发明名称 Extensible security system and method for controlling access to objects in a computing environment
摘要 A method and computing system for extending access control of system objects in a computing environment beyond traditional rights such as read, write, create and delete. According to the invention, a system administrator or user application is able to create control rights that are unique to the type of object. Rights can be created that do not relate to any specific property of the object, but rather define how a user may control the object. A novel object, referred to as a control access data structure, is defined for each unique control right and associates the control right with one or more objects of the computing environment. In order to grant the right to a trusted user, an improved access control entry (ACE) is defined which holds a unique identifier of the trusted user and a unique identifier of the control access data structure.
申请公布号 US6412070(B1) 申请公布日期 2002.06.25
申请号 US19980157882 申请日期 1998.09.21
申请人 MICROSOFT CORPORATION 发明人 VAN DYKE CLIFFORD P.;BRUNDRETT PETER T.;SWIFT MICHAEL M.;GARG PRAERIT;WARD RICHARD B.
分类号 G06F9/46;G06F21/00;(IPC1-7):G06F12/14 主分类号 G06F9/46
代理机构 代理人
主权项
地址