 |
 |
|
|
|
|
Title: |
US6044373:
Object-oriented access control method and system for military and commercial file systems
[ Derwent Title ]

|
Country: |
US United States of America

|
| |
Inventor: |
Gladney, Henry Martin; Saratoga, CA
Reimer, James Allen; Morgan Hill, CA

|
Assignee: |
International Business Machines Corporation, Armonk, NY
other patents from INTERNATIONAL BUSINESS MACHINES CORPORATION (280070) (approx. 44,393)
News, Profiles, Stocks and More about this company

|
Published / Filed: |
2000-03-28
/ 1997-09-29

|
Application Number: |
US1997000939682

|
IPC Code: |
Advanced:
G06F 17/30;
Core:
more...
IPC-7:
G06F 17/30;

|
ECLA Code: |
G06F17/30B;

|
U.S. Class: |
Current:
707/010;
707/009;
707/E17.005;
713/167;
Original:
707/010;
707/009;
380/004;
380/024;

|
Field of Search: |
707/003,203,206,9,10
709/203
380/004,24

|
Priority Number: |
| 1997-09-29 |
US1997000939682 |

|
Abstract: |
A method and system are provided for controlling a client's access to a protected element, in which the protected element is contained in a protected resource which includes a data manager. The invention provides efficient access control for existing data elements while requiring only minimal changes to existing software components. In response to a request for access to the protected element the data manager sends an authorization checking request to a protecting resource. The protecting resource, which is in a distributed arrangement with the protected resource, determines, based on an access control element which can be associated with one or more protected elements, whether the client has permission to be provided the requested access to the protected element. It then sends an access control message (e.g. YES/NO) to the data manager based on the determination, and optionally send explanatory information if access is denied. Access to the protected element is provided or denied based on that message. The protected element can be a file, a data block within a database, an object, method or object-method in an object-oriented system.

|
Attorney, Agent or Firm: |
Sughrue, Mion, Zinn, Macpeak & Seas, PLLC ;

|
Primary / Asst. Examiners: |
Amsbury, Wayne; Rones, Charles L.

|
Maintenance Status: |
E2 Expired Check current status

|
INPADOC Legal Status: |
Show legal status actions

|
Family: |
None

|
First Claim:
Show all 31 claims |
What is claimed is:
1. A computer program product including a computer-readable medium, comprising:
- a computer-readable protected resource program code, including a data manager and a protected resource element;
- a computer-readable protecting resource program code including a protecting resource manager and an access control element; and
- a computer-readable client program code, sending a request to the protected resource program code for access to the protected element,
- wherein in response to the request from said client program code said data manager identifies said protecting resource manager based on the request for access to the protected element and sends a request to said protecting resource program code, and in response to said request from said data manager said protecting resource manager determines based on the access control element whether to grant access to said protected element,
- wherein said protected resource program code and said protecting resource program code are to be operated in computing devices arranged in a distributed manner.

|
Background / Summary: |
Show background / summary

|
Drawing Descriptions: |
Show drawing descriptions

|
Description: |
Show description

|
Forward References: |
Show 26 U.S. patent(s) that reference this one

|
 |
 |
|
|
|
|
Foreign References: |
None

|
Other Abstract Info: |
DERABS G2000-270443
DERABS G2000-270443

|
Other References: |
ISO/IEC 10181-3, Information Technology-Open Systems Interconnection-Security Frameworks For Open Systems: Access Control Framework (1996), pp. 1-36.
H.M. Gladney, Access Control for Large Collections, ACM Transactions on Information Systems (Apr. 1997), pp. 154-194.
(41 pages)
Cited by 12 patents
[ISI abstract]
H.M. Gladney, et al., External Design of a Document Storage Subsystem, IBM Research Report RJ 8267 (Aug. 1, 1991), pp. 1-153.
H.M. Gladney, A Storage Subsystem for Image and Records Management, IBM Systems Journal, vol. 32, No. 3 (1993), pp. 512-540.
(29 pages)
Cited by 4 patents
[ISI abstract]
S. Hitchcock et al., Citation Linking: Improving Access to Online Journals, Proc. 2nd ACM Int'l. Conf. on Digital Libraries, (Jul. 1997), pp. 115-122.

|


|
Nominate this for the Gallery...

|
|