System, server, and program for access right management
First Claim
1. A system comprising an access right management device, which is provided in each domain, for creating a resource-sharing policy and performing resource-sharing policy negotiation between a plurality of domain administrators, whereinthe access right management device performs:
- for each policy unit of the resource-sharing policy, identifying an access right management device which is a negotiating partner about each policy unit;
generating negotiation information including an identification name of the identified access right management device and the policy unit to be negotiated; and
transmitting the negotiation information to the identified access right management device; and
setting the resource-sharing policy on shared resource when having received an instruction to agree on every policy unit from the identified access right management device to which the negotiation information was sent.
1 Assignment
0 Petitions
Accused Products
Abstract
Each domain is provided with an access right management device which creates a resource-sharing policy and performs processing for resource-sharing policy negotiation between a plurality of domain administrators. An access right management device that has created a resource-sharing policy identifies, for each policy unit included in the resource-sharing policy, an access right management device that is a negotiating partner to negotiate with about the policy unit in question. The access right management device generates negotiation information including an identification name of the identified negotiating-partner access right management device and the policy unit in question and sends the negotiation information to the negotiating-partner access right management device. Only when all policy units are agreed on by respective identified negotiating-partner access right management devices, the resource-sharing policy is set on shared resources.
-
Citations
25 Claims
-
1. A system comprising an access right management device, which is provided in each domain, for creating a resource-sharing policy and performing resource-sharing policy negotiation between a plurality of domain administrators, wherein
the access right management device performs: -
for each policy unit of the resource-sharing policy, identifying an access right management device which is a negotiating partner about each policy unit;
generating negotiation information including an identification name of the identified access right management device and the policy unit to be negotiated; and
transmitting the negotiation information to the identified access right management device; andsetting the resource-sharing policy on shared resource when having received an instruction to agree on every policy unit from the identified access right management device to which the negotiation information was sent. - View Dependent Claims (2, 3, 4, 5, 6, 8)
-
-
7. A system comprising:
-
an access right management server provided in each domain, which, for each policy unit of a generated resource-sharing policy, identifies a negotiating partner about the policy unit;
generates negotiation information including an identification name of the identified negotiating partner and the policy unit to be negotiated; and
transmits the negotiation information to the identified negotiating partner; and
when having received an instruction to agree on every policy unit from the identified negotiating partner to which the negotiation information was sent, sets the resource-sharing policy on shared resource; anda client terminal which connects to the access right management server to allow a domain administrator to instruct editing, negotiation and forcedly setting of the resource-sharing policy. - View Dependent Claims (9)
-
-
10. A server, which is provided in each domain, for creating a resource-sharing policy and performing resource-sharing policy negotiation between a plurality of domain administrators, wherein the server performs:
-
for each policy unit of the resource-sharing policy, identifying a server which is a negotiating partner about each policy unit;
generating negotiation information including an identification name of the identified server and the policy unit to be negotiated; and
transmitting the negotiation information to the identified server; andsetting the resource-sharing policy on shared resource when having received an instruction to agree on every policy unit from the identified server to which the negotiation information was sent. - View Dependent Claims (11, 12, 13, 14, 15)
-
-
16. An access right management program which runs on an access right management server provided in each domain, for creating a resource-sharing policy and performing resource-sharing policy negotiation between a plurality of domain administrators, wherein the program instructs the access right management server to performs:
-
a function of, for each policy unit of the resource-sharing policy, identifying an access right management server which is a negotiating partner about each policy unit;
generating negotiation information including an identification name of the identified access right management server and the policy unit to be negotiated; and
transmitting the negotiation information to the identified access right management server; anda function of setting the resource-sharing policy on shared resource when having received an instruction to agree on every policy unit from the identified access right management server to which the negotiation information was sent. - View Dependent Claims (17, 18, 19, 20, 21)
-
-
22. A method for creating a resource-sharing policy and performing resource-sharing policy negotiation between a plurality of domain administrators in an access right management server provided in each domain, comprising:
-
for each policy unit of the resource-sharing policy, identifying an access right management server which is a negotiating partner about each policy unit;
generating negotiation information including an identification name of the identified access right management server and the policy unit to be negotiated; and
transmitting the negotiation information to the identified access right management server; andsetting the resource-sharing policy on shared resource when having received an instruction to agree on every policy unit from the identified access right management server to which the negotiation information was sent. - View Dependent Claims (23, 24, 25)
-
Specification