Security policy generation
Abstract
The invention provides security policy generation methods and devices for generating a security policy that is set up for an information processing apparatus comprises a step of generating an application model having a transmitter and a receiver of a message decided, for each of a plurality of messages that are communicated, a step of storing in advance a plurality of security patterns with a signer of electronic signature appended to the message as an undecided parameter, a step of selecting a security pattern that is a model of security policy to be setup for the transmitter or receiver of the message, corresponding to each of the plurality of messages included in the application model, and a step of substituting the identification information of the transmitter or receiver of each message included in the application model for the undecided parameter of the security pattern selected corresponding to the message.
Claims
exact text as granted — not AI-modified1 . A security policy generation method comprising generating a security policy that decides at least one electronic signature to be appended to a message transmitted or received by an information processing apparatus and an encryption method for encrypting the message transmitted or received by the information processing apparatus, the security policy being set up for the information processing apparatus, the step of generating a security policy comprising:
an application model generation step of generating an application model having a transmitter and a receiver of the message decided, for each of a plurality of messages that are communicated using a distributed application program, according to an instruction of the user; a security pattern storage step of storing in advance a plurality of security patterns that are models of security policy with a signer of electronic signature appended to the message or a decoder for decoding the encrypted message as an undecided parameter; a security pattern selection step of selecting a security pattern that is a model of security policy to be set up for the transmitter or receiver of the message, corresponding to each of the plurality of messages included in the application model, according to an instruction of the user; and a security policy generation step of generating the security policy by substituting the identification information of the transmitter or receiver of each message included in the application model for the undecided parameter of the security pattern selected corresponding to the message.
2 . The security policy generation method according to claim 1 , wherein the security pattern storage step stores as the security pattern, a setting for the receiver of the message that includes the transmitter of the message as an undecided parameter and indicates that the reception of the message with the electronic signature of the transmitter appended thereto is permitted, and the security policy generation step substitutes in response that the security pattern is selected, the identification information of the transmitter of the message corresponding to the security pattern for the undecided parameter of the security pattern regarding the transmitter.
3 . The security policy generation method according to claim 1 , wherein the security pattern storage step stores as the security pattern, a setting for the receiver of the message that includes the receiver of the message as an undecided parameter and indicates that the reception of the message encrypted using a cipher that the receiver can decode is permitted, and
the security policy generation step substitutes in response that the security pattern is selected, the identification information of the receiver of the message corresponding to the security pattern for the undecided parameter of the security pattern regarding the receiver.
4 . The security policy generation method according to claim 1 , wherein the message comprises a plurality of message parts, and
the application model generation step generates for each message part the application model having a transmitter and a receiver of the message part decided, and the security pattern selection step selects a security pattern that is a model of security policy to be set up for the transmitter or receiver of the message part, corresponding to each of the plurality of message parts, and the security policy generation step generates a security policy by substituting the identification information of the transmitter or receiver of each message part for the undecided parameter of the security pattern selected corresponding to the message part.
5 . The security policy generation method according to claim 1 , wherein the security pattern storage step stores a security pattern for transmitter, a security pattern for receiver and a security pattern for intermediary, each being a model of security policy settable in each of the transmitter, receiver and intermediary of the message,
the security policy generation method further comprising a candidate selection step of selecting according to the determination of whether the information processing apparatus of security policy setting object is any one of a transmitter, a receiver and an intermediary of the message of security policy setting object, the candidates of security patterns settable in the information processing apparatus, wherein the security pattern selection step selects a security pattern from among the candidates of security patterns selected by the candidate selection step, according to an instruction of the user.
6 . The security policy generation method according to claim 5 , wherein the security pattern storage step stores a security pattern that includes a presence attribute indicating the presence of an intermediary in the message of setting object or a presence inhibition attribute indicating the prohibition of the presence of an intermediary in the message of setting object, and
the candidate selection step selects the candidates of security patterns according to the determination of whether there exists an intermediary in the message of setting object.
