U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

Access control subsystem and method for distributed computer system using compound principals

Patent 5173939 Issued on December 22, 1992. Estimated Expiration Date: Icon_subject October 28, 2011. Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.

Patent References

3245045

Electronic security system
Patent #: 4100534
Issued on: 07/11/1978
Inventor: Shifflet, Jr.

Self-contained programmable terminal for security systems
Patent #: 4218690
Issued on: 08/19/1980
Inventor: Ulch ,   et al.

Security system with multiple levels of access
Patent #: 4532507
Issued on: 07/30/1985
Inventor: Edson ,   et al.

Information recording system with multiple levels of data access
Patent #: 4651279
Issued on: 03/17/1987
Inventor: Suzuki

Apparatus and methods for granting access to computers Patent #: 4799258
Issued on: 01/17/1989
Inventor: Davies

Inventors

Assignee

Application

No. 783361 filed on 10/28/1991

US Classes:

707/9, Privileged access340/5.74, Access to electrical information713/167Object protection

Examiners

Primary: Gregory, Bernarr E.

Attorney, Agent or Firm

International Class

H04L 009/32

Abstract

A distributed computer system has a number of computers coupled thereto at distinct nodes and a naming service with a membership table that defines a list of assumptions concerning which principals in the system are stronger than other principals, and which roles adopted by principals are stronger than other roles. Each object in the system has an access control list (ACL) having a list of entries. Each entry is either a simple principal or a compound principal. The set of allowed compound principals is limited to a predefined set of allowed combinations of simple principals, roles, delegations and conjunctions in accordance with a defined hierarchical ordering of the conjunction, delegation and role portions of each compound principal. The assumptions in the membership table reduce the number of entries needed in an ACL by allowing an entry to state only the weakest principals and roles that are to be allowed access. The reference checking process, handled by a reference monitor found at each node of the distributed system, grants an access request if the requestor is stronger than any one of the entries in the access control list for the resource requested. Furthermore, one entry is stronger than another entry if for each of the conjuncts in the latter entry there is a stronger conjunct in the former. Additional rules used by the reference monitor during the reference checking process govern the processes of comparing conjuncts in a requestor principal with the conjuncts in an access control list entry and of using assumptions to compare the relative strengths of principals and roles.

PatentsPlus Images
Enhanced PDF formats
loading...
PatentsPlus: add to cart
PatentsPlus: add to cartSearch-enhanced full patent PDF image
$9.95more info
PatentsPlus: add to cart
PatentsPlus: add to cartIntelligent turbocharged patent PDFs with marked up images
$16.95more info
 
Sign InRegister
Username  
Password   
forgot password?