IP Library Granted Patent US 6,928,427
Granted Patent B2
US 6,928,427 · App. 10/094,509 · Granted Aug 9, 2005

Efficient computational techniques for authorization control

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,928,427
App. No.
10/094,509
Granted
Aug 9, 2005
Kind
B2
Abstract

In an authorization system, access is defined by rules, roles and active rules. These definitions are preprocessed to form a bit array for each of a plurality of roles representing the rules that apply to that role. Once a bit array is calculated or generated for a given user based on that user's roles, the user bit array can be cached so that it need not be regenerated for each time the user requests access to resources. The rules used can either be role-based rules or active rules.

Claims (8)

1. A computer implemented method of processing authorization requests, wherein an authorization request received from a user system is a request to allow a user of that user system to access to a resource to perform an action on that resource, the method comprising:

prior to receipt of the authorization request from the user system, generating a plurality of role bit arrays for a plurality of roles, wherein a role bit array indicates which actions are allowed with which resources for that role;

upon receipt of the authorization request, determining if a user bit array associated with that user exists, wherein a user bit array is a bit array indicating, for the user associated with the user bit array, which actions are allowed with which resources;

if the user bit array does not exist, generating a user bit array from at least one role bit arrays for roles associated with the user;

if the user bit array is generated, at least temporarily storing the generated user bit array for use with subsequent requests from that user;

applying rules to at least one bit of the user bit array where the rules are not entirely encoded in the user bit array or the role bit arrays used to determine the user bit array;

identifying an authorization flag at an index in the user bit array corresponding to the requested resource and the requested action;

responding to the authorization request by either allowing the access or denying the access, based on the identified authorization flag.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2012
From: ARCOT SYSTEMS, INC.
To: COMPUTER ASSOCIATES THINK, INC.
Reel/Frame 028943/0020 →
MERGER Recorded Sep 12, 2012
From: COMPUTER ASSOCIATES THINK, INC.
To: CA, INC.
Reel/Frame 028943/0463 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2011
From: MVC CAPITAL, INC. (FORMERLY KNOWN AS MEVC DRAPER FISHER JURVETSON FUND I, INC.)
To: ARCOT SYSTEMS, INC.
Reel/Frame 025894/0720 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2011
From: SAND HILL VENTURE DEBT III, L.L.C.
To: ARCOT SYSTEMS, INC.
Reel/Frame 025894/0895 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2011
From: HORIZON TECHNOLOGY FUNDING COMPANY V L.L.C.
To: ARCOT SYSTEMS, INC.
Reel/Frame 025895/0870 →
RELEASE OF SECURITY INTEREST Recorded Aug 2, 2010
From: SAND HILL VENTURE DEBT III, LLC
To: ARCOT SYSTEMS, INC.
Reel/Frame 024767/0935 →
RELEASE OF SECURITY INTEREST Recorded Aug 2, 2010
From: MVC CAPITAL, INC. (F/K/A MEVC DRAPER FISHER JURVETSON FUND I, INC.)
To: ARCOT SYSTEMS, INC.
Reel/Frame 024776/0159 →
SECURITY AGREEMENT Recorded Aug 21, 2006
From: ARCOT SYSTEMS, INC.
To: SAND HILL VENTURE DEBT III, LLC
Reel/Frame 018148/0286 →
SECURITY INTEREST Recorded Jan 23, 2003
From: ARCOT SYSTEMS, INC.
To: MEVC DRAPER FISHER JURVETSON FUND I, INC.
Reel/Frame 013691/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2002
From: RAJASEKARAN, SANGUTHEVAR; GOPALAKRISHNA, RAJENDRA A.
To: ARCOT SYSTEMS, INC.
Reel/Frame 012994/0875 →