×

ACCESS CONTROL POLICIES ASSOCIATED WITH FREEFORM METADATA

  • US 20140207861A1
  • Filed: 01/22/2013
  • Published: 07/24/2014
  • Est. Priority Date: 01/22/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer implemented method for using tags to control access to resources, said method comprising:

  • under the control of one or more computer systems configured with executable instructions,associating a first access control policy and a second access control policy with a metadata tag, the first access control policy identifying which principals are allowed to assign the metadata tag to at least one computing resource, the second access control policy identifying operations that are allowed or not allowed to be performed on resources associated with the metadata tag;

    receiving, from a user using an application programming interface (API), a request to assign the metadata tag to the at least one computing resource;

    evaluating the first access control policy and assigning the metadata tag to the computing resource in response to determining that the first access control policy allows the user to assign the metadata tag;

    receiving a request to perform an operation on the computing resource;

    evaluating the second access control policy associated with the metadata tag; and

    authorizing the request to perform the operation on the computing resource based at least in part on evaluation of the second access control policy.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×