7 . The security policy generation method according to claim 1 , further comprising a platform model storage step of storing in advance an encryption processing parameter used in a process of encryption or decoding by the information processing apparatus or a signature processing parameter used in a process of generating the electronic signature or in a process of authenticating the electronic signature by the information processing apparatus, each parameter being specified in advance for each information processing apparatus, wherein the security pattern storage step stores a security pattern that includes as an additional undecided parameter the encryption processing parameter used in the process of encryption or decoding or the signature processing parameter used in the process of generating the electronic signature to be appended to the message or in the process of authenticating the electronic signature, and
the security policy generation step further substitutes the encryption processing parameter or the signature processing parameter in the information processing apparatus of security policy setting object for the undecided parameter of the security pattern.
8 . A security policy generation device for generating a security policy that decides at least one of an electronic signature to be appended to a message transmitted or received by an information processing apparatus and an encryption method for encrypting the message transmitted or received by the information processing apparatus, the security policy being set up for the information processing apparatus, said device comprising:
an application model generation part for generating an application model having a transmitter and a receiver of the message decided, for each of a plurality of messages that are communicated using a distributed application program, according to an instruction of the user; a security pattern storage part for storing in advance a plurality of security patterns that are models of security policy with a signer of electronic signature appended to the message or a decoder for decoding the encrypted message as an undecided parameter; a security policy pattern selection part for selecting a security pattern that is a model of security policy to be set up for the transmitter or receiver of the message, corresponding to each of the plurality of messages included in the application model, according to an instruction of the user; and a security policy generation part for generating a security policy by substituting the identification information of the transmitter or receiver of each message included in the application model for the undecided parameter of the security pattern selected corresponding to the message.
9 . The security policy generation device according to claim 8 , wherein the security pattern storage step stores as the security pattern, a setting for the receiver of the message that includes the transmitter of the message as an undecided parameter and indicates that the reception of the message with the electronic signature of the transmitter appended thereto is permitted, and
the security policy generation part substitutes in response that the security pattern is selected, the identification information of the transmitter of the message corresponding to the security pattern for the undecided parameter of the security pattern regarding the transmitter.
10 . The security policy generation device according to claim 8 , wherein the security pattern storage part stores as the security pattern, a setting for the receiver of the message that includes the receiver of the message as an undecided parameter and indicates that the reception of the message encrypted using a cipher that the receiver can decode is permitted, and
the security policy generation part substitutes in response that the security pattern is selected, the identification information of the receiver of the message corresponding to the security pattern for the undecided parameter of the security pattern regarding the receiver.
11 . The security policy generation device according to claim 8 , wherein the message comprises a plurality of message parts, and
the application model generation part generates for each message part the application model having a transmitter and a receiver of the message part decided, and the security pattern selection part selects a security pattern that is a model of security policy to be set up for the transmitter or receiver of the message part, corresponding to each of the plurality of message parts, and the security policy generation part generates a security policy by substituting the identification information of the transmitter or receiver of each message part for the undecided parameter of the security pattern selected corresponding to the message part.
12 . The security policy generation device according to claim 8 , wherein the security pattern storage part stores a security pattern for transmitter, a security pattern for receiver and a security pattern for intermediary, each being a model of security policy settable in each of the transmitter, receiver and intermediary of the message,
the security policy generation device further comprising a candidate selection part of selecting according to the determination of whether the information processing apparatus of security policy setting object is any one of a transmitter, a receiver and an intermediary of the message of security policy setting object, the candidates of security pattern settable in the information processing apparatus, wherein the security pattern selection part selects a security pattern from among the candidates of security patterns selected by the candidate selection step, according to an instruction of the user.
