IP Library Granted Patent US 12,238,107
Granted Patent B2
US 12,238,107 · App. 18/563,713 · Granted Feb 25, 2025

Access control method, device, apparatus and readable storage medium

Inventors: Xishuang Xing (Jiangsu, CN); Guixiang Song (Jiangsu, CN)
Assignee: SUZHOU METABRAIN INTELLIGENT TECHNOLOGY CO., LTD.
H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,107
App. No.
18/563,713
Granted
Feb 25, 2025
Kind
B2
Abstract

The present application provides an access control method, device, apparatus, and readable storage medium. The method comprises: receiving and parsing an access request, and determining a subject and an object corresponding to the access request; by using a security access strategy, obtaining a first result of whether the subject has permission to access the object, and determining whether a match access control linked list exists; when the access control linked list exists, by using the access control linked list, obtaining a second result whether the subject has permission to access the object; when the second result is obtained, by using the second result, performing control processing on the access request; or when the second result is not obtained, by using the first result, performing control processing on the access request.

Claims (35)

1. An electronic device, comprising:

a processor; and

a memory, configured for storing computer-readable instructions, wherein the computer-readable instructions, when executed by the processor, cause the processor to perform operations of:

receiving and parsing an access request, and determining a subject and an object corresponding to the access request;

by using a security access strategy, obtaining a first result whether the subject has a permission to access the object, and determining whether a match access control linked list exists;

when the access control linked list exists, by using the access control linked list, obtaining a second result whether the subject has a permission to access the object; and

when the second result is obtained, by using the second result, performing control processing on the access request, or when the second result is not obtained, by using the first result, performing control processing on the access request.

2. The electronic device according to claim 1 , wherein when the access control linked list is an attribute access control linked list, the step of, by using the access control linked list, obtaining the second result whether the subject has the permission to access the object, comprising:

obtaining an attribute of the subject and the object; and

querying the second result matching the attribute from the attribute access control linked list.

3. The electronic device according to claim 1 , wherein when the access control linked list is a scenario access control linked list, the step of, by using the access control linked list, obtaining the second result whether the subject has the permission to access the object, comprising:

acquiring scenario information corresponding to the access request; and

querying the second result matching the scenario information from the scenario access control linked list.

4. The electronic device according to claim 1 , wherein the processor is further configured to perform operations of:

receiving a modification request of the access control linked list to obtain modification content; and

by using the modification content, modifying the access control linked list.

5. The electronic device according to claim 1 , wherein the processor is further configured to perform operations of:

receiving a viewing request of the access control linked list; and

outputting the access control linked list.

6. The electronic device according to claim 1 , wherein when the security access strategy is a discretionary access strategy, the step of, by using the security access strategy, obtaining the first result whether the subject has the permission to access the object, comprising:

obtaining an authorization list corresponding to the object; and

searching the subject in the authorization list to obtain the first result whether the subject has the permission to access the object.

7. The electronic device according to claim 1 , wherein when the security access strategy is a mandatory access strategy, the step of, by using the security access strategy, obtaining a first result whether the subject has the permission to access the object, comprises:

obtaining a security tag of the subject and a security tag of the object; and

comparing the security tag of the subject with the security tag of the object to obtain the first result whether the subject has the permission to access the object.

8. The electronic device according to claim 7 , wherein the security tag of the subject is a security level label tag having a partial order relationship.

9. The access control method according to claim 7 , wherein the security tag of the object is a non-level classification tag.

10. The electronic device according to claim 7 , wherein the attributes of the subject are the features of the subject, and the attributes of the object are the features of the object.

11. The electronic device according to claim 1 , wherein the subject is a process or a thread.

12. The electronic device according to claim 1 , wherein the object may be a file, a directory, a Transmission Control Protocol (TCP)/User Datagram Protocol (UDP) port, a shared memory segment, an input/output (I/O) device, a table, a view or a process.

13. A non-transitory computer-readable storage medium storing computer-readable instructions, wherein when the computer-readable instruction is executed by one or more processors, making the one or more processors perform operations of:

receiving and parsing an access request, and determining a subject and an object corresponding to the access request;

by using a security access strategy, obtaining a first result whether the subject has a permission to access the object, and determining whether a match access control linked list exists;

when the access control linked list exists, by using the access control linked list, obtaining a second result whether the subject has a permission to access the object; and

when the second result is obtained, by using the second result, performing control processing on the access request, or when the second result is not obtained, by using the first result, performing control processing on the access request.

Assignments (2)
LICENSE Recorded Jun 30, 2026
From: IEIT SYSTEMS CO., LTD
To: AIVRES SYSTEMS INC.
Reel/Frame 075857/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2023
From: XING, XISHUANG; SONG, GUIXIANG
To: SUZHOU METABRAIN INTELLIGENT TECHNOLOGY CO., LTD.
Reel/Frame 065649/0296 →
Priority Claims (1)
CN 202111168143.X · Oct 8, 2021 · national
Continuity (1)
Related Publication 20240305642A1 · Sep 12, 2024
References Cited (33)
US 6105132A · Fritch · 2000 [cited by examiner]
US 6279111B1 · Jensenworth · 2001 [cited by examiner]
US 8468579B2 · Ellison · 2013 [cited by examiner]
US 8826390B1 · Varda · 2014 [cited by examiner]
US 9253195B2 · Ellison · 2016 [cited by examiner]
US 10044718B2 · Burrows · 2018 [cited by examiner]
US 20110222099A1 · Mori · 2011 [cited by examiner]
US 20110321117A1 · Nestler et al. · 2011 [cited by applicant]
US 20120151554A1 · Tie et al. · 2012 [cited by applicant]
US 20170063862A1 · Guo · 2017 [cited by examiner]
US 20190253427A1 · Kling · 2019 [cited by examiner]
US 20220159004A1 · De Santis · 2022 [cited by examiner]
CN 101729403A · 2010 [cited by applicant]
CN 104094618A · 2014 [cited by applicant]
CN 104484617A · 2015 [cited by applicant]
CN 105959322A · 2016 [cited by applicant]
CN 108614969A · 2018 [cited by applicant]
CN 109460673A · 2019 [cited by applicant]
CN 109992983A · 2019 [cited by applicant]
CN 109995738A · 2019 [cited by applicant]
CN 112733165A · 2021 [cited by applicant]
CN 113612802A · 2021 [cited by applicant]
EP 1084464A1 · 2001 [cited by examiner]
EP 697662B1 · 2001 [cited by examiner]
EP 2973184A1 · 2016 [cited by examiner]
EP 3509004A1 · 2019 [cited by applicant]
EP 3699799A1 · 2020 [cited by examiner]
WO 2020169555A1 · 2020 [cited by applicant]
Zhang, Dao-Yin. “Research on hybrid access control policy and its application.” Computer Engineering and Design 30.15 (2009): 3514-3516. [cited by applicant]
Hwang, JeeHyun, et al. “ACPT: A tool for modeling and verifying access control policies.” 2010 IEEE International Symposium on Policies for Distributed Systems and Networks. IEEE, 2010. [cited by applicant]
Zhen Liu. “Research on access control technology of associated data.” Information Theory and Practice 37.12 (2014): 127-132. [cited by applicant]
Wang, Yu-Ding, et al. “Survey on access control technologies for cloud computing.” Journal of Software 26.5 (2015): 1129-1150. [cited by applicant]
Fang, Liang, et al. “A survey of key technologies in attribute-based access control scheme.” Chinese Journal of Computers 40.7 (2017): 1680-1698. [cited by applicant]