×

Modular enterprise authorization solution

  • US 8,060,932 B2
  • Filed: 11/03/2006
  • Issued: 11/15/2011
  • Est. Priority Date: 11/03/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method for authorizing a request for a component within an application, comprising:

  • providing a first interface for directly calling a plurality of provider modules that are for implementing authorization, the provider modules are directly callable through the first interface by supplemental authorization code to provide a granular level of authorization;

    providing a second interface that is directly callable by supplemental authorization code, a call to the second interface allows one or more of the plurality of provider modules to be specified, the second interface invokes at least the specified provider module or modules to provide authorization;

    receiving an authorization request at an external authorization system from supplemental authorization code inside an application, the authentication request is received either at the first interface or the second interface, the authorization request requests authorization to perform an operation on a component within the application, the external authorization system located external to the application;

    determining whether a role is authorized to perform the requested operation on the application component by the external authorization system, the determining includes retrieving a rule which specifies one or more operations that one or more roles are allowed to perform on the application component;

    configuring a token in response to said step of determining, the token indicating the authorization for the requested operation on the application component; and

    providing the token to said application.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×