发明名称 RESTRICTING ACCESS TO OBJECTS CREATED BY PRIVILEGED COMMANDS
摘要 A method and system for restricting access to objects created by privileged commands. In an RBAC environment, execution of certain privileged commands creates objects, which typically, have traditional access permissions based on the user ID and not the role. To enhance security of these objects, a new security attribute is introduced. The security attribute can be associated to the privileged command. Therefore, whenever a privileged command creates an object, the security attribute associated with the privileged command is applied on the object. The security attribute can mask the traditional access permissions of the object, and modify the access permissions, which can be stored along with the object. An AND operation can be performed on the traditional access permissions and the security attribute, to determine the modified permissions of the object. Further, an authorized user can modify, add, delete, or customize the security attribute at any time.
申请公布号 US2010242083(A1) 申请公布日期 2010.09.23
申请号 US20090409141 申请日期 2009.03.23
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BEGUM HUSSAINA N.;KOIKARA GEORGE M.;PATTANSHETTI MANJUNATH A.
分类号 H04L9/32 主分类号 H04L9/32
代理机构 代理人
主权项
地址