发明名称 SECURITY FOR COMPUTER SYSTEM RESOURCES
摘要 Provided is a scheme for implementing flexible control of subject authorizations (i.e. the authorizations which users or processes have) to perform operations in relation to computer resources. The methods, computer systems and authorization facilities which are provided by the invention enhance the security provisions of operating systems which have only very limited authorization facilities, by mapping the available operating system permissions to specified resource authorities for each of a set of aspects or characteristics of a computer system resource. Thus, the standard operating system permissions (e.g. read, write, execute) can have different meanings for different resource aspects, and an individual subject can have separate authorization levels set for the different resource aspects. The mappings between authorities and the available permissions may be different for different types of resources. The invention provides great flexibility in setting the authorizations that a subject may have in relation to particular resources.
申请公布号 WO9642057(A1) 申请公布日期 1996.12.27
申请号 WO1995GB02269 申请日期 1995.09.25
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION;LEWIS, JONATHAN, RHYS 发明人 LEWIS, JONATHAN, RHYS
分类号 G06F1/00;G06F9/46;G06F12/14;G06F21/62;(IPC1-7):G06F12/14 主分类号 G06F1/00
代理机构 代理人
主权项
地址