Techniques and System for Specifying Policies Using Abstractions
Abstract
A policy language for an information management system allows specifying or more policies using policy abstractions. The policies and policy abstractions are decoupled from one another, so policies and policy abstractions may be specified and altered separately from each other. A policy may refer to any number of policy abstractions. Multiple policies may reference a single policy abstraction, and a change to that policy abstraction will result in multiple policies being changed. Further, policy abstractions may be nested, so one policy abstraction may reference another policy abstraction, and so forth.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1 . A method of managing information comprising:
providing a plurality of policies stored at a server, wherein a first policy comprises a first conditional statement comprising a first variable defined by a first abstraction and a first corresponding action that will be performed when the first conditional statement is satisfied, the first abstraction comprises a definition statement stored separately from the first policy; determining a subset of the plurality of policies relevant to a target; transferring the subset of the plurality of policies comprising the first conditional statement comprising the first variable at the target, wherein the subset of the plurality of policies is stored at the target; and allowing the target to control access to the information based on the subset of the plurality of policies stored at the target.
2 . The method of claim 1 wherein the information, for which the target controls access, is stored at the server.
3 . The method of claim 1 wherein the information, for which the target controls access, is stored at the target device.
4 . The method of claim 1 wherein the definition statement associated with the first variable is not transferred and stored at the target.
5 . The method of claim 1 wherein the target comprises a device.
6 . The method of claim 1 wherein the target is a computer, and the computer comprises executable code controlling access to the information based on the subset of policies.
7 . The method of claim 1 wherein the first variable comprises a resource, and the resource comprises at least one of a file, an e-mail message, a Web page, a file system object, a portlet, a range of cells on a spreadsheet, a named region in a document, or an application data object.
8 . A method of managing information comprising:
providing a plurality of policies stored at a server, wherein a first policy comprises a first conditional statement comprising a first variable defined by a first abstraction and a first corresponding action that will be performed when the first conditional statement is satisfied, and the first abstraction comprises a definition statement stored separately from the first policy; transferring at least one of the plurality of policies to a target; and allowing the target to control application usage based on the plurality of policies transferred to the target, wherein application is resident at the target.
9 . The method of claim 8 wherein the target is a computer, and the computer comprises executable code controlling application usage.
10 . The method of claim 8 wherein the at least one of the plurality of policies transferred to a target is stored at the target.
11 . The method of claim 8 wherein the application, for which the target controls usage, is a word processing program.
12 . The method of claim 8 wherein the application, for which the target controls usage, is a spreadsheet program.
13 . The method of claim 8 wherein the application, for which the target controls usage, is an e-mail program.
14 . The method of claim 8 wherein the application, for which the target controls usage, is a Web browser program.
15 . An information management system comprising:
a plurality of rule components and a plurality of abstraction components, wherein a rule component comprises an expression having a variable, and the variable is defined in an abstraction component; a policy server component, accessing the rule and abstraction components; a target device component, coupled through a network connection to the policy server component, the target device comprising a code component, wherein the rule and abstraction components stored remotely from the target device component are stored separately; a deployment mode of operation in which the policy server determines a subset of rule and abstraction components are relevant to the target device component and transfers this subset of rule and abstraction components to the target device component via the network connection; and an execution mode of operation in which the code component of the target device manages access to information based on the subset of rule and abstraction components.
16 . The system of claim 15 wherein the subset of rule and abstraction components is stored at the target device.
17 . The system of claim 15 wherein the information, for which the target device manages access to, is stored at a server that is remote from the target device.
18 . The system of claim 15 wherein the information, for which the target device manages access to, is stored at a target device.
19 . An information management system comprising:
a plurality of rule components and a plurality of abstraction components, wherein a rule component comprises an expression having a variable, and the variable is defined in an abstraction component; a policy server component, accessing the rule and abstraction components; a target device component, coupled through a network connection to the policy server component, the target device comprising a code component, wherein the rule and abstraction components stored remotely from the target device component are stored separately; a deployment mode of operation in which the policy server determines a subset of rule and abstraction components are relevant to the target device component and transfers this set of rule and abstraction components to the target device component via the network connection; and an execution mode of operation in which the code component of the target device manages application usage in the information management system based on the subset of rule and abstraction components.
20 . The system of claim 19 wherein the subset of rule and abstraction components is stored at the target device.Join the waitlist — get patent alerts
Track US2016308914A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.