×

Access control system, access control method, and access control program

  • US 7,624,424 B2
  • Filed: 05/20/2005
  • Issued: 11/24/2009
  • Est. Priority Date: 05/21/2004
  • Status: Active Grant
First Claim
Patent Images

1. An access control system comprising:

  • a knowledge database configured to store(i) information indicative of a relationship between a group of users or devices that use at least a resource as an access destination, and user identification information or device identification information capable of identifying the user or device,(ii) information indicative of a relationship between a position as an access source of access to the resource, and access source identification information capable of identifying the position, or(iii) information indicative of a relationship between the resource and access destination identification information capable of identifying the resource; and

    a policy engine configured to(i) store an access control policy describing at least the group, position, and resource of the information stored in the knowledge database,(ii) generate an access control list indicating accessibility/inaccessibility to an access destination from an access source by use of the access control policy and the information stored in the knowledge database, and(iii) set the access control list in an existing access control device,wherein said knowledge database includesa knowledge storage configured to store(i) information indicative of a relationship between a group and user identification information or device identification information, as a directional graph having a path from one group to another group, user identification information, or device identification information,(ii) information indicative of a relationship between a position and access source identification information, as a directional graph having a path from one position to another position or access source identification information, and(iii) information indicative of a relationship between a resource and access destination identification information, as a directional graph having a path from one resource to another resource or access destination identification information.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×