IP Library Granted Patent US 8,977,845
Granted Patent B2
US 8,977,845 · App. 11/734,319 · Granted Mar 10, 2015

Methods and apparatus for access control in service-oriented computing environments

Inventors: Arun Kwangil Iyengar (Yorktown Heights, NY); Thomas A. Mikalsen (Cold Spring, NY); Isabelle Marie Rouvellou (New York, NY); Mudhakar Srivalso (Atlanta, GA); Jian Yin (Bronx, NY)
Assignee: International Business Machines Corporation
H04L63/102G06F21/31G06F2221/2105G06F2221/2119
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,977,845
App. No.
11/734,319
Granted
Mar 10, 2015
Kind
B2
Abstract

Improved access control techniques for use in a service-oriented computing environment are disclosed. For example, one method for authenticating a client in a service-oriented environment, wherein the service-oriented environment includes a plurality of services, includes the following steps. At least one service of the plurality of services is invoked. State information is associated with the at least one service invoked. The state information is used to authenticate a client with at least one service. Further, a method for access control in a service-oriented environment, wherein the service-oriented environment includes a plurality of services, includes the following steps. A rule specification language is provided. At least one rule is specified using the rule specification language. A verification is performed to determine whether or not the client satisfies the at least one rule. The client is granted access to a service when the client satisfies the at least one rule.

Claims (45)

1. In a service-oriented environment comprising a plurality of services, a method for authenticating a client, the method comprising the steps:

a client invoking a composite service, the composite service comprising a plurality of different services and different principles, wherein the principles are entities that invoke the different services of the composite service;

maintaining state information comprising an identify of at least one service that is associated with the composite service; and

using the state information to enforce access control on invocation of the at least one service,

wherein at least a portion of the state information is stored in the form of a composite principle, wherein the composite principle comprises a temporally ordered sequence of the different principles that are responsible for nested invocation of the different services associated with the composite service, and

wherein using the state information to enforce access control on invocation of the at least one service comprises:

obtaining one or more rules that are used to determine if the client can invoke the composite service, wherein the one or more rules define access control policies which are specified using a pure-past linear temporal logic based specification language having past time temporal operators, and which support a temporal predicate on the composite principle; and

processing the one or more rules against the composite principle to verify whether invocation of the composite service by the client satisfies the one or more rules.

2. The method of claim 1 , wherein at least a portion of the state information is stored in the form of an audit/logging service.

3. The method of claim 1 , wherein the access control policies are stored in a policy database.

4. The method of claim 1 , wherein the client is authenticated based on an access control decision.

5. The method of claim 4 , wherein the access control decision is made in accordance with at least one temporal predicate on the composite principle.

6. The method of claim 4 , wherein the access control decision is made in accordance with at least one scoped access control rule.

7. The method of claim 4 , wherein the access control decision is made in accordance with at least one role translation.

8. The method of claim 4 , wherein the access control decision is made in accordance with at least one scoped role.

9. The method of claim 4 , wherein the access control decision is made in accordance with at least one Boolean predicate.

10. The method of claim 4 , wherein the access control decision is made in accordance with at least one constraint.

11. The method of claim 10 , wherein the at least one constraint comprises one or more of a role constraint, a privilege constraint, a Boolean constraint, a separation of duty constraint and a scope constraint.

12. An article of manufacture for authenticating a client in a service-oriented environment comprising a plurality of services, the article comprising a computer readable tangible storage medium containing one or more computer programs, which when executed implement the steps of claim 1 .

13. In a service-oriented environment comprising at least one service, a method for access control, the method comprising the steps of:

providing a rule specification language, wherein said rule specification language is based on pure-past linear temporal logic having past time temporal operators;

specifying at least one rule using the rule specification language, wherein the rule is used for determining whether a client can access a composite service, the composite service comprising a plurality of different services and different principles, wherein the principles are entities that invoke the different services of the composite service;

verifying whether an invocation of the composite service by the client satisfies the at least one rule; and

granting the client access to the composite service if the invocation of the composite service by the client satisfies the at least one rule,

wherein said rule specification language supports a temporal predicate on at least one composite principle, wherein the composite principle comprises a temporally ordered sequence of the different principles that are responsible for nested invocation of the different services associated with the composite service.

14. The method of claim 13 , wherein said rule specification language further supports at least one of: a scoped access control rule; a role translation; a scoped role, a Boolean predicate; a temporal constraint; a role constraint; a privilege constraint; a Boolean constraint; a separation of duty constraint, and a scope constraint.

15. An article of manufacture for authenticating a client in a service-oriented environment comprising a plurality of services, the article comprising a computer readable tangible storage medium containing one or more computer programs, which when executed implement the steps of claim 13 .

16. Apparatus for authenticating a client in a service-oriented environment comprising a plurality of services, the apparatus comprising:

a memory; and

at least one processor coupled to the memory and operative to:

invoke a composite service, the composite service comprising a plurality of different services and different principles, wherein the principles are entities that invoke the different services of the composite service;

maintain state information comprising an identify of at least one service that is associated with the composite service; and

use the state information to enforce access control on invocation of the at least one service,

wherein at least a portion of the state information is stored in the form of a composite principle, wherein the composite principle comprises a temporally ordered sequence of the different principles that are responsible for nested invocation of the different services associated with the composite service, and

wherein in using the state information to enforce access control on invocation of the at least one service, the at least one processor is further operative to:

obtain one or more rules that are used to determine if the client can invoke the composite service, wherein the one or more rules define access control policies which are specified using a pure-past linear temporal logic based specification language having past time temporal operators, and which support a temporal predicate on the composite principle; and

process the one or more rules against the composite principle to verify whether invocation of the composite service by the client satisfies the one or more rules.

17. Apparatus for access control in a service-oriented environment comprising a plurality of services, the apparatus comprising:

a memory; and

at least one processor coupled to the memory and operative to:

provide a rule specification language, wherein said rule specification language is based on pure-past linear temporal logic having past time temporal operators;

specify at least one rule using the rule specification language, wherein the rule is used for determining whether a client can access a composite service, the composite service comprising a plurality of different services and different principles, wherein the principles are entities that invoke the different services of the composite service;

verify whether an invocation of the composite service by the client satisfies the at least one rule; and

grant the client access to the composite service if the invocation of the composite service by the client satisfies the at least one rule,

wherein said rule specification language supports a temporal predicate on at least one composite principle, wherein the composite principle comprises a temporally ordered sequence of the different principles that are responsible for nested invocation of the different services associated with the composite service.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2022
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 061706/0202 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2007
From: IYENGAR, ARUN KWANGIL; MIKALSEN, THOMAS A.; ROUVELLOU, ISABELLE MARIE; SRIVATSA, MUDHAKAR; YIN, JIAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 019151/0407 →
Continuity (1)
Related Publication 20080256357A1 · Oct 16, 2008