for the extracted attributes; (iv) caching the policy as a simplified policy; (v) translating the simplified policy and the given decision into a satisfiable logic proposition; (vi) deriving all solutions satisfying the proposition; and (vi) extracting, based on the solutions, all access requests from the set for which the policy yields the given decision.</p>
申请公布号 EP2548141(A1) 申请公布日期 2013.01.23
申请号 EP20110853144 申请日期 2011.07.19
申请人 AXIOMATICS AB 发明人 RISSANEN, JAN ERIK;GIAMBIAGI, PABLO EDUARDO
分类号 G06F21/60;G06F17/30 主分类号 G06F21/60
代理机构 代理人
主权项
地址