$\require{mediawiki-texvc}$

연합인증

연합인증 가입 기관의 연구자들은 소속기관의 인증정보(ID와 암호)를 이용해 다른 대학, 연구기관, 서비스 공급자의 다양한 온라인 자원과 연구 데이터를 이용할 수 있습니다.

이는 여행자가 자국에서 발행 받은 여권으로 세계 각국을 자유롭게 여행할 수 있는 것과 같습니다.

연합인증으로 이용이 가능한 서비스는 NTIS, DataON, Edison, Kafe, Webinar 등이 있습니다.

한번의 인증절차만으로 연합인증 가입 서비스에 추가 로그인 없이 이용이 가능합니다.

다만, 연합인증을 위해서는 최초 1회만 인증 절차가 필요합니다. (회원이 아닐 경우 회원 가입이 필요합니다.)

연합인증 절차는 다음과 같습니다.

최초이용시에는
ScienceON에 로그인 → 연합인증 서비스 접속 → 로그인 (본인 확인 또는 회원가입) → 서비스 이용

그 이후에는
ScienceON 로그인 → 연합인증 서비스 접속 → 서비스 이용

연합인증을 활용하시면 KISTI가 제공하는 다양한 서비스를 편리하게 이용하실 수 있습니다.

Flexible and dynamic derivation of permissions 원문보기

IPC분류정보
국가/구분 United States(US) Patent 등록
국제특허분류(IPC7판)
  • G06F-012/14
출원번호 US-0979807 (1997-11-25)
발명자 / 주소
  • Anand Rangachari
  • Giraud Frederique-Anne
  • Islam Nayeem
  • Jaeger Trent Ray
  • Liedtke Jochen
출원인 / 주소
  • International Business Machines Corp.
대리인 / 주소
    Scully, Scott, Murphy & PresserJordan, Esq.
인용정보 피인용 횟수 : 113  인용 특허 : 8

초록

A dynamic derivation mechanism is defined which enables limited permissions to be dynamically and flexibly derived for executables based upon their authenticated description. The dynamic derivation mechanism uses the authenticated description to determine the maximal permissions that individual prin

대표청구항

[ Having thus described our invention, what we claim as new, and desire to secure by Letters Patent is:] [1.] A method for deriving current and maximal permissions for executable content using:a. one or more executable content descriptions;b. one or more sets of permissions (access rights) that desc

이 특허에 인용된 특허 (8)

  1. Fabbio Robert A. (Austin TX), Access control policies for an object oriented database, including access control lists which span across object boundar.
  2. Miller Donald V. (Los Altos CA), Access restriction facility method and apparatus.
  3. Sweeney Christopher Lee ; Stodghill Scott A. ; DeShazer Kurt A. ; Marimuthu Aravindan, Application and database security and integrity system and method.
  4. Sutter Herbert P.,CAX, Independent distributed database system.
  5. Batten-Carew Mark,CAX ; Buchler Marek,CAX ; Hiller Stephen William,CAX ; Otway Josanne Mary,CAX, Method and apparatus for processing administration of a secured community.
  6. Deinhart Klaus,DEX ; Gligor Virgil ; Lingenfelder Christoph,DEX ; Lorenz Sven,DEX, Method and system for advanced role-based access control in distributed and centralized computer systems.
  7. Theimer Marvin M. (Mountain View CA) Nichols David A. (Mountain View CA) Terry Douglas B. (San Carlos CA), Method for delegating access rights through executable access control program without delegating access rights not in a.
  8. Hsieh Vincent, Method for security shield implementation in computer system's software.

