发明名称 Method and system for controlling user access to a resource in a networked computing environment
摘要 A unified and straightforward approach to managing file and other resource security in a networked computing environment is disclosed. The invention can be implemented in a multi-user computer network that includes a client computer, a server computer that controls a resource sharable among users of the network, such as a shared file folder or directory, and a communications pathway between the client computer and the server computer. The resource is organized as a hierarchy of elements with a root element at the top of the hierarchy and additional elements below the root element. According to the invention, a request is received to change a protection, such as an access permission, of an element of the resource hierarchy (other than the root) with respect to a particular network user. If the element in question lacks an associated access control list, a nearest ancestor element of the hierarchy is located that has an associated access control list. The first (descendant) element inherits the access control list of the second (ancestor) element. This inheritance is done by generating a copy of the access control list of the second element and associating the generated copy with the first element. The requested change in protection is then incorporated into the generated copy that has been associated with the first element so as to establish an updated access control list for the first element. Further, the requested change can be propagated downwards in the hierarchy from the first element to its descendants having access control lists.
申请公布号 US5956715(A) 申请公布日期 1999.09.21
申请号 US19960710975 申请日期 1996.09.23
申请人 MICROSOFT CORPORATION 发明人 GLASSER, DANIEL S.;MCCURDY, ANN ELIZABETH;PRICE, ROBERT M.
分类号 G06F17/30;G06F21/00;H04L29/06;(IPC1-7):G06F17/30 主分类号 G06F17/30
代理机构 代理人
主权项
地址