Patent ReferencesDistributed data processing system Data processing system Data processing system having a memory using object-based information and a protection scheme for determining access rights to such information Mechanical handling apparatus Method and system for providing system security in a remote terminal environment Funtionally structured distributed data processing system Distributed control of alias name usage in networks License mangagement system and license storage key Network license server Distributed security auditing subsystem for an operating system Patent #: 5032979 InventorApplicationNo. 480437 filed on 02/15/1990US Classes:707/9, Privileged access709/217, REMOTE DATA ACCESSING713/167Object protectionExaminersPrimary: Lee, Thomas C.Assistant: Lintz, Paul R. Attorney, Agent or FirmInternational ClassG06F 015/40AbstractA method is disclosed for providing user access control for a plurality of resource objects within a distributed data processing system having a plurality of resource managers. A reference monitor service is established and a plurality of access control profiles are stored therein. Thereafter, selected access control profiles are exchanged between the reference monitor service and a resource manager in response to an attempted access of a particular resource object controlled by that resource manager. The resource manager may then control access to the resource object by utilizing the exchanged access control profile. In a preferred embodiment of the present invention, each access control profile may include access control information relating to a selected user; a selected resource object; a selected group of users; a selected set of resource objects; or, a predetermined set of resource objects and a selected group of users. | |