发明名称 Risk Adaptive Information Flow Based Access Control
摘要 Systems and methods are provided to manage risk associated with access to information within a given organization. The overall risk tolerance for the organization is determined and allocated among a plurality of subjects within the organization. Allocation is accomplished using either a centralized, request/response or free market mechanism. As requested from subjects within the organization for access to objects, i.e. information and data, are received, the amount of risk or risk level associated with each requested is quantified. Risk quantification can be accomplished using, for example, fuzzy multi-level security. The quantified risk associated with the access request in combination with the identity of the object and the identity of the subject are used to determine whether or not the request should be granted, denied or granted with appropriated mitigation measures.
申请公布号 US2011173084(A1) 申请公布日期 2011.07.14
申请号 US20070623838 申请日期 2007.01.17
申请人 发明人 CHENG PAU-CHEN;ROHATGI PANKAJ;KESER CLAUDIA;RAO JOSYULA R.
分类号 G06Q30/00;G06F21/00 主分类号 G06Q30/00
代理机构 代理人
主权项
地址