Security Objects Controlling Access To Resources
Abstract
Controlling access to resources through use of security objects including creating a security object in dependence upon user-selected security control data types, the security object comprising security control data and at least one security method; receiving a request for access to the resource; receiving security request data; and determining access to the resource in dependence upon the security control data and the security request data. Creating a security object includes storing in the security object a resource identification for the resource; storing in the security object an authorization level of access for the resource; storing in the security object user-selected security control data types; and storing in the security object security control data for each user-selected security control data type. Embodiments include deploying the security object on a security server or on a client device.
Claims
exact text as granted — not AI-modified1 . A method of controlling access to a resource, the method comprising:
creating a security object in dependence upon user-selected security control data types, the security object comprising security control data and at least one security method receiving a request for access to the resource; receiving security request data; and determining access to the resource in dependence upon the security control data and the security request data.
2 . The method of claim 1 wherein creating a security object further comprises:
storing in the security object a resource identification for the resource; storing in the security object an authorization level of access for the resource; storing in the security object user-selected security control data types; and storing, in the security object, security control data for each user-selected security control data type.
3 . The method of claim 2 wherein determining access includes authorizing a level of access in dependence upon the authorization level of access for the resource.
4 . The method of claim 1 further comprising deploying the security object.
5 . The method of claim 1 further comprising deploying the security object on a client device.
6 . The method of claim 1 wherein the resource is located on a security server.
7 . The method of claim 1 wherein the resource is located on a client device.
8 . The method of claim 1 wherein:
the resource resides on a client device, the client device having an application program, the method further comprises deploying the security object on the client device, and receiving a request for access to the resource further comprises receiving, in the security object itself, the request for access to the resource as a call to the security method.
9 . The method of claim 1 wherein receiving a request for access to the resource comprises calling the security method.
10 . The method of claim 1 wherein receiving a request for access to the resource further comprises identifying the security object.
11 . The method of claim 10 wherein identifying the security object comprises identifying the security object in dependence upon a URI.
12 . The method of claim 11 wherein identifying the security object comprises identifying the security object in dependence upon a URI that identifies the resource, including finding, in dependence upon the URI identifying the resource, an identification of the security object in an access control table.
13 . A system for controlling access to a resource, the system comprising:
means for creating a security object in dependence upon user-selected security control data types, the security object comprising security control data and at least one security method; means for receiving a request for access to the resource; means for receiving security request data; and means for determining access to the resource in dependence upon the security control data and the security request data.
14 . The system of claim 13 wherein means for creating a security object further comprises:
means for storing in the security object a resource identification for the resource; means for storing in the security object an authorization level of access for the resource; means for storing in the security object user-selected security control data types; and means for storing in the security object security control data for each user-selected security control data type.
15 . The system of claim 15 wherein means for determining access includes means for authorizing a level of access in dependence upon the authorization level of access for the resource.
16 . The system of claim 13 further comprising means for deploying the security object.
17 . The system of claim 13 further comprising means for deploying the security object on a security server.
18 . The system of claim 13 further comprising means for deploying the security object on a client device.
19 . The system of claim 13 wherein the resource is located on a security server.
20 . The system of claim 13 wherein the resource is located on a client device.
21 . The system of claim 13 wherein:
the resource resides on a client device, the client device having an application program, the system further comprises means for deploying the security object on the client device, and means for receiving a request for access to the resource further comprises means for receiving, in the security object itself, the request for access to the resource as a call to the security method.
22 . The system of claim 13 wherein means for receiving a request for access to the resource comprises means for calling the security method.
23 . The system of claim 13 wherein means for receiving a request for access to the resource further comprises means for identifying the security object.
24 . The system of claim 23 wherein means for identifying the security object comprises means for identifying the security object in dependence upon a URI.
25 . The method of claim 24 wherein means for identifying the security object comprises means for identifying the security object in dependence upon a URI that identifies the resource, including means for finding, in dependence upon the URI identifying the resource, an identification of the security object in an access control table.
26 . A computer program product for controlling access to a resource, the computer program product comprising:
a recording medium; means, recorded on the recording medium, for creating a security object in dependence upon user-selected security control data types, the security object comprising security control data and at least one security; means, recorded on the recording medium, for receiving a request for access to the resource; means, recorded on the recording medium, for receiving security request data; and means, recorded on the recording medium, for determining access to the resource in dependence upon the security control data and the security request data.
27 . The computer program product of claim 26 wherein means for creating a security object further comprises:
means, recorded on the recording medium, for storing in the security object a resource identification for the resource; means, recorded on the recording medium, for storing in the security object an authorization level of access for the resource; means, recorded on the recording medium, for storing in the security object user-selected security control data types; and means, recorded on the recording medium, for storing in the security object security control data for each user-selected security control data type.
28 . The computer program product of claim 26 wherein means for determining access includes means, recorded on the recording medium, for authorizing a level of access in dependence upon the authorization level of access for the resource.
29 . The computer program product of claim 26 further comprising means, recorded on the recording medium, for deploying the security object.
30 . The computer program product of claim 26 further comprising means, recorded on the recording medium, for deploying the security object on a client device.
31 . The computer program product of claim 26 wherein the resource is located on a security server.
32 . The computer program product of claim 26 wherein the resource is located on a client device.
33 . The computer program product of claim 26 wherein:
the resource resides on a client device, the client device having an application program, the system further comprises means, recorded on the recording medium, for deploying the security object on the client device, and means for receiving a request for access to the resource further comprises means, recorded on the recording medium, for receiving, in the security object itself, the request for access to the resource as a call to the security method.
34 . The computer program product of claim 26 wherein means for receiving a request for access to the resource comprises means, recorded on the recording medium, for calling the security method.
35 . The computer program product of claim 26 wherein means for receiving a request for access to the resource further comprises means, recorded on the recording medium, for identifying the security object.
36 . The computer program product of claim 35 wherein means for identifying the security object comprises means, recorded on the recording medium, for identifying the security object in dependence upon a URI.
37 . The computer program product of claim 36 wherein means for identifying the security object comprises means, recorded on the recording medium, for identifying the security object in dependence upon a URI that identifies the resource, including means, recorded on the recording medium, for finding, in dependence upon the URI identifying the resource, an identification of the security object in an access control table.Join the waitlist — get patent alerts
Track US2008256628A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.