会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Method and apparatus for processing requests in a network data processing system based on a trust association between servers
    • 基于服务器之间的信任关联在网络数据处理系统中处理请求的方法和装置
    • US06965939B2
    • 2005-11-15
    • US09755351
    • 2001-01-05
    • Gennaro A. CuomoWilfred C. JamisonNataraj Nagaratnam
    • Gennaro A. CuomoWilfred C. JamisonNataraj Nagaratnam
    • G06F15/16H04L9/00H04L29/06H04L29/08
    • H04L63/0281H04L63/08H04L63/0807H04L63/102H04L67/28H04L67/2804
    • A method, apparatus, and computer implemented instructions for handling requests in a network data processing system. The network data processing system includes a network and clients connected to the network. A first server is present in which the first server receives a request from a client to access a resource, performs an authentication process with the client, add information to the request in which the information indicates that the request is from a trusted source to form a modified request, and sends the modified request for processing. This modified request is received by a second server. This second server determines whether the first server is a trusted server based on the information, and provides access to the resource in response to a determination that the first server is a trusted server. If the second server receives the request directly from a client, it would process the request by itself instead of basing its trust on any of the known first servers.
    • 一种用于在网络数据处理系统中处理请求的方法,装置和计算机实现的指令。 网络数据处理系统包括网络和连接到网络的客户端。 存在第一服务器,其中第一服务器从客户端接收到访问资源的请求,与客户端进行认证处理,向请求添加信息,在该请求中,该信息指示请求来自可信源,以形成 修改请求,并发送修改后的请求进行处理。 该修改的请求由第二服务器接收。 该第二服务器基于该信息确定第一服务器是否为可信服务器,并响应于确定第一服务器是可信服务器而提供对资源的访问。 如果第二台服务器直接从客户端收到请求,它将自己处理该请求,而不是将其信任放在任何已知的第一台服务器上。
    • 8. 发明授权
    • Federating policies from multiple policy providers
    • 联合政策来自多个政策提供者
    • US08683545B2
    • 2014-03-25
    • US12192769
    • 2008-08-15
    • Anthony J. NadalinNataraj NagaratnamSridhar R. Muppidi
    • Anthony J. NadalinNataraj NagaratnamSridhar R. Muppidi
    • G06F21/00
    • H04L63/102H04L63/20
    • One aspect of the present invention can include a system, a method, a computer program product and an apparatus for federating policies from multiple policy providers. The aspect can identify a set of distinct policy providers, each maintaining at least one policy related to a service or a resource. A federated policy exchange service can be established that has a policy provider plug-in for each of the distinct policy providers. The federated policy exchange service can receive requests for policies from a set of policy requesters. Each request can include a resource_id or a service_id used to uniquely identify the service or resource. The federated policy exchange service can dynamically connect to a set of the policy providers to determine policies applicable to each request. For each request, results from the policy providers can be received and processed to generate a response. The federated policy exchange service can provide the response to each policy requestor responsive in response to each response.
    • 本发明的一个方面可以包括系统,方法,计算机程序产品和用于从多个策略提供者联合策略的装置。 该方面可以识别一组不同的策略提供者,每个策略提供者保持至少一个与服务或资源相关的策略。 可以建立联合的策略交换服务,其具有针对每个不同策略提供者的策略提供者插件。 联合策略交换服务可以从一组策略请求者接收到策略请求。 每个请求可以包括用于唯一标识服务或资源的resource_id或service_id。 联合策略交换服务可以动态地连接到一组策略提供者,以确定适用于每个请求的策略。 对于每个请求,可以接收和处理策略提供者的结果以产生响应。 联合策略交换服务可以响应于每个响应来响应每个策略请求者。
    • 9. 发明授权
    • Classification and policy management for software components
    • 软件组件的分类和策略管理
    • US08112370B2
    • 2012-02-07
    • US12235900
    • 2008-09-23
    • Sridhar R MuppidiNataraj NagaratnamAnthony Joseph Nadalin
    • Sridhar R MuppidiNataraj NagaratnamAnthony Joseph Nadalin
    • G06N5/00
    • G06F21/604
    • A method, system, and computer usable program product for classification and policy management for software components are provided in the illustrative embodiments. A metadata associated with an application or component is identified. A mapping determination is made whether the metadata maps to a classification in a set of classifications. A policy that is applicable to the classification is identified and associated with the classification. If the mapping determination is deterministic, the component is assigned to the classification and the policy associated with the classification is associated with the component. If the mapping determination is not deterministic, a user intervention may be necessary, the component may be classified in a default classification, or both. Because of the policy being associated with the classification, associating the policy with the component may occur based on the metadata of the application or component and its resultant classification.
    • 在说明性实施例中提供了用于软件组件的分类和策略管理的方法,系统和计算机可用程序产品。 识别与应用或组件相关联的元数据。 做出映射确定是否元数据映射到一组分类中的分类。 识别适用于分类的策略并与分类相关联。 如果映射确定是确定性的,则将组件分配给分类,并且与分类相关联的策略与组件相关联。 如果映射确定不是确定性的,则可能需要用户干预,该组件可以被分类为默认分类,或者两者。 由于与分类相关联的策略,将策略与组件相关联可以基于应用或组件的元数据及其合成分类而发生。
    • 10. 发明申请
    • DECLARATIVE INSTANCE BASED ACCESS CONTROL FOR APPLICATION RESOURCES WITH PERSISTED ATTRIBUTES AND STATE
    • 具有相关属性和状态的应用资源的基于事件的基于实例的访问控制
    • US20090183184A1
    • 2009-07-16
    • US12013867
    • 2008-01-14
    • Anthony J. NadalinNataraj NagaratnamIndrajit Poddar
    • Anthony J. NadalinNataraj NagaratnamIndrajit Poddar
    • G06F9/54
    • G06F9/4435G06F9/4493
    • Embodiments of the present invention provide a method, system and computer program product for declarative instance based access control for persistent application resources in a multi-tier application. In one embodiment of the invention, a method for instance based access control in a persistent application resource can be provided. The method can include creating one or more instances of an persistent application resource for a particular user or based on attributes of the user, coupling the instance(s) of the persistent application resource to a database implementing row-level access control, initializing access to the database according to a role or attribute for the particular user, and accessing a restricted set of data in the database through the instance(s) of the persistent application resource.
    • 本发明的实施例提供了一种用于在多层应用中用于持久应用资源的基于声明性实例的访问控制的方法,系统和计算机程序产品。 在本发明的一个实施例中,可以提供用于持久应用资源中的基于实例的访问控制的方法。 该方法可以包括为特定用户创建持久性应用资源的一个或多个实例,或者基于用户的属性,将持久应用资源的实例耦合到实现行级访问控制的数据库,初始化对 数据库根据特定用户的角色或属性,以及通过持久性应用程序资源的实例访问数据库中受限制的一组数据。