发明名称 System and method for using security levels to simplify security policy management
摘要 A system and method is provided for reducing the complexity and improving the performance of enforcing security restrictions on the execution of program code in a runtime environment. In a preferred embodiment, units of executable code, such as methods or functions, are classified by "security level." Code units belonging to a "trusted" security level may call any other code unit in the runtime environment, but other security levels are restricted in the code units they can call. In a preferred embodiment, the security levels are represented by corresponding permission objects. Each permission object that is associated with a particular security level includes a numerical value that denotes that security level. Security policies can be enforced with respect to caller and callee code units by comparing numerical values of corresponding permission objects. This security level scheme also improves runtime performance by making it unnecessary to check individually-defined permissions in many cases.
申请公布号 US2005278790(A1) 申请公布日期 2005.12.15
申请号 US20040865345 申请日期 2004.06.10
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BIRK PETER D.;CHAO CHING-YUN
分类号 G06F11/30;G06F12/14;G06F21/00;H04L9/00;H04L9/32;(IPC1-7):H04L9/00 主分类号 G06F11/30
代理机构 代理人
主权项
地址