发明名称 Distributed capability-based authorization architecture using roles
摘要 An authorization architecture for authorizing access to resource objects in an object-oriented programming environment. In one distributed environment, the permission model of JAAS (Java Authentication and Authorization Service) is replaced or enhanced with role-based access control. Thus, users and other subjects (e.g., pieces of code) are assigned membership in one or more roles, and appropriate permissions or privileges to access resource objects are granted to those roles. Permissions may also be granted directly to users. Roles may be designed to group users having similar functions, duties or similar requirements for accessing the resources. Roles may be arranged hierarchically, so that users explicitly assigned to one role may indirectly be assigned to one or more other roles (i.e., descendants of the first role). A realm or domain may be defined as a namespace, in which one or more role hierarchies are established.
申请公布号 US7461395(B2) 申请公布日期 2008.12.02
申请号 US20030430505 申请日期 2003.05.06
申请人 ORACLE INTERNATIONAL CORPORATION 发明人 NG RAYMOND K.
分类号 G06F21/22;G06F9/44;G06F21/00;H04L9/00 主分类号 G06F21/22
代理机构 代理人
主权项
地址