×

Policy resolution in an entitlement management system

  • US 8,010,991 B2
  • Filed: 01/22/2008
  • Issued: 08/30/2011
  • Est. Priority Date: 01/29/2007
  • Status: Active Grant
First Claim
Patent Images

1. A data processing apparatus, comprising:

  • a policy administration point that is configured to receive one or more definitions or updates of entitlement policies specifying subjects, actions, and resources, and to update a first entitlement repository coupled to the policy administration point with the definitions or updates in response to receiving the definitions or updates;

    one or more policy decision points that are coupled to the policy administration point over a network;

    one or more policy enforcement points that are integrated into one or more respective first application programs, wherein each of the policy enforcement points is coupled to one of the policy decision points;

    one or more action handlers in the policy administration point, wherein each of the action handlers is configured to intercept a particular action represented in an update to an entitlement policy, to transform the action into an entitlement update in a form compatible with a native entitlement mechanism of a second application program that does not have one of the policy enforcement points, to send the transformed entitlement update to the second application program, and to cause a rollback of the update of the first entitlement repository if the second application program fails to implement the entitlement update in the native entitlement mechanism.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×