IP Library › Granted Patent US 8,631,476
Granted Patent B2
US 8,631,476 · App. 11/095,301 · Granted Jan 14, 2014

Data processing system including explicit and generic grants of action authorization

Inventor: Christoph H. Hofmann (Wiesloch, DE)
Assignee: SAP AG
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,631,476
App. No.
11/095,301
Granted
Jan 14, 2014
Kind
B2
Abstract

A method of determining whether to authorize a user of a computer system to perform an action in the computer system is described. Besides the explicit authorization grants, a new, more secure semantics is defined where only unassigned users or actions are granted generically. For example, if an access control list for an action is not empty, a user may be authorized to perform the action only if the user is a member of the access control list for the action. If the access control list for the action is empty, the user may be authorized to perform the action only if the user is not a member of any access control list of a group of access control lists.

Claims (26)

1. A method of using access control lists (ACLs) and an authorization model to determine whether to authorize a user to perform an action requested by the user, the method comprising:

storing a plurality of ACLs in a storage device, each individual ACL of the plurality of ACLs being dedicated to a respective one of a plurality of actions and having zero or more users that are assigned to the individual ACL and are explicitly authorized to perform the action to which the individual ACL is dedicated;

receiving, by a processor that is coupled to the storage device and coupled to a communication device, a request from a user to perform one of the plurality of actions;

if there are not zero users assigned to the ACL dedicated to the one of the plurality of actions, authorizing, by the processor, the user to perform the one of the plurality of actions only if the user is assigned to the ACL dedicated to the one of the plurality of actions; and

if there are zero users assigned to the ACL dedicated to the one of the plurality of actions, authorizing, by the processor, the user to perform the one of the plurality of actions only if the user is assigned to none of the plurality of ACLs each individual ACL of which is dedicated to a respective one of a plurality of actions and has zero or more users that are assigned to the individual ACL and explicitly authorized to perform the action to which the individual ACL is dedicated.

2. The method of claim 1 , wherein the user is a business-to-business sender and the one of the plurality of actions is sending a message to an application integration software component.

3. The method of claim 1 , wherein the one of the plurality of actions is accessing an object.

4. The method of claim 1 , wherein it is determined whether the user is assigned to none of the plurality of ACLs by searching for the user among all ACLs for an atomic grant relation.

5. A non-transitory computer readable medium having instructions stored thereon, the instructions executable by a machine to result in a method comprising:

storing a plurality of ACLs in a storage device, each individual ACL of the plurality of ACLs being dedicated to a respective one of a plurality of actions and having zero or more users that are assigned to the individual ACL and are explicitly authorized to perform the action to which the individual ACL is dedicated;

receiving a request from a user to perform one of the plurality of actions;

if there are not zero users assigned to the ACL dedicated to the one of the plurality of actions, authorizing the user to perform the one of the plurality of actions only if the user is assigned to the ACL dedicated to the one of the plurality of actions; and

if there are zero users assigned to the ACL dedicated to the one of the plurality of actions, authorizing the user to perform the one of the plurality of actions only if the user is assigned to none of the plurality of ACLs each individual ACL of which is dedicated to a respective one of a plurality of actions and has zero or more users that are assigned to the individual ACL and explicitly authorized to perform the action to which the individual ACL is dedicated.

6. The medium of claim 5 , wherein the user is a business-to-business sender and the one of the plurality of actions is sending a message to an application integration software component.

7. The medium of claim 5 , wherein the one of the plurality of actions is accessing an object.

8. The medium of claim 5 , wherein it is determined whether the user is assigned to none of the plurality of ACLs by searching for the user among all ACLs for an atomic grant relation.

9. Apparatus comprising:

a memory; and

a processor that is in communication with the memory and to:

store a plurality of ACLs in a storage device, each individual ACL of the plurality of ACLs being dedicated to a respective one of a plurality of actions and having zero or more users that are assigned to the individual ACL and are explicitly authorized to perform the action to which the individual ACL is dedicated;

receive a request from a user to perform one of the plurality of actions;

if there are not zero users assigned to the ACL dedicated to the one of the plurality of actions, authorize the user to perform the one of the plurality of actions only if the user is assigned to the ACL dedicated to the one of the plurality of actions; and

if there are zero users assigned to the ACL dedicated to the one of the plurality of actions, authorize the user to perform the one of the plurality of actions only if the user is assigned to none of the plurality of ACLs each individual ACL of which is dedicated to a respective one of a plurality of actions and has zero or more users that are assigned to the individual ACL and explicitly authorized to perform the action to which the individual ACL is dedicated.

10. The apparatus of claim 9 , wherein the user is a business-to-business sender and the one of the plurality of actions is sending a message to an application integration software component.

11. The apparatus of claim 9 , wherein the one of the plurality of actions is accessing an object.

12. The apparatus of claim 9 , wherein it is determined whether the user is assigned to none of the plurality of ACLs by searching for the user among all ACLs for an atomic grant relation.

Assignments (2)
CHANGE OF NAME Recorded Aug 26, 2014
From: SAP AG
To: SAP SE
Reel/Frame 033625/0334 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2005
From: HOFMANN, CHRISTOPH H.
To: SAP AKTIENGESELLSCHAFT
Reel/Frame 015915/0777 →
Continuity (1)
Related Publication 20060230281A1 · Oct 12, 2006