Patent · US Expired

Distributed administration of access to information

US6785728B1 · kind B1 · utility

215Cited by
13References
15Claims
0Family size

Inventors

Key dates

Filing dateMar 23, 2000
Grant dateAug 31, 2004
Priority date
Expiry dateMar 23, 2020

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L41/28
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A scalable access filter that is used together with others like it in a virtual private network to control access by users at clients in the network to information resources provided by servers in the network. Each access filter use a local copy of an access control data base to determine whether an access request made by a user. Changes made by administrators in the local copies are propagated to all of the other local copies. Each user belongs to one or more user groups and each information resource belongs to one or more information sets. Access is permitted or denied according to of access policies which define access in terms of the user groups and information sets. The rights of administrators are similarly determined by administrative policies. Access is further permitted only if the trust levels of a mode of identification of the user and of the path in the network by which the access is made are sufficient for the sensitivity level of the information resource. If necessary, the access filter automatically encrypts the request with an encryption method whose trust level is sufficient. The first access filter in the path performs the access check and encrypts and authenticat…

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.