×

Method for controlling access to information

  • US 6,516,315 B1
  • Filed: 11/05/1999
  • Issued: 02/04/2003
  • Est. Priority Date: 11/05/1998
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for controlling access to information on a computer system being accessible to a plurality of users, wherein the computer system has information including a plurality of data objects, the steps comprising:

  • providing an access right for each relationship between a user and a data object, wherein each user can have a plurality of relationships to each data object, wherein at least one user has a plurality of relationships with one data object, wherein each access right comprises a security classification, wherein some of the data objects have a vertical relationship defined by a parent data object and a child data object, and wherein for each vertical relationship the child data object has a more restrictive security classification than the parent data object;

    obtaining a request from a user for information about a data object;

    finding at least one of the relationships between the user and the data object;

    determining the security classification for each relationship found between the user and the data object;

    determining a security classification of the data object;

    granting the user access to the data object if a level of one of the security classifications for all the relationships is greater than a level of the security classification of the data object;

    granting the user access to a parent data object if the user has been granted access to a corresponding child data object; and

    denying the user access to the data object if the security classifications for all the relationships are less than a level of the security classifications of the data object.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×