US2007294404A1PendingUtilityA1

Method and system for authorization and access control delegation in an on demand grid environment

Assignee: IBMPriority: Jun 15, 2006Filed: Jun 15, 2006Published: Dec 20, 2007
Est. expiryJun 15, 2026(expired)· nominal 20-yr term from priority
Inventors:Irwin Boutboul
H04L 63/0823H04L 41/28H04L 63/101H04L 41/044
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The method of the invention provides for dynamic on-demand delegation of control and access in a grid computing environment comprising granting authority of a grid node to a first moderator by a superauthority; admitting the first moderator to the grid node; modifying the access control list of the grid node by the first moderator; inviting other entities listed on the access control list to access the grid node; and issuing a unique authorization certificate to each of the other entities, wherein the first moderator controls the inviting of the other entities without contact with or accessing to the superauthority for certification.

Claims

exact text as granted — not AI-modified
1 . A method for dynamic delegation of control in a grid computing environment comprising:
 granting authority of a grid node to a moderator by a superauthority;   admitting said moderator to said grid node;   modifying an access control list of said grid node by said moderator; and   inviting other entities listed on said access control list to access said grid node,   wherein said first moderator controls said inviting of said other entities without contact with said superauthority.   
   
   
       2 . The method of  claim 1 , wherein said modifying comprising adding or deleting said other entities on said access control list. 
   
   
       3 . The method of  claim 1 , further comprising issuing a unique authorization certificate to each of said other entities. 
   
   
       4 . The method of  claim 1 , further comprising delegating privileged users by said moderator, wherein said moderator controls said delegating privileged users without contact with said superauthority. 
   
   
       5 . The method of  claim 4 , wherein said modifying of said access control list is performed by either said moderator or said privileged users. 
   
   
       6 . The method of  claim 4 , wherein said delegating of said privileged users is performed by said moderator or privileged users. 
   
   
       7 . A method for dynamic delegation of control in a grid computing environment comprising:
 granting authority of a grid node to a moderator by a superauthority;   admitting said moderator to said grid node;   modifying an access control list of said grid node by said moderator;   inviting other entities listed on said access control list to access said grid node; and   issuing a unique authorization certificate to each of said other entities;   wherein said moderator controls said inviting of said other entities without contact with said superauthority.   
   
   
       8 . The method of  claim 6 , wherein said modifying comprising adding or deleting said other entities on said access control list. 
   
   
       9 . The method of  claim 6 , further comprising delegating privileged users by said first moderator, wherein said moderator controls said delegating privileged users without contact with said superauthority. 
   
   
       10 . The method of  claim 9 , wherein said modifying of said access control list is performed by either said moderator or said privileged users. 
   
   
       11 . The method of  claim 9 , wherein said delegating of said privileged users is performed by said first moderator or said privileged users. 
   
   
       12 . A computer program product readable by machine, tangibly embodying a program of instructions executable by said machine to perform a method for dynamic delegation of control in a grid computing environment, said method comprising:
 granting authority of a grid node to a moderator by a superauthority;   admitting said moderator to said grid node;   modifying an access control list of said grid node by said moderator wherein said modeling comprises adding or deleting said other entities on said access control list;   inviting other entities listed on said access control list to access said grid node; and   issuing a unique authorization certificate to each of said other entities;   wherein said moderator controls said inviting of said other entities without contact with said superauthority.   
   
   
       13 . The computer program product of  claim 12 , further comprising delegating privileged users by said moderator, wherein said moderator controls said delegating privileged users without contact with said superauthority. 
   
   
       14 . The computer program product of  claim 13 , wherein said modifying of said access control list is performed by either said moderator or said privileged users. 
   
   
       15 . The computer program product of  claim 13 , wherein said delegating of said privileged users is performed by said moderator or said privileged users. 
   
   
       16 . A service for dynamic delegation of control in a grid computing environment comprising:
 granting authority of a grid node to a moderator by a superauthority;   admitting said moderator to said grid node;   modifying an access control list of said grid node by said moderator;   inviting other entities listed on said access control list to access said grid node; and   issuing a unique authorization certificate to each of said other entities;   wherein said moderator controls said inviting of said other entities without contact with said superauthority.   
   
   
       17 . The service of  claim 16 , wherein said modifying comprising adding or deleting said other entities on said access control list. 
   
   
       18 . The service of  claim 16 , further comprising delegating privileged users by said moderator, wherein said moderator controls said delegating privileged users without contact with said superauthority. 
   
   
       19 . The service of  claim 18 , wherein said modifying of said access control list is performed by either said moderator or said privileged users. 
   
   
       20 . The service of  claim 18 , wherein said delegating of said additional moderators is performed by said moderator or said privileged users.

Join the waitlist — get patent alerts

Track US2007294404A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.