IP Library › Granted Patent US 8,566,906
Granted Patent B2
US 8,566,906 · App. 13/077,881 · Granted Oct 22, 2013

Access control in data processing systems

Inventors: Thomas R. Gross (Rueschlikon, CH); Guenter Karjoth (Rueschlikon, CH)
Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,566,906
App. No.
13/077,881
Granted
Oct 22, 2013
Kind
B2
Abstract

A policy data structure defines predetermined authorizations, each relating to authorization of at least one user to access at least one resource as well as to dynamic access requests. Each dynamic access request indicates a condition to be satisfied by a respective set of attributes associated with a user request to access a resource and for the request to be granted in absence of an authorization determinative of the request. If the structure does not define an authorization for a request to access a resource, it is determined whether the structure defines a dynamic access requirement determinative for the request, and if so, whether to grant the request in accordance with the respective set of attributes associated with the request. For at least one request, after determining whether to grant the request, a dynamic authorization relating to authorization to access the resource within the request is added to the structure.

Claims (42)

1. A storage device storing computer program code when executed by a processor, the computer program code comprising:

a first computer program part to determine whether a policy data structure defines an authorization for a request to access a resource, the policy data structure defining a plurality of predetermined authorizations, each predetermined authorization relating to authorization of at least one user to access at least one resource, each predetermined authorization further relating to a plurality of dynamic access requests, each dynamic access request indicating a condition to be satisfied by a respective set of attributes associated with a user request to access a resource and for the request to be granted in absence of an authorization determinative of the request;

a second computer program part to, in response to determining that the policy data structure defines an authorization for the request to access the resource, apply the authorization to determine whether to grant the request;

a third computer program part to, in response to determining that the policy data structure does not define an authorization for the request to access the resource,

determine whether the policy data structure defines a dynamic access requirement determinative for the request;

in response to determining that the policy data structure defines a dynamic access requirement determinative for the request,

determine whether to grant the request in accordance with the respective set of attributes associated with the request; and,

a fourth computer program part to, for at least one user request, after determining whether to grant the request, add a dynamic authorization relating to authorization to access the resource within the request to the policy data structure,

wherein where the policy data structure defines the authorization for the request, no determination as to whether the policy data structure defines the dynamic access requirement for the request is made,

wherein the computer program code further comprises a fifth computer program part to, upon the dynamic authorization having been added to the policy data structure:

define an expiration time for the dynamic authorization in the policy data structure in accordance with a temporal validity limitation for the respective set of attributes associated with the request; and

only apply the dynamic authorization to a subsequent request up to the expiration time.

2. An apparatus comprising:

a memory to store an access control policy data structure defining predetermined authorizations, each predetermined authorization relating to authorization of at least one user to access at least one resource, each predetermined authorization further relating to a plurality of dynamic access requests, each dynamic access request indicating a condition to be satisfied by a respective set of attributes associated with a user request to access a resource and for the request to be granted in absence of an authorization determinative of the request; and,

control logic to respond to a request to access a resource by:

determining whether the policy data structure defines an authorization for the request;

in response to determining that the policy data structure defines an authorization for the request to access the resource, applying the authorization to determine whether to grant the request;

in response to determining that the policy data structure does not define an authorization for the request to access the resource,

determining whether the policy data structure defines a dynamic access requirement determinative for the request;

in response to determining that the policy data structure defines a dynamic access requirement determinative for the request,

determining whether to grant the request in accordance with the respective set of attributes associated with the request;

for at least one user request, after determining whether to grant the request, adding a dynamic authorization relating to authorization to access the resource within the request to the policy data structure,

wherein where the policy data structure defines the authorization for the request, no determination as to whether the policy data structure defines the dynamic access requirement for the request is made,

wherein, upon the dynamic authorization having been added to the policy data structure, the control logic is further configured to:

define an expiration time for the dynamic authorization in the policy data structure in accordance with a temporal validity limitation for the respective set of attributes associated with the request; and

only apply the dynamic authorization to a subsequent request up to the expiration time.

3. A system comprising:

a plurality of resources;

an apparatus to control access to the resources, the apparatus comprising:

a memory to store an access control policy data structure defining predetermined authorizations, each predetermined authorization relating to authorization of at least one user to access at least one resource, each predetermined authorization further relating to a plurality of dynamic access requests, each dynamic access request indicating a condition to be satisfied by a respective set of attributes associated with a user request to access a resource and for the request to be granted in absence of an authorization determinative of the request; and,

control logic to respond to a request to access a resource by:

determining whether the policy data structure defines an authorization for the request;

in response to determining that the policy data structure defines an authorization for the request to access the resource, applying the authorization to determine whether to grant the request;

in response to determining that the policy data structure does not define an authorization for the request to access the resource,

determining whether the policy data structure defines a dynamic access requirement determinative for the request;

in response to determining that the policy data structure defines a dynamic access requirement determinative for the request,

 determining whether to grant the request in accordance with the respective set of attributes associated with the request;

for at least one user request, after determining whether to grant the request, adding a dynamic authorization relating to authorization to access the resource within the request to the policy data structure,

wherein where the policy data structure defines the authorization for the request, no determination as to whether the policy data structure defines the dynamic access requirement for the request is made,

wherein, upon the dynamic authorization having been added to the policy data structure, the control logic is further to:

define an expiration time for the dynamic authorization in the policy data structure in accordance with a temporal validity limitation for the respective set of attributes associated with the request; and

only apply the dynamic authorization to a subsequent request up to the expiration time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2011
From: KARJOTH, GUENTER; GROSS, THOMAS R.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 026458/0571 →
Priority Claims (1)
EP 10158633 · Mar 31, 2010 · regional
Continuity (1)
Related Publication 20110247046A1 · Oct 6, 2011