Trust ratings in group credentials
First Claim
1. A method for evaluating a set of credentials comprising at least one group credential comprising:
- ascertaining at least one first trust rating within at least one of said credentials within said set of credentials including said group credential, wherein each of said first trust ratings is associated with a level of confidence in information being certified within the respective credential;
determining a second trust rating for said set of credentials based, at least in part, upon an analysis of said at least one first trust rating; and
providing a signal in the event said second trust rating satisfies predetermined criteria.
2 Assignments
0 Petitions
Accused Products
Abstract
A method and system for evaluating a set of credentials that includes at least one group credential and that may include one or more additional credentials. A trust rating is provided in association with the at least one group credential within the set of credentials and trust ratings may also be provided in other credentials within the set of credentials. Each trust rating provides an indication of the level of confidence in the information being certified in the respective credential. In response to a request for access to a resource or service, an evaluation of the group credentials is performed by an access control program to determine whether access to the requested resource or service should be provided. In one embodiment, within any given certification path a composite trust rating for the respective path is determined. An overall trust rating for the set of credentials is determined based upon the composite trust ratings. Upon a determination that a user requesting access to a resource has an acceptable set of credentials and a satisfactory trust rating, access to the requested resource or service is granted to the user.
-
Citations
22 Claims
-
1. A method for evaluating a set of credentials comprising at least one group credential comprising:
-
ascertaining at least one first trust rating within at least one of said credentials within said set of credentials including said group credential, wherein each of said first trust ratings is associated with a level of confidence in information being certified within the respective credential;
determining a second trust rating for said set of credentials based, at least in part, upon an analysis of said at least one first trust rating; and
providing a signal in the event said second trust rating satisfies predetermined criteria. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 14, 15, 16, 17)
-
-
13. A system for evaluating a set of credentials including at least one group credential comprising;
-
a memory containing an access control program; and
a processor operative to execute said access control program;
said access control program comprising;
program code for ascertaining at least one first trust rating within at least one of said credentials within said set of credentials including said group credential, wherein each of said first trust ratings is associated with a level of confidence in information being certified within the respective credential;
program code for determining a second trust rating for said set of credentials based, at least in part, upon an analysis of said at least one first trust rating; and
program code for providing a signal in the event said second trust rating satisfies predetermined criteria.
-
-
18. A computer program product including a computer readable medium, said computer readable medium having an access control program stored thereon, said access control program for execution on a processor and comprising:
-
program code for ascertaining at least one first trust rating within at least one credential within a set of credentials including group credential, wherein each of said first trust ratings is associated with a level of confidence in information being certified within the respective credential;
program code for determining a second trust rating for said set of credentials based, at least in part, upon an analysis of said at least one first trust rating; and
program code for providing a signal in the event said second trust rating satisfies predetermined criteria.
-
-
19. A computer data signal, said computer data signal including a computer program for use in evaluating a set of credentials, said computer program comprising:
-
program code for ascertaining at least one first trust rating within at least one credential within said set of credentials, wherein said set of credentials includes a group credential and wherein each of said first trust ratings is associated with a level of confidence in information being certified within the respective credential;
program code for determining a second trust rating for said set of credentials based, at least in part, upon an analysis of said at least one first trust rating; and
program code for providing a signal in the event said second trust rating satisfies predetermined criteria.
-
-
20. A system for evaluating a set of credentials including at least one group credential comprising;
-
means for storing an access control program; and
means for executing said access control program out of said storing means, said access control program including;
program code for ascertaining at least one first trust rating within at least one of said credentials within said set of credentials including said group credential, wherein each of said first trust ratings is associated with a level of confidence in information being certified within the respective credential;
program code for determining a second trust rating for said set of credentials based, at least in part, upon an analysis of said at least one first trust rating; and
program code for providing a signal in the event said second trust rating satisfies predetermined criteria.
-
-
21. A method for evaluating a set of credentials comprising at least one group credential comprising:
-
ascertaining at least one first trust rating within at least one of said credentials within said set of credentials including said group credential, wherein each of said first trust ratings is associated with a level of confidence in information being certified within the respective credential;
determining a second trust rating for said set of credentials based, at least in part, upon an analysis of said at least one first trust rating; and
storing said second trust rating for subsequent use. - View Dependent Claims (22)
-
Specification