发明名称 Method and apparatus for providing process-based access controls on computer resources
摘要 A method, apparatus, and computer instructions for process-based access controls on computer resources to processes. An access mechanism is provided in which a specific invoker obtains an object access identity (ACI). Another mechanism is provided in which a specific object, such as a file system resource, requires a specific object access identity to obtain one of the forms of access denoted by an access control list. A process may "grant" an identifier that is later "required" for a system resource access. Objects may specify their own access requirements and permitted access modes. The granted identifier, ACI, is stored in the process's credentials once these credentials match a specific "grant" entry in the access control list. This identifier has no meaning outside of being used to make an access decision for a specific resource. When a process tries to access the object, the object's access control list is scanned for "required" entries. If a match occurs between the "required" entry's identifier and the ACI stored, access to the object is granted with access rights specified in the "require" entries.
申请公布号 US2005071641(A1) 申请公布日期 2005.03.31
申请号 US20030672261 申请日期 2003.09.25
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BASIBES MOUNIR EMIL;HAUGH JULIANNE FRANCES
分类号 G06F21/00;H04K1/00;(IPC1-7):H04K1/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址