이 특허를 인용한 특허 (113)

  1. Stancheva, Svetlana; Blagoev, Jako; Zheleva, Ekaterina; Kacarov, Ilia; Zlatarev, Stephan; Jaeschke, Hiltrud, Abstract configuration files for efficient implementation of security services.
  2. Kanai, Yoichi, Access control apparatus, access control method, access control program, recording medium, access control data, and relation description data.
  3. Oliphant, Brett M.; Blignaut, John P., Anti-vulnerability system, method, and computer program product.
  4. Oliphant, Brett M.; Blignaut, John P., Anti-vulnerability system, method, and computer program product.
  5. Oliphant, Brett M.; Blignaut, John P., Anti-vulnerability system, method, and computer program product.
  6. Oliphant, Brett M.; Blignaut, John P., Anti-vulnerability system, method, and computer program product.
  7. Oliphant, Brett M.; Blignaut, John P., Anti-vulnerability system, method, and computer program product.
  8. Oliphant, Brett M.; Blignaut, John P., Anti-vulnerability system, method, and computer program product.
  9. Suzuki, Yosuke; Takahashi, Masahiro, Apparatus and method for reproducing character information recorded on a recording medium.
  10. Angelo, Robert F.; Azmi, Amir; Bajpai, Chandra; Britton, Colin P.; Kaufman, Noah W.; Kumar, Ashok; Raybourn, Darren, Appliance for enterprise information integration and enterprise resource interoperability platform and methods.
  11. LaMacchia,Brian A.; Fee,Gregory Darrell; Kohnfelder,Loren M.; Kamath,Ashok Cholpady, Applying a permission grant set to a call stack during runtime.
  12. Gavrilov, Dmitri; He, Xin; Balarajan, Sanjeev; Muggli, Nathan, Client-specific transformation of distributed data.
  13. Avgerinos, Athanasios; Jakubowski, Mariusz H.; Peinado, Marcus, Code base partitioning system.
  14. Oliphant, Brett M.; Blignaut, John P., Computer program product and apparatus for multi-path remediation.
  15. Oliphant, Brett M.; Blignaut, John P., Computer program product and apparatus for multi-path remediation.
  16. Oliphant, Brett M.; Blignaut, John P., Computer program product and apparatus for multi-path remediation.
  17. Colby, Logan M.; Frey, Jeffrey A.; High, Robert H.; Vignola, Christopher P., Context-based dynamic policy assignment in a distributed processing environment.
  18. Adams,Robert; Puthenkulam,Jose P., Control of access control lists based on social networks.
  19. Pon, Michael, Controlling use of a network resource.
  20. Kimmel, Gerald D.; Adamouski, Francis J.; Domangue, Ersin L.; Kimmel, Wayne R.; Lightburn, James G.; Viola, Leonard R., Cryptographic key management.
  21. Brunn, Jonathan F.; Forrester, Jessica W.; Hess, Stephen C.; Hoy, Jeffrey R., Delivering author specific content.
  22. Brunn, Jonathan F.; Forrester, Jessica W.; Hess, Stephen C.; Hoy, Jeffrey R., Delivering author specific content.
  23. Brunn, Jonathan F.; Forrester, Jessica W.; Hess, Stephen C.; Hoy, Jeffrey R., Delivering author specific content.
  24. Corless, Peter P., Digital identifiers and digital identifier control systems for intellectual properties.
  25. James, Arthur; Brent, Michelle; Corless, Peter P.; Khera, Sanjay; Park, Soyoung, Digital rights framework.
  26. Oberst, Shawn, Distributed expression-based access control.
  27. Peterka, Petr, Dynamic security for digital television receivers.
  28. Bader, Lauren L.; Myers, Julia V.; Schenck, James F.; Scheiern, Kevin L.; Wimer, II, William C., Dynamical dual permissions-based data capturing and logging.
  29. LaMacchia,Brian A.; Kohnfelder,Loren M.; Fee,Gregory Darrell, Evaluating initially untrusted evidence in an evidence-based security policy manager.
