IP Library Granted Patent US 7,836,510
Granted Patent B1
US 7,836,510 · App. 10/836,991 · Granted Nov 16, 2010

Fine-grained attribute access control

Assignee: Oracle America, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,836,510
App. No.
10/836,991
Granted
Nov 16, 2010
Kind
B1
Abstract

A mechanism is disclosed for enabling an attribute provider service (APS), which provides access to one or more attributes, to control access to the attributes at the attribute level. In one implementation, a request is received, which specifies a particular attribute that is desired to be accessed from an attribute repository. In response to this request, a policy that applies to the particular attribute is accessed. The policy is then processed to determine whether access to the particular attribute is to be allowed or denied. With the above mechanism, it is possible to control access to attributes at the attribute level rather than at the service level. Because access control is exercised at such a low level, an administrator can exercise much tighter and precise control over how attributes provided by an APS are accessed.

Claims (27)

1. An attribute provider service (APS), comprising:

a processor;

a request processing mechanism (RPM), when executed by the processor, configured to:

receive a request for an attribute from a consumer,

forward the request to an attribute provider mechanism (APM) for processing,

receive, from the APM, a response to the request, and

provide the response to the consumer;

the APM, when executed by the processor, configured to:

receive the request from the RPM,

invoke, in response to the request, a policy evaluator to determine whether the consumer is allowed to access the attribute,

receive a response from the policy evaluator indicating whether access to the attribute by the consumer is allowed,

obtain an attribute value corresponding to the attribute from an attribute repository based on the response from the policy evaluator, and

provide the response to the request to the RPM, wherein the response comprises the attribute value when the response from the policy evaluator indicates that access to the attribute by the consumer is allowed; and

the policy evaluator, when executed by the processor, configured to:

identify an attribute level policy corresponding to the attribute, wherein the attribute level policy comprises at least one condition used to determine whether access to the attribute is allowed by the consumer wherein the attribute level policy is associated with application criteria, and wherein the application criteria comprises an attribute specification specifying the attribute, a subject parameter which identifies the consumer, a resource parameter which specifies a service that provides the attribute, and an action parameter which specifies an action that the consumer is allowed to perform on the attribute value, and

determine, using the attribute level policy, whether to allow access to the attribute by the consumer.

2. The APS of claim 1 , wherein the policy evaluator, when executed by the processor, is further configured to evaluate the at least one condition to determine whether it is satisfied to determine whether to allow access to the attribute.

3. The APS of claim 1 , wherein the request specifies a subject and the attribute, and wherein the policy evaluator, when executed by the processor, is configured to identify the attribute level policy that corresponds to the subject and the attribute.

4. The APS of claim 1 , wherein the request specifies a resource and the attribute, and wherein the policy evaluator, when executed by the processor, is configured to identify the attribute level policy that corresponds to the resource and the attribute.

5. The APS of claim 1 , wherein the request specifies an action to be performed on the attribute, and wherein the policy evaluator, when executed by the processor, is further configured to identify the attribute level policy that applies to the action and the attribute.

6. The APS of claim 1 , wherein the policy evaluator, when executed by the processor, is further configured, when determining whether to allow access to the attribute, to:

determining, based upon the attribute level policy, that access to the attribute is allowed when correct user input is received from the user;

invoking an interaction engine in the APS to request input from the consumer;

receiving, from the interaction engine, the input from the consumer; and

determining, based at least in part on the input from the consumer, whether to allow the consumer to access the attribute.

7. The APS of claim 1 , wherein the action parameter specifies at least one selected from a group consisting of get and post.

8. The APS of claim 1 , wherein the subject parameter further identifies at least one selected from a group consisting of a role, a group, an organization, which may access the attribute.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded Dec 16, 2015
From: ORACLE USA, INC.; SUN MICROSYSTEMS, INC.; ORACLE AMERICA, INC.
To: ORACLE AMERICA, INC.
Reel/Frame 037306/0556 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2004
From: ANGAL, RAJEEV; CHENG, QINGWEN; HSU, HENG-MING; SIMHACHALAM, MALLA; ARUMUGAM, DILLI DORAI MINNAL
To: SUN MICROSYSTEMS, INC.
Reel/Frame 015295/0468 →