×

Auditing authorization decisions

  • US 8,225,378 B2
  • Filed: 10/12/2010
  • Issued: 07/17/2012
  • Est. Priority Date: 09/08/2006
  • Status: Active Grant
First Claim
Patent Images

1. A device comprising:

  • memory and a processor;

    an auditing scheme module, stored in the memory and executable on the processor; and

    an access control scheme module, stored in the memory and executable on the processor, that is integrated with the auditing scheme module, whereinthe access control scheme module makes authorization decisions in response to access requests for resources, the authorization decisions including inputs, outputs, and internal data, andthe auditing scheme module includes an audit policy that comprises audit policy rules, the audit policy rules including audit content rules that;

    specify what audit information from any of the inputs, the outputs, or the internal data is to be included in an audit record, andspecify logical deduction data used or produced during evaluation algorithms of the authorization decisions, the logical deduction data comprising proof graphs indicating respective logical chains of deductions that occur within the evaluation algorithms.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×