发明名称 Trusted delegation system
摘要 A trust manager examines each new class before it is allowed to execute by examining a policy file which includes data structures defining security policies of the user system, a certificate repository for storing a plurality of certificates, a certificate being a data record which is digitally signed and which certifies claims relevant to a security evaluation, a code examiner adapted to analyze the portion of code to determine potential resource use of the portion of code and a trust evaluator adapted to evaluate certificate requirements of the portion of code based on policy rules extracted from the policy file and the potential resource use specified by the code examiner. The trust evaluator also determines, from certificates from the certificate repository and a code identifier identifying the portion of code, whether execution of the portion of code is allowed by the policy rules given the potential resource use, the code supplier and applicable certificates. Certificates and policies can be specified in hierarchical form, so that some levels of security can be delegated to trusted entities.
申请公布号 US5958050(A) 申请公布日期 1999.09.28
申请号 US19960777328 申请日期 1996.12.26
申请人 ELECTRIC COMMUNITIES 发明人 GRIFFIN, CLAIRE;BARNES, DOUGLAS
分类号 G06F1/00;G06F21/00;(IPC1-7):G06F12/14;G06F13/00 主分类号 G06F1/00
代理机构 代理人
主权项
地址