  30. Fee, Gregory D.; Goldfeder, Aaron; Hawkins, John M.; Cool, Jamie L.; Lange, Sebastian; Khorun, Sergey, Evidence-based application security.
  31. LaMacchia,Brian A; Kohnfelder,Loren M.; Fee,Gregory Darrell; Toutonghi,Michael J., Evidence-based security policy manager.
  32. LaMacchia, Brian A.; Kohnfelder, Loren M.; Fee, Gregory Darrell; Toutonghi, Michael J., Filtering a permission set using permission requests associated with a code assembly.
  33. LaMacchia,Brian A.; Kohnfelder,Loren M.; Fee,Gregory D.; Toutonghi,Michael J., Filtering a permission set using permission requests associated with a code assembly.
  34. LaMacchia,Brian A.; Kohnfelder,Loren M.; Fee,Gregory D.; Toutonghi,Michael J., Filtering a permission set using permission requests associated with a code assembly.
  35. Chang, David Yu; Venkataramappa, Vishwanath; Williamson, Leigh Allen, Fine-grained authorization by authorization table associated with a resource.
  36. Barkley John ; Cincotta Anthony V., Implementation of role/group permission association using object access type.
  37. Felsher, David Paul, Information record infrastructure, system and method.
  38. Kimmel, Gerald D.; Domangue, Ersin L.; Adamouski, Francis J., Information-centric security.
  39. Chang, David Yu; Chao, Ching-Yun, Integrated security roles.
  40. Chan, Keen W.; Chu, Nai-Chi M., Integrity scanner.
  41. Dayn?s, Laurent P., Lock delegation with space-efficient lock management.
  42. Shyam Sundar Sarkar, METHOD AND APPARATUS FOR PROCESSING MARKUP LANGUAGE SPECIFICATIONS FOR DATA AND METADATA USED INSIDE MULTIPLE RELATED INTERNET DOCUMENTS TO NAVIGATE, QUERY AND MANIPULATE INFORMATION FROM A PLURALITY.
  43. Sturtevant,Reed Padi Maw; Eberstadt,George A.; Kresch,Jeffrey A., Managing relationships of parties interacting on a network.
  44. Guo,Jinhong Katherine; Johnson,Stephen L.; Park,Il Pyung, Mandatory access control (MAC) method.
  45. Guo, Jinhong Katherine; Johnson, Stephen L.; Park, Il Pyung, Mandatory access control scheme with active objects.
  46. Ramic, Haris; Tirpak, Thomas M., Method and apparatus for dynamic management of distributed context.
  47. Raley, Michael C.; Chen, Daniel C.; Wu, Hsi-Cheng; Ta, Thanh, Method and apparatus for identifying installed software and regulating access to content.
  48. Lau, Alex; Bandekar, Namrata Jayant; Yuen, Chun Fung; Lam, Wing Young, Method and system for managing and presenting multiple application containers as a single logical container.
  49. Srivastava, Alok; Ahad, Rafiul, Method for application-to-application authentication via delegation.
  50. Chang,David Yu; Chao,Ching Yun, Method for integrated security roles.
  51. Harvey, Andrew G.; Ng, John, Method of controlling network access that induces consumption of merchant goods or services.
  52. Colby,Logan M.; Frey,Jeffrey A.; High,Robert H.; Vignola,Christopher P., Method, system, and storage medium for providing context-based dynamic policy assignment in a distributed processing environment.
  53. Colby,Logan M.; Frey,Jeffrey A.; High,Robert H.; Vignola,Christopher P., Method, system, and storage medium for providing context-based dynamic policy assignment in a distributed processing environment.
  54. Britton, Colin P.; Azmi, Amir; Kumar, Ashok; Kaufman, Noah W.; Bajpai, Chandra; Angelo, Robert F., Methods and apparatus for enterprise application integration.
  55. Britton, Colin P.; Azmi, Amir; Kumar, Ashok; Kaufman, Noah W.; Bajpai, Chandra; Angelo, Robert F., Methods and apparatus for enterprise application integration.
  56. Greenblatt, Howard; Greenblatt, Alan; Bigwood, David A.; Britton, Colin P., Methods and apparatus for identifying related nodes in a directed graph having named arcs.
