会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明申请
    • METHOD AND APPARATUS FOR CONTROLLING ACCESS TO A RESOURCE IN A COMPUTER DEVICE
    • 用于控制在计算机设备中访问资源的方法和装置
    • WO2013045928A1
    • 2013-04-04
    • PCT/GB2012/052394
    • 2012-09-27
    • AVECTO LIMITEDAUSTIN, Mark James
    • AUSTIN, Mark James
    • G06F21/54
    • G06F21/31G06F21/335G06F21/54G06F21/604G06F21/6227G06F2221/2141
    • A computer device (200) and method are described for controlling access to a resource (115). An execution environment (203) executes a user process (120) with access privileges according to a user security context (121). A security unit (250) controls access to resources (115, 125) according to the user security context (121a), with the user process (120) making system calls (501 ) to the security unit (250). A proxy hook module (310) embedded within the user process (120) intercepts the system call (501 ) and generates a proxy resource access request (502). A proxy service module (320) in a privileged security context (111 ) validates the proxy resource access request (502) from the proxy hook module (310) and, if validated, obtains and returns a resource handle that permits access to the desired resource (115) by the user process (120).
    • 描述了用于控制对资源(115)的访问的计算机设备(200)和方法。 执行环境(203)根据用户安全上下文(121)执行具有访问权限的用户进程(120)。 安全单元(250)根据用户安全上下文(121a)控制对资源(115,125)的访问,用户进程(120)向安全单元(250)进行系统呼叫(501)。 嵌入用户进程(120)内的代理挂钩模块(310)拦截系统呼叫(501)并产生代理资源访问请求(502)。 特权安全上下文(111)中的代理服务模块(320)从代理挂钩模块(310)验证代理资源访问请求(502),并且如果被验证,则获得并返回允许访问期望资源的资源句柄 (115)由用户进程(120)。