IP Library Patent Application 11809856
Patent Application
App. No. 11/809,856

Distributed knowledge access control

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/809,856
Abstract

Techniques for distributed knowledge access control are disclosed herein. These techniques may enable access control information to be provided in the form of a statement that includes an assertion and a construct that targets the assertion to one or more intended entities. By targeting the statement to intended entities, the construct may help protect resources from unauthorized use and may also help protect the issuer of the statement from accountability resulting from misuse of the statement.

Claims (35)

1 . A computer-readable medium having stored thereon computer-executable instructions for controlling, by an entity, access to a resource based on information by performing the following steps:

determining a known portion the information, the known portion comprising an assertion issued by the entity itself or an assertion issued by another entity and targeted to the entity; and

determining whether to grant access to the resource based on the known portion of the information.

2 . The computer-readable medium of claim 1 , wherein the known portion comprises all of the information.

3 . The computer-readable medium of claim 1 , wherein the known portion comprises less than all of the information.

4 . The computer-readable medium of claim 1 , wherein the computer-executable instructions are further for performing the steps of:

applying a trust policy to determine whether another entity that issued the known portion of the information is a trusted entity;

if the other entity is not a trusted entity, disregarding the known portion of the information; and

if the other entity is a trusted entity, determining whether to grant access to the resource based on the known portion of the information.

5 . The computer-readable medium of claim 1 , wherein the known portion of the information further comprises information that logically follows from other known information.

6 . The computer-readable medium of claim 1 , wherein the computer-executable instructions are further for performing the steps of:

identifying an unknown portion of the information; and

disregarding the unknown portion of the information.

7 . The computer-readable medium of claim 1 , wherein the known portion comprises a statement having the assertion and a construct that targets the assertion to the entity.

8 . The computer-readable medium of claim 7 , wherein the construct protects an issuer of the statement from accountability if the statement is used by an entity that is not identified by the construct.

9 . The computer-readable medium of claim 1 , wherein the statement is targeted exclusively to the entity.

10 . The computer-readable medium of claim 1 , wherein the statement is targeted to the entity and to at least one other entity.

11 . A computer-readable medium having stored thereon computer-executable instructions for performing the following steps:

generating an assertion;

identifying an intended entity to which the assertion is targeted; and

generating a statement comprising the assertion and a construct that targets the assertion to the intended entity.

12 . The computer-readable medium of claim 11 , wherein the construct targets the statement exclusively to the intended entity.

13 . The computer-readable medium of claim 11 , wherein the construct targets the statement to the intended entity and to at least one other intended entity.

14 . The computer-readable medium of claim 11 , wherein the construct protects an issuer of the statement from accountability if the statement is used by a non-intended entity.

15 . The computer-readable medium of claim 11 , wherein the assertion grants authority over a resource.

16 . The computer-readable medium of claim 11 , wherein the computer-executable instructions are further for performing the step of sending the statement to the intended entity.

17 . A method for controlling, by an entity, access to a resource based on information, the method comprising:

determining a known portion of the information, the known portion comprising an assertion issued by the entity itself or an assertion issued by another entity and targeted to the entity; and

determining whether to grant access to the resource based on the known portion of the information.

18 . The method of claim 17 , further comprising:

applying a trust policy to determine whether another entity that issued the known portion of the information is a trusted entity;

if the other entity is not a trusted entity, disregarding the known portion of the information; and

if the other entity is a trusted entity, determining whether to grant access to the resource based on the known portion of the information.

19 . The method of claim 17 , wherein the known portion of the information further comprises information that logically follows from other known information.

20 . The method of claim 17 , wherein the known portion comprises a statement having the assertion and a construct that targets the assertion to the entity.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034766/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2008
From: GUREVICH, YURI; PARAMASIVAM, MUTHUKRISHNAN; NEEMAN, ITAY
To: MICROSOFT CORPORATION
Reel/Frame 020942/0656 →