US2008256628A1PendingUtilityA1

Security Objects Controlling Access To Resources

Assignee: HIMMEL MARIA AZUAPriority: Jun 24, 2002Filed: Jun 19, 2007Published: Oct 16, 2008
Est. expiryJun 24, 2022(expired)· nominal 20-yr term from priority
G06F 21/6218G06F 2221/2113G06F 2221/2119G06F 2221/2141
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Controlling access to resources through use of security objects including creating a security object in dependence upon user-selected security control data types, the security object comprising security control data and at least one security method; receiving a request for access to the resource; receiving security request data; and determining access to the resource in dependence upon the security control data and the security request data. Creating a security object includes storing in the security object a resource identification for the resource; storing in the security object an authorization level of access for the resource; storing in the security object user-selected security control data types; and storing in the security object security control data for each user-selected security control data type. Embodiments include deploying the security object on a security server or on a client device.

Claims

exact text as granted — not AI-modified
1 . A method of controlling access to a resource, the method comprising:
 creating a security object in dependence upon user-selected security control data types, the security object comprising security control data and at least one security method   receiving a request for access to the resource;   receiving security request data; and   determining access to the resource in dependence upon the security control data and the security request data.   
   
   
       2 . The method of  claim 1  wherein creating a security object further comprises:
 storing in the security object a resource identification for the resource;   storing in the security object an authorization level of access for the resource;   storing in the security object user-selected security control data types; and   storing, in the security object, security control data for each user-selected security control data type.   
   
   
       3 . The method of  claim 2  wherein determining access includes authorizing a level of access in dependence upon the authorization level of access for the resource. 
   
   
       4 . The method of  claim 1  further comprising deploying the security object. 
   
   
       5 . The method of  claim 1  further comprising deploying the security object on a client device. 
   
   
       6 . The method of  claim 1  wherein the resource is located on a security server. 
   
   
       7 . The method of  claim 1  wherein the resource is located on a client device. 
   
   
       8 . The method of  claim 1  wherein:
 the resource resides on a client device, the client device having an application program,   the method further comprises deploying the security object on the client device, and   receiving a request for access to the resource further comprises receiving, in the security object itself, the request for access to the resource as a call to the security method.   
   
   
       9 . The method of  claim 1  wherein receiving a request for access to the resource comprises calling the security method. 
   
   
       10 . The method of  claim 1  wherein receiving a request for access to the resource further comprises identifying the security object. 
   
   
       11 . The method of  claim 10  wherein identifying the security object comprises identifying the security object in dependence upon a URI. 
   
   
       12 . The method of  claim 11  wherein identifying the security object comprises identifying the security object in dependence upon a URI that identifies the resource, including finding, in dependence upon the URI identifying the resource, an identification of the security object in an access control table. 
   
   
       13 . A system for controlling access to a resource, the system comprising:
 means for creating a security object in dependence upon user-selected security control data types, the security object comprising security control data and at least one security method;   means for receiving a request for access to the resource;   means for receiving security request data; and   means for determining access to the resource in dependence upon the security control data and the security request data.   
   
   
       14 . The system of  claim 13  wherein means for creating a security object further comprises:
 means for storing in the security object a resource identification for the resource;   means for storing in the security object an authorization level of access for the resource;   means for storing in the security object user-selected security control data types; and   means for storing in the security object security control data for each user-selected security control data type.   
   
   
       15 . The system of  claim 15  wherein means for determining access includes means for authorizing a level of access in dependence upon the authorization level of access for the resource. 
   
   
       16 . The system of  claim 13  further comprising means for deploying the security object. 
   
   
       17 . The system of  claim 13  further comprising means for deploying the security object on a security server. 
   
   
       18 . The system of  claim 13  further comprising means for deploying the security object on a client device. 
   
   
       19 . The system of  claim 13  wherein the resource is located on a security server. 
   
   
       20 . The system of  claim 13  wherein the resource is located on a client device. 
   
   
       21 . The system of  claim 13  wherein:
 the resource resides on a client device, the client device having an application program,   the system further comprises means for deploying the security object on the client device, and   means for receiving a request for access to the resource further comprises means for receiving, in the security object itself, the request for access to the resource as a call to the security method.   
   
   
       22 . The system of  claim 13  wherein means for receiving a request for access to the resource comprises means for calling the security method. 
   
   
       23 . The system of  claim 13  wherein means for receiving a request for access to the resource further comprises means for identifying the security object. 
   
   
       24 . The system of  claim 23  wherein means for identifying the security object comprises means for identifying the security object in dependence upon a URI. 
   
   
       25 . The method of  claim 24  wherein means for identifying the security object comprises means for identifying the security object in dependence upon a URI that identifies the resource, including means for finding, in dependence upon the URI identifying the resource, an identification of the security object in an access control table. 
   
   
       26 . A computer program product for controlling access to a resource, the computer program product comprising:
 a recording medium;   means, recorded on the recording medium, for creating a security object in dependence upon user-selected security control data types, the security object comprising security control data and at least one security;   means, recorded on the recording medium, for receiving a request for access to the resource;   means, recorded on the recording medium, for receiving security request data; and   means, recorded on the recording medium, for determining access to the resource in dependence upon the security control data and the security request data.   
   
   
       27 . The computer program product of  claim 26  wherein means for creating a security object further comprises:
 means, recorded on the recording medium, for storing in the security object a resource identification for the resource;   means, recorded on the recording medium, for storing in the security object an authorization level of access for the resource;   means, recorded on the recording medium, for storing in the security object user-selected security control data types; and   means, recorded on the recording medium, for storing in the security object security control data for each user-selected security control data type.   
   
   
       28 . The computer program product of  claim 26  wherein means for determining access includes means, recorded on the recording medium, for authorizing a level of access in dependence upon the authorization level of access for the resource. 
   
   
       29 . The computer program product of  claim 26  further comprising means, recorded on the recording medium, for deploying the security object. 
   
   
       30 . The computer program product of  claim 26  further comprising means, recorded on the recording medium, for deploying the security object on a client device. 
   
   
       31 . The computer program product of  claim 26  wherein the resource is located on a security server. 
   
   
       32 . The computer program product of  claim 26  wherein the resource is located on a client device. 
   
   
       33 . The computer program product of  claim 26  wherein:
 the resource resides on a client device, the client device having an application program,   the system further comprises means, recorded on the recording medium, for deploying the security object on the client device, and   means for receiving a request for access to the resource further comprises means, recorded on the recording medium, for receiving, in the security object itself, the request for access to the resource as a call to the security method.   
   
   
       34 . The computer program product of  claim 26  wherein means for receiving a request for access to the resource comprises means, recorded on the recording medium, for calling the security method. 
   
   
       35 . The computer program product of  claim 26  wherein means for receiving a request for access to the resource further comprises means, recorded on the recording medium, for identifying the security object. 
   
   
       36 . The computer program product of  claim 35  wherein means for identifying the security object comprises means, recorded on the recording medium, for identifying the security object in dependence upon a URI. 
   
   
       37 . The computer program product of  claim 36  wherein means for identifying the security object comprises means, recorded on the recording medium, for identifying the security object in dependence upon a URI that identifies the resource, including means, recorded on the recording medium, for finding, in dependence upon the URI identifying the resource, an identification of the security object in an access control table.

Join the waitlist — get patent alerts

Track US2008256628A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.