发明名称 SYSTEM AND METHOD FOR REPRESENTING MULTIPLE SECURITY GROUPS AS A SINGLE DATA OBJECT
摘要 A system and method for representing multiple security groups as a single data object are provided. With the system and method, a complex group object is created that consists of a group set value and a mask value. The complex group object represents a plurality of groups by the group set value. The mask value is used to apply to group identifiers received during an authentication process to generate a value that is compared against the group set value to determine if the group identifiers are part of the complex group. For example, in a first step of authorization processing, the group identifier received in an authorization request is bit-wise AND'd with the mask value for the complex group data object. In a second step, the masked group identifier from the received request is compared to the group set value of the complex group object. Such comparison may take the form of masking the group set value and comparing the masked group set value to the masked group identifier from the received request, for example. If the two values match, then access is granted. If the two values do not match, then access is denied.
申请公布号 KR20060023962(A) 申请公布日期 2006.03.15
申请号 KR20057021116 申请日期 2005.11.07
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 HAUGH JULIANNE FRANCES
分类号 G06F15/00;G06F1/00;G06F21/00;H04L9/00 主分类号 G06F15/00
代理机构 代理人
主权项
地址