13 . The security policy generation device according to claim 12 , wherein the security pattern storage part stores a security pattern that includes a presence attribute indicating the presence of an intermediary in the message of setting object or a presence inhibition attribute indicating the prohibition of the presence of an intermediary in the message of setting object, and the candidate selection part selects the candidates of security patterns according to the determination of whether there exists an intermediary in the message of setting object.
14 . The security policy generation device according to claim 8 , wherein further comprising a platform model storage part of storing in advance an encryption processing parameter used in a process of encryption or decoding by the information processing apparatus or a signature processing parameter used in a process of generating an electronic signature or in a process of authenticating an electronic signature by the information processing apparatus, each parameter being specified in advance for each information processing apparatus, wherein the security pattern storage part stores a security pattern that includes as an additional undecided parameter the encryption processing parameter used in the process of encryption or decoding or the signature processing parameter used in the process of generating the electronic signature to be appended to the message or in the process of authenticating the electronic signature, and
the security policy generation part further substitutes the encryption processing parameter or the signature processing parameter in the information processing apparatus of security policy setting object for the undecided parameter of the security pattern.
15 . A program for enabling a computer to operate as a security policy generation device for generating a security policy that decides at least one of an electronic signature to be appended to a message transmitted or received by an information processing apparatus and an encryption method for encrypting the message transmitted or received by the information processing apparatus, the security policy being set up for the information processing apparatus, the program enabling the computer to operate as:
an application model generation part for generating an application model having a transmitter and a receiver of the message decided, for each of a plurality of messages that are communicated using a distributed application program, according to an instruction of the user; a security pattern storage part for storing in advance a plurality of security patterns that are models of security policy with a signer of electronic signature appended to the message or a decoder for decoding the encrypted message as an undecided parameter; a security policy pattern selection part for selecting a security pattern that is a model of security policy to be set up for the transmitter or receiver of the message, corresponding to each of the plurality of messages included in the application model, according to an instruction of the user; and a security policy generation part for generating a security policy by substituting the identification information of the transmitter or receiver of each message included in the application model for the undecided parameter of the security pattern selected corresponding to the message.
16 . A recording medium on which the program according to claim 15 is recorded.
17 . The security policy generation method according to claim 1 , wherein:
the security pattern storage step stores as the security pattern, a setting for the receiver of the message that includes the transmitter of the message as an undecided parameter and indicates that the reception of the message with the electronic signature of the transmitter appended thereto is permitted, and the security policy generation step substitutes in response that the security pattern is selected, the identification information of the transmitter of the message corresponding to the security pattern for the undecided parameter of the security pattern regarding the transmitter; the security pattern storage step stores a security pattern for transmitter, a security pattern for receiver and a security pattern for intermediary, each being a model of security policy settable in each of the transmitter, receiver and intermediary of the message, the security policy generation method further comprising a candidate selection step of selecting according to the determination of whether the information processing apparatus of security policy setting object is any one of a transmitter, a receiver and an intermediary of the message of security policy setting object, the candidates of security patterns settable in the information processing apparatus, wherein the security pattern selection step selects a security pattern from among the candidates of security patterns selected by the candidate selection step, according to an instruction of the user; the security pattern storage step stores a security pattern that includes a presence attribute indicating the presence of an intermediary in the message of setting object or a presence inhibition attribute indicating the prohibition of the presence of an intermediary in the message of setting object, and the candidate selection step selects the candidates of security pattern according to the determination of whether there exists an intermediary in the message of setting object.
18 . An article of manufacture comprising a computer usable medium having computer readable program code means embodied therein for causing generation of a security policy, the computer readable program code means in said article of manufacture comprising computer readable program code means for causing a computer to effect the steps of claim 1 .
19 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform method steps for generating a security policy, said method steps comprising the steps of claim 1 .
20 . A computer program product comprising a computer usable medium having computer readable program code means embodied therein for causing generation of security policy, the computer readable program code means in said computer program product comprising computer readable program code means for causing a computer to effect the functions of claim 8.Join the waitlist — get patent alerts
Track US2005283824A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.