×

Declarative permission requests in a computer system

  • US 6,473,800 B1
  • Filed: 07/15/1998
  • Issued: 10/29/2002
  • Est. Priority Date: 07/15/1998
  • Status: Expired due to Term
First Claim
Patent Images

1. A computer-implemented method for providing security on a host computer by selectively restricting the access of computer-executable instructions to system operations provided by the host computer, the method comprising:

  • defining a security zone corresponding to a set of data sources;

    associating a security policy with the security zone, the security policy including a host permission set created by a user of the host computer that defines a set of permissions that restrict access to the system operations provided by the host computer by computer-executable instructions to be retrieved from said set of data sources;

    accessing a data source;

    determining if the accessed data source is one of said sources of computer-executable instructions;

    if the accessed data source is one of said set of data sources and if data to be retrieved by the host computer from said accessed data source contains computer-executable instructions, obtaining a requested permission set associated with the computer-executable instructions contained in the data retrieved from the accessed data souree, the requested permission set asserting a set of permissions that are requested by the computer-executable instructions for access to the system operations provided by the host computer; and

    restricting the access of the computer-executable instructions to the system operations provided by the host computer based on a comparison of the requested permission set to the host permission set.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×