  57. Trefler, Alan; Hofmann, Andreas G., Methods and apparatus for integration of declarative rule-based processing with procedural programming in a digital data-processing environment.
  58. Trefler, Alan; Hofmann, Andreas G., Methods and apparatus for integration of declarative rule-based processing with procedural programming in a digital data-processing evironment.
  59. Bender, Christopher Lyle, Methods and apparatus for maintaining permissions for client/server processing in a communication device.
  60. Bender, Christopher Lyle, Methods and apparatus for maintaining permissions for client/server processing in a communication device.
  61. Britton, Colin P.; Kumar, Ashok; Bigwood, David; DeFusco, Anthony J.; Greenblatt, Howard, Methods and apparatus for querying a relational data store using schema-less queries.
  62. Britton, Colin P.; Azmi, Amir; Kumar, Ashok; Kaufman, Noah W.; Bajpai, Chandra; Angelo, Robert F.; Bigwood, David A., Methods and apparatus for real-time business visibility using persistent schema-less data storage.
  63. Corley, Carole Rhoads; Lobo, Jorge; Vassberg, Lorraine Phyllis; Wang, Xiping, Methods and apparatus for scoped role-based access control.
  64. Trefler, Alan; Sachs, Baruch, Methods and apparatus for user interface optimization.
  65. Trefler, Alan; Hofmann, Andreas G., Methods and apparatus for work management and routing.
  66. Arrouye, Yan; Giampaolo, Dominic; Carol, Andrew; Zellers, Steve, Methods and systems for managing data.
  67. Giampaolo, Dominic; Arrouye, Yan, Methods and systems for managing data.
  68. H{hacek over (o)}rnkvist, John; Arrouve, Yan, Methods and systems for managing permissions data and/or indexes.
  69. Oliphant, Brett M.; Blignaut, John P., Multi-path remediation.
  70. Agbabian, Paul, Multi-policy security auditing system and method.
  71. Hoffberg, Steven M., Multifactorial optimization system and method.
  72. Oliphant, Brett M., Multiple-path remediation.
  73. Fee, Gregory D.; Pratt, Brian; Lange, Sebastian; Kohnfelder, Loren, Partial grant set evaluation from partial evidence in an evidence-based security policy manager.
  74. Puthenkulam, Jose P.; Bowman, Mic, Peer discovery and connection management based on context sensitive social networks.
  75. Puthenkulam, Jose P.; Bowman, Mic, Peer discovery and connection management based on context sensitive social networks.
  76. Puthenkulam,Jose P.; Bowman,Mie, Peer discovery and connection management based on context sensitive social networks.
  77. Arai,Masato; Kai,Satoshi, Policy setting support tool.
  78. Hutchinson, Blake R.; Ou, Jesse Shi-Yuan; Leung, Ambrose Y. W.; Chalk, Brandon A.; Mooney, III, Robert J., Principal access determination in an enviroment.
  79. Khatutsky, Victor E., Proactive performance management for multi-user enterprise software systems.
  80. Khatutsky, Victor E., Proactive performance management for multi-user enterprise software systems.
  81. Oliphant, Brett M.; Blignaut, John P., Real-time vulnerability monitoring.
  82. Oliphant, Brett M.; Blignaut, John P., Real-time vulnerability monitoring.
  83. Raley, Michael C.; Gilliam, Charles P.; Ham, Manual; Lao, Guillermo; Tadayon, Bijan, Rights expression profile system and method using templates.
  84. Trefler, Alan; Sachs, Baruch A., Rule-based user interface conformance methods.
  85. Lange, Sebastian; Fee, Gregory D.; Goldfeder, Aaron; Medvedev, Ivan; Gashler, Michael, Security requirement determination.
  86. Britton, Colin P.; Greenblatt, Howard; Greenblatt, Alan, Surveillance, monitoring and real-time events platform.
  87. Stefik, Mark J.; Pirolli, Peter L. T., System and method for controlling utilization of content.
