Extensible security system and method for controlling access to objects in a computing environment
US6412070B1 · kind B1 · utility
Assignee
Inventors
Key dates
| Filing date | Sep 21, 1998 |
| Grant date | Jun 25, 2002 |
| Priority date | — |
| Expiry date | Sep 21, 2018 |
Classification
- Technology area (CPC Y)Emerging Cross-Sectional Technologies
- CPC primaryY10S707/99939
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
A method and computing system for extending access control of system objects in a computing environment beyond traditional rights such as read, write, create and delete. According to the invention, a system administrator or user application is able to create control rights that are unique to the type of object. Rights can be created that do not relate to any specific property of the object, but rather define how a user may control the object. A novel object, referred to as a control access data structure, is defined for each unique control right and associates the control right with one or more objects of the computing environment. In order to grant the right to a trusted user, an improved access control entry (ACE) is defined which holds a unique identifier of the trusted user and a unique identifier of the control access data structure.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.