Patent · US Expired

Evidence-based security policy manager

US7051366B1 · kind B1 · utility

32Cited by
5References
42Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 21, 2000
Grant dateMay 23, 2006
Priority date
Expiry dateSep 24, 2022

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2141
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

An evidence-based policy manager generates a permission grant set for a code assembly received from a resource location. The policy manager executes in a computer system (e.g., a Web client or server) in combination with the verification module and class loader of the run-time environment. The permission grant set generated for a code assembly is applied in the run-time call stack to help the system determine whether a given system operation by the code assembly is authorized. Both code assemblies and evidence may be received from a local origin or from a remote resource location via a network (e.g., the Internet). The policy manager may comprise execution modules for parsing a security policy specification, generating a one or more code hierarchies, evaluating membership of the received code assembly in one or more code groups, and generating a permission grant set based upon this membership evaluation.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.