发明名称 SICHERHEITSMODELL MIT BESCHRÄNKTEN TOKEN
摘要 <p>A restrict ed access token is created from an existing token, and provides less access than that token. A restricted token may be created by changing an attribute of one or more security identifiers allowing access in the parent token to a setting that denies access in the restricted token and/or removing one or more privileges from the restricted token relative to the parent token. A restricted access token also may be created by adding restricted security identifiers thereto. Once created, a process associates another process with the restricted token to launch the other process in a restricted context that is a subset of its own rights and privileges. A kernel-mode security mechanism determines whether the restricted process has access to a resource by first comparing user-based security identifiers in the restricted token and the intended type of action against a list of identifiers and actions associated with the resource. If no restricted security identifiers are in the restricted token, access is determined by this first check, otherwise a second access check further compares the restricted security identifiers against the list of identifiers and actions associated with the resource. With a token having restricted security identifiers, the process is granted access if both the first and second access checks pass. In this manner, a process is capable of restricting another process, such as possibly unruly code, in the actions it can perform.</p>
申请公布号 AT518179(T) 申请公布日期 2011.08.15
申请号 AT19990927413T 申请日期 1999.06.09
申请人 MICROSOFT CORPORATION 发明人 JENSENWORTH, GREGORY;GARG, PRAERIT;SWIFT, MICHAEL;GOERTZEL, MARIO;CHAN, SHANNON
分类号 G06F1/00;G06F9/46;G06F12/14;G06F21/00;G06F21/24;H04L29/06 主分类号 G06F1/00
代理机构 代理人
主权项
地址