×

Methods and apparatus for pre-filtered access control in computing systems

  • US 7,216,125 B2
  • Filed: 09/17/2002
  • Issued: 05/08/2007
  • Est. Priority Date: 09/17/2002
  • Status: Active Grant
First Claim
Patent Images

1. An automated method implemented in a computer system for selecting one or more resources on which a principal is authorized to perform at least one action, the method comprising the steps of:

  • selecting a plurality of authorization policies that apply to a given principal;

    transforming a first nonempty subset of the plurality of authorization policies based on meta-information associated with the one or more resources so as to form a query against a resource store that selects resources from the resource store;

    executing the query to select the resources from the resource store;

    removing one or more resources from the selected resources on which the given principal is not permitted to perform the at least one action in accordance with a second nonempty subset of the plurality of authorization policies, so as to select the one or more resources on which the plurality of authorization policies allow the given principal to perform the at least one action; and

    presenting the given principal the one or more resources on which the plurality of authorization policies allow the given principal to perform the at least one action.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×