发明名称 Computer system security method and apparatus having program authorization information data structures
摘要 Method and apparatus are disclosed including a system monitor which limits the ability of a program about to be executed to the use of predefined resources (e.g., data files, disk writing capabilities, etc.). The system monitor processes a data structure including a set of authorities defining that which a program is permitted to do and/or that which the program is precluded from doing. The set of authorities and/or restrictions assigned to a program to be executed are referred to as "program authorization information" (or "PAI"). Once defined, the program authorization information is thereafter associated with at least one program to be executed to thereby delineate the resources and functions that the program is allowed to utilize and/or is not allowed to utilize. The PAI associated with a particular program may be assigned by a computer system owner/user or by someone who the computer system owner/user implicitly trusts. The PAI permits an associated program to access what has been authorized and nothing else. The program may be regarded as being placed in a program capability limiting "safety box". This "safety box" is thereafter associated with the program such that when the system monitor runs the program, the PAI for that program is likewise loaded and monitored. When the program is to perform a function or access a resource, the associated PAI is monitored to confirm that the operation is within the defined program limits. If the program is prevented from doing anything outside the authorized limits.
申请公布号 US5412717(A) 申请公布日期 1995.05.02
申请号 US19920883868 申请日期 1992.05.15
申请人 FISCHER, ADDISON M. 发明人 FISCHER, ADDISON M.
分类号 G06F1/00;G06F12/14;G06F21/00;(IPC1-7):H04L9/00 主分类号 G06F1/00
代理机构 代理人
主权项
地址