会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 4. 发明申请
    • DISCOVERY AND MANAGEMENT OF CONTEXT-BASED ENTITLEMENTS ACROSS LOOSELY-COUPLED ENVIRONMENTS
    • 基于环境友好环境的基于语境的实践的发现与管理
    • US20110162034A1
    • 2011-06-30
    • US12649421
    • 2009-12-30
    • NATARAJ NAGARATNAMAnthony Joseph Nadalin
    • NATARAJ NAGARATNAMAnthony Joseph Nadalin
    • H04L9/32G06F21/22
    • G06F21/604
    • A method, apparatus and computer program product are provided to model and manage context-based entitlements that govern a user's access to information, applications and systems across a loosely-coupled distributed environment. One such distributed environment is a federated environment, which may span across companies, organizations, and geographical locations and regions. According to one embodiment, an entitlement modeling framework comprises a discovery module and an entitlement generator module. The discovery framework generates a data model for storing information concerning user identity, context, relationships between users, relationships between users and contexts and relationships between contexts. Preferably, the user identity, context, relationships between users, relationships between users and contexts, and relationships between contexts, are stored as attributes in the data model. An entitlement generator generates an entitlement according to the data model, wherein the entitlement (e.g., a user entitlement) is generated according to one or more contexts.
    • 提供了一种方法,装置和计算机程序产品来建模和管理基于上下文的权限,该权限管理用户对松散耦合的分布式环境中的信息,应用和系统的访问。 一个这样的分布式环境是联合环境,可能跨越公司,组织以及地理位置和地区。 根据一个实施例,授权建模框架包括发现模块和授权生成器模块。 发现框架生成用于存储关于用户身份,上下文,用户之间的关系,用户与上下文之间的关系以及上下文之间的关系的信息的数据模型。 优选地,用户身份,上下文,用户之间的关系,用户和上下文之间的关系以及上下文之间的关系被存储为数据模型中的属性。 授权生成器根据数据模型生成授权,其中根据一个或多个上下文生成授权(例如,用户授权)。
    • 5. 发明申请
    • CLASSIFICATION AND POLICY MANAGEMENT FOR SOFTWARE COMPONENTS
    • 软件组件的分类和政策管理
    • US20100076914A1
    • 2010-03-25
    • US12235900
    • 2008-09-23
    • Sridhar R. MuppidiNataraj NagaratnamAnthony Joseph Nadalin
    • Sridhar R. MuppidiNataraj NagaratnamAnthony Joseph Nadalin
    • G06F15/18G06N5/02
    • G06F21/604
    • A method, system, and computer usable program product for classification and policy management for software components are provided in the illustrative embodiments. A metadata associated with an application or component is identified. A mapping determination is made whether the metadata maps to a classification in a set of classifications. A policy that is applicable to the classification is identified and associated with the classification. If the mapping determination is deterministic, the component is assigned to the classification and the policy associated with the classification is associated with the component. If the mapping determination is not deterministic, a user intervention may be necessary, the component may be classified in a default classification, or both. Because of the policy being associated with the classification, associating the policy with the component may occur based on the metadata of the application or component and its resultant classification.
    • 在说明性实施例中提供了用于软件组件的分类和策略管理的方法,系统和计算机可用程序产品。 识别与应用或组件相关联的元数据。 做出映射确定是否元数据映射到一组分类中的分类。 识别适用于分类的策略并与分类相关联。 如果映射确定是确定性的,则将组件分配给分类,并且与分类相关联的策略与组件相关联。 如果映射确定不是确定性的,则可能需要用户干预,该组件可以被分类为默认分类,或者两者。 由于与分类相关联的策略,将策略与组件相关联可以基于应用或组件的元数据及其结果分类而发生。
    • 7. 发明申请
    • FEDERATING POLICIES FROM MULTIPLE POLICY PROVIDERS
    • 多个政策提供者的联邦政策
    • US20100043050A1
    • 2010-02-18
    • US12192769
    • 2008-08-15
    • Anthony J. NadalinNataraj NagaratnamSridhar R. Muppidi
    • Anthony J. NadalinNataraj NagaratnamSridhar R. Muppidi
    • G06F21/00G06F15/16
    • H04L63/102H04L63/20
    • One aspect of the present invention can include a system, a method, a computer program product and an apparatus for federating policies from multiple policy providers. The aspect can identify a set of distinct policy providers, each maintaining at least one policy related to a service or a resource. A federated policy exchange service can be established that has a policy provider plug-in for each of the distinct policy providers. The federated policy exchange service can receive requests for policies from a set of policy requesters. Each request can include a resource_id or a service_id used to uniquely identify the service or resource. The federated policy exchange service can dynamically connect to a set of the policy providers to determine policies applicable to each request. For each request, results from the policy providers can be received and processed to generate a response. The federated policy exchange service can provide the response to each policy requestor responsive in response to each response.
    • 本发明的一个方面可以包括系统,方法,计算机程序产品和用于从多个策略提供者联合策略的装置。 该方面可以识别一组不同的策略提供者,每个策略提供者保持至少一个与服务或资源相关的策略。 可以建立联合的策略交换服务,其具有针对每个不同策略提供者的策略提供者插件。 联合策略交换服务可以从一组策略请求者接收到策略请求。 每个请求可以包括用于唯一标识服务或资源的resource_id或service_id。 联合策略交换服务可以动态地连接到一组策略提供者,以确定适用于每个请求的策略。 对于每个请求,可以接收和处理策略提供者的结果以产生响应。 联合策略交换服务可以响应于每个响应来响应每个策略请求者。
    • 8. 发明申请
    • Identity Data Model Broker
    • 身份数据模型经纪人
    • US20090171989A1
    • 2009-07-02
    • US11966541
    • 2007-12-28
    • Gregory T. ByrdMichael McintoshAnthony J. NadalinNataraj Nagaratnam
    • Gregory T. ByrdMichael McintoshAnthony J. NadalinNataraj Nagaratnam
    • G06F17/30
    • G06F16/25
    • A method, system and computer program product for handling identity data from heterogeneous sources utilizes an Identity Data Model Broker (IDMB). The IDMB maps fields between heterogeneous data sources, served by disparate Identity Attribute Service (IdAS) context providers, to establish a normalized data format. Within an IdAS, an abstract data model, which is brokered the IDMB, is created to present a normalized view of the data from the IDMB. When a request for data is received at the IdAS, the requested data is retrieved from appropriate data sources, through respective IdAS context providers, normalized to the abstract data model, and provided to the requester by the IdAS, such that the heterogeneous data sources are shielded from the requester.
    • 用于处理来自异构源的身份数据的方法,系统和计算机程序产品利用身份数据模型代理(IDMB)。 IDMB映射异构数据源之间的字段,由不同的身份属性服务(IdAS)上下文提供者提供服务,以建立规范化的数据格式。 在IdAS中,创建了代理IDMB的抽象数据模型,以呈现来自IDMB的数据的归一化视图。 当在IdAS上接收到对数据的请求时,通过相应的IdAS上下文提供者从适当的数据源检索所请求的数据,其被标准化为抽象数据模型,并由IdAS提供给请求者,使得异构数据源是 屏蔽了请求者。