发明名称 Method and system for automatic generation of cache directives for security policy
摘要 An authorization method is implemented in an authorization engine external to an authorization server. The authorization server includes a cache. The external authorization engine comprises an authorization decision engine, and a policy analytics engine. The method begins when the authorization decision engine receives a request for an authorization decision. The request is generated (at the authorization server) following receipt of a client request for which an authorization decision is not then available at the server. The authorization decision engine determines an authorization policy to apply to the client request, applies the policy, and generates an authorization decision. The authorization decision is then provided to the policy analytics engine, which stores previously-generated potential cache directives that may be applied to the authorization decision. Preferably, the cache directives are generated in an off-line manner (e.g., during initialization) by examining each security policy and extracting one or more cache dimensions associated with each such policy. The policy analytics engine determines an applicable cache directive, and the decision is augmented to include that cache directive. The decision (including the cache directive) is then returned to the authorization server, where the decision is applied to process the client request. The cache directive is then cached for re-use at the authorization server.
申请公布号 US2012311674(A1) 申请公布日期 2012.12.06
申请号 US201113152943 申请日期 2011.06.03
申请人 HOCKINGS CHRISTOPHER JOHN;CANNING SIMON GILBERT;EXTON SCOTT ANTHONY;READSHAW NEIL IAN;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 HOCKINGS CHRISTOPHER JOHN;CANNING SIMON GILBERT;EXTON SCOTT ANTHONY;READSHAW NEIL IAN
分类号 G06F21/00;G06F17/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址