IP Library Granted Patent US 8,397,056
Granted Patent B1
US 8,397,056 · App. 12/763,582 · Granted Mar 12, 2013

Method and apparatus to apply an attribute based dynamic policy for mashup resources

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,397,056
App. No.
12/763,582
Granted
Mar 12, 2013
Kind
B1
Abstract

A computer system includes a mashup section that provides a mashup that performs an action on a resource. An attribute identification section identifies an attribute of a user running the mashup. An access control section provides access control. The mashup is associated to a permission artifact. The permission artifact specifies a principal and whether to permit the principal to take the action on the resource. The access control is triggered only when the mashup attempts to perform the action on the resource, and checks whether the attribute of the user running the mashup is predefined as belonging to the principal specified in the permission artifact associated to the mashup, and then permits the action on the resource only when the attribute belongs to the principal. Plural users with the same attribute belong to the principal when the same attribute is defined as belonging to the principal.

Claims (51)

1. A computer system, comprising:

a processor configured with:

a mashup section that provides a mashup that performs an action on a resource included in the mashup;

an attribute identification section that identifies an attribute of a user running the mashup to perform the action on the resource; and

an access control section providing an access control,

the mashup being associated to a permission artifact, the permission artifact specifying a principal and whether one of to permit and to prohibit the principal to take the action on the resource,

wherein

the access control is triggered only when the mashup attempts to perform the action on the resource,

the access control (i) checks whether the attribute of the user running the mashup to perform the action is predefined as belonging to the principal specified in the permission artifact associated to the mashup, and then (ii) performs the one of to permit and to prohibit the action on the resource only when the attribute belongs to the principal,

plural users that have a same single attribute belong to the principal when the same single attribute is defined as belonging to the principal, and

the permission artifact further specifies: (i) the resource used by the mashup and (ii) the action on the resource for which permission is needed.

2. The computer system of claim 1 , further comprising:

changing whether the single attribute belongs to the principal, thereby changing whether one of to permit and to prohibit the action on the resource for all of the plural users that have the same single attribute.

3. The computer system of claim 1 , the access control being separate from an authentication and an authorization passed through from the resource included in the mashup.

4. The computer system of claim 1 , the mashup further comprising an extensible access control markup language (XACML) attribute-based artifact, the running of the mashup with the XACML attribute-based artifact results in a second access control.

5. The computer system of claim 1 , further comprising

a user interface configured to specify, in the permission artifact, the principal, the action, the resource, and that the principal is one of permitted and prohibited from taking the action on the resource.

6. The computer system of claim 1 , further comprising associating the user as an owner of the mashup, only the owner of the mashup being allowed to set and update the permission artifact for the mashup.

7. A computer-implemented method for providing a mashup, comprising:

providing, in a processor, a mashup that performs an action on a resource included in the mashup;

identifying an attribute of a user running the mashup to perform the action on the resource; and

providing an access control,

the mashup being associated to a permission artifact, the permission artifact specifying a principal and whether one of to permit and to prohibit the principal to take the action on the resource,

wherein

the access control is triggered only when the mashup attempts to perform the action on the resource,

the access control (i) checks whether the attribute of the user running the mashup to perform the action is predefined as belonging to the principal specified in the permission artifact associated to the mashup, and then (ii) performs the one of to permit and to prohibit the action on the

resource only when the attribute belongs to the principal, plural users that have a same single attribute belong to the principal when the same single attribute is defined as belonging to the principal, and

the permission artifact further specifies: (i) the resource used by the mashup, and (ii) the action on the resource for which permission is needed.

8. The method of claim 7 , further comprising:

changing whether the single attribute belongs to the principal, thereby changing whether one of to permit and to prohibit the action on the resource for all of the plural users that have the same single attribute.

9. The method of claim 7 , the access control being separate from an authentication and an authorization passed through from the resource included in the mashup.

10. The method of claim 7 , the mashup further comprising an extensible access control markup language (XACML) attribute-based artifact, the running of the mashup with the XACML attribute-based artifact results in a second access control.

11. The method of claim 7 , further comprising

specifying, via a user interface, in the permission artifact, the principal, the action, the resource, and that the principal is one of permitted and prohibited from taking the action on the resource.

12. The method of claim 7 , further comprising associating the user as an owner of the mashup, only the owner of the mashup being allowed to set and update the permission artifact for the mashup.

13. A non-transitory computer-readable medium comprising instructions for execution by a computer, the instructions including a computer-implemented method for providing a mashup, the instructions for implementing:

providing a mashup that performs an action on a resource included in the mashup;

identifying an attribute of a user running the mashup to perform the action on the resource; and

providing an access control,

the mashup being associated to a permission artifact, the permission artifact specifying a principal and whether one of to permit and to prohibit the principal to take the action on the resource,

wherein

the access control is triggered only when the mashup attempts to perform the action on the resource,

the access control (i) checks whether the attribute of the user running the mashup to perform the action is predefined as belonging to the principal specified in the permission artifact associated to the mashup, and then (ii) performs the one of to permit and to prohibit the action on the resource only when the attribute belongs to the principal,

plural users that have a same single attribute belong to the principal when the same single attribute is defined as belonging to the principal, and

the permission artifact further specifies: (i) the resource used by the mashup, and (ii) the action on the resource for which permission is needed.

14. The computer-readable medium of claim 13 , further comprising:

changing whether the single attribute belongs to the principal, thereby changing whether one of to permit and to prohibit the action on the resource for all of the plural users that have the same single attribute.

15. The computer-readable medium of claim 13 , the mashup further comprising an extensible access control markup language (XACML) attribute-based artifact, the running of the mashup with the XACML attribute-based artifact results in a second access control.

16. The computer-readable medium of claim 13 , further comprising

specifying, via a user interface, in the permission artifact, the principal, the action, the resource, and that the principal is one of permitted and prohibited from taking the action on the resource.

17. The computer-readable medium of claim 13 , further comprising associating the user as an owner of the mashup, only the owner of the mashup being allowed to set and update the permission artifact for the mashup.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2024
From: SOFTWARE AG, LLC
To: ARIS USA, INC.
Reel/Frame 069603/0614 →
ENTITY CONVERSION Recorded Dec 16, 2024
From: SOFTWARE AG, INC.
To: SAG 1, LLC
Reel/Frame 069712/0001 →
CHANGE OF NAME Recorded Nov 29, 2024
From: SOFTWARE AG, INC.
To: SAG 1, LLC
Reel/Frame 069712/0881 →
CHANGE OF NAME Recorded Sep 13, 2024
From: SAG 1, LLC
To: SOFTWARE AG, LLC
Reel/Frame 069021/0280 →
MERGER Recorded Sep 13, 2024
From: SOFTWARE AG USA, INC.
To: SOFTWARE AG, INC.
Reel/Frame 068586/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2015
From: JACKBE LLC
To: SOFTWARE AG USA, INC.
Reel/Frame 035757/0551 →
CHANGE OF NAME Recorded May 21, 2015
From: JACKBE CORPORATION
To: JACKBE LLC
Reel/Frame 035748/0972 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2010
From: MALKS, DANIEL; POLENUR, ALEKSEY; THOPE, KARTHIC
To: JACKBE CORPORATION
Reel/Frame 024598/0888 →