发明名称 Access control via properties system
摘要 An access control via properties system provides ACL rules based on the properties associated with the entries, thereby taking advantage of the fact that there are inherent properties associated with each entry and does not require any changes to the schema. Once the server supports the invention, the system administrator creates a few simple ACL rules and is done. The invention structures the ACL rule such that it indicates the attributes that the administrator has selected for user access and specifies the type of access to be granted to a user which can include: read, write, or any other privileges that the system supports. The desired attributes that the user must have to be granted such access is also listed along with the attribute fieldname associated with the desired attributes. The directory server will match the desired attributes within the specified attribute fieldname with the user's attributes and allows access to the directory entry only if the user has the desired attribute values. Alternatively, a match function can be specified for the desired attributes where the directory server matches the desired attributes with the user and the owner of the list of attributes and allows access to the directory entry only if the both the user and the owner have the desired attribute values. When a user accesses a directory entry, the directory server selects and analyzes a specific access control command according to the attribute being accessed.
申请公布号 US6535879(B1) 申请公布日期 2003.03.18
申请号 US20000507536 申请日期 2000.02.18
申请人 NETSCAPE COMMUNICATIONS CORPORATION 发明人 BEHERA PRASANTA
分类号 G06F21/00;H04L29/06;(IPC1-7):G06F17/30 主分类号 G06F21/00
代理机构 代理人
主权项
地址