  88. Hoffberg, Steven M., System and method for determining contingent relevance.
  89. Adams, Carlisle, System and method for granting security privilege in a communication system.
  90. Hoffberg, Steven M., System and method for incentivizing participation in a market transaction.
  91. Swingler, Michael Alan; O'Brien, Thomas John, System and method for incorporating an originating site into a security protocol for a downloaded program object.
  92. Nguyen, Mai; Wang, Xin; Ta, Thanh; Lao, Guillermo; Chen, Eddie J., System and method for managing transfer of rights using shared state variables.
  93. Nguyen, Mai; Wang, Xin; Ta, Thanh; Lao, Guillermo; Chen, Eddie J., System and method for managing transfer of rights using shared state variables.
  94. Stefik, Mark J.; Pirolli, Peter L. T., System and method for permitting use of content using transfer rights.
  95. Le Saint, Eric F., System and method for privilege delegation and control.
  96. Hoffberg, Steven M., System and method for providing a payment to a non-winning auction participant.
  97. Haugh, Julianne Frances, System and method for representing multiple security groups as a single data object.
  98. Haugh,Julianne Frances, System and method for representing multiple security groups as a single data object.
  99. Felsher, David P.; Nagel, Robert H.; Hoffberg, Steven M., System and method for secure three-party communications.
  100. Felsher, David P.; Nagel, Robert H.; Hoffberg, Steven M., System and method for secure three-party communications.
  101. Nagel,Robert H.; Felsher,David P.; Hoffberg,Steven M., System and method for secure three-party communications.
  102. Chase, James Edward, System and method for updating or modifying an application without manual coding.
  103. Frenkel, Benjamin A., System and software for creation and modification of software.
  104. Stefik, Mark J.; Petrie, Glen W.; Okamoto, Steve A.; Briggs, Nicholas H., System for controlling the distribution and use of rendered digital works through watermarking.
  105. Centonze, Paolina; Haviv, Yinnon Avraham; Hay, Roee; Pistoia, Marco; Sharabani, Adi; Tripp, Omer, System, method and apparatus for simultaneous definition and enforcement of access-control and integrity policies.
  106. Centonze, Paolina; Haviv, Yinnon Avraham; Hay, Roee; Pistoia, Marco; Sharabani, Adi; Tripp, Omer, System, method and apparatus for simultaneous definition and enforcement of access-control and integrity policies.
  107. Centonze, Paolina; Haviv, Yinnon Avraham; Hay, Roee; Pistoia, Marco; Sharabani, Adi; Tripp, Omer, System, method and apparatus for simultaneous definition and enforcement of access-control and integrity policies.
  108. Oliphant, Brett M.; Blignaut, John P., System, method, and computer program product for reporting an occurrence in different manners.
  109. Valenzuela, Edgardo; Chen, Eddie J.; DeMartini, Thomas; Fung, Joseph Zhung Yee; Nguyen, Mai; Tieu, Vincent Hsiang; Tran, Duc, Systems and methods for creating, manipulating and processing rights and contract expressions using tokenized templates.
  110. Clinton, John W.; Trefler, Alan; Frenkel, Benjamin, Systems and methods for distributed rules processing.
  111. Frenkel, Benjamin A., Systems and methods for distributed rules processing.
  112. Blumenthal,Andreas; Ziegler,Klaus; Staader,Juergen; Schmitt,Andreas Simon, Testing flow control at test assertion level.
  113. Dayn?s, Laurent P., Validation technique for bulk lock delegation.
섹션별 컨텐츠 바로가기

AI-Helper ※ AI-Helper는 오픈소스 모델을 사용합니다.

AI-Helper 아이콘
AI-Helper
안녕하세요, AI-Helper입니다. 좌측 "선택된 텍스트"에서 텍스트를 선택하여 요약, 번역, 용어설명을 실행하세요.
※ AI-Helper는 부적절한 답변을 할 수 있습니다.

선택된 텍스트

맨위로