发明名称 Method and system for determining and enforcing security policy in a communication session
摘要 A method and system for determining and enforcing security policy in a communication session are provided in distributed systems. Policy encompasses the provisioning, authorization, and access control within the protected environment. Hence, all communication security requirements are explicitly stated through policy. A policy instantiation is constructed at run-time through policy determination. Conditional, abstract, and discretionary policies stated by communication participants are reconciled to arrive at an instantiation. The resulting instantiation is a concrete specification of the mechanisms, configurations, and access control model to be implemented by the session. The semantics of an instantiation are achieved through policy enforcement. The policy enforcement architecture implements session policies through the composition and configuration of security mechanisms using a novel event-bus architecture. Policy is enforced through the observation of and reaction to relevant events. The method and system of the invention diverges from past subscription-based event architectures by introducing additional infrastructure allowing significant implementation flexibility, robustness, and efficiency.
申请公布号 US2003126464(A1) 申请公布日期 2003.07.03
申请号 US20010006552 申请日期 2001.12.04
申请人 MCDANIEL PATRICK D.;PRAKASH ATUL 发明人 MCDANIEL PATRICK D.;PRAKASH ATUL
分类号 G06F21/00;(IPC1-7):G06F11/30 主分类号 G06F21/00
代理机构 代理人
主权项
地址