发明名称 SIMPLIFIED LDAP ACCESS CONTROL LANGUAGE SYSTEM
摘要 A simplified LDAP access language system provides user-defined attributes that tell the directory system who the user wants to give read or write access to a specific set of his attributes. The read and write attributes are separate lists and may, in fact, differ, thereby giving the user the flexibility to better manage access to his attributes. The value of the read and write attributes are in an LDAP Filter format which is an Internet standard (RFC 2254) which allows the user to specify not only users local to his intranet, but users across the Internet as well. Access control lists (ACL) are created by the System Administrators and list the specific attributes that the user is allowed to control read or write access, giving the Administrators full control of what information the user can give out. The ACLs are stored in the directory along with the entries. When a user accesses an entry in a directory, the server checks the ACL specified for the attributes being accessed. The read or write attribute for the owner of the attributes being accessed are used by the server when it checks the ACL. The combination of the read or write attribute and the ACL determine whether the user has permission to perform the read or write access to the attribute being accessed.
申请公布号 WO0138971(A3) 申请公布日期 2002.03.07
申请号 WO2000US29057 申请日期 2000.10.19
申请人 NETSCAPE COMMUNICATIONS CORPORATION 发明人 BEHERA, PRASANTA
分类号 G06F12/14;G06F9/46;G06F12/00;G06F21/24;(IPC1-7):G06F1/00 主分类号 G06F12/14
代理机构 代理人
主权项
地址