or
Bookmark and Share
User access to objects in group based access control based on result of greatest common divisor of assigned unique prime numbers of user and object
   
Document Number
US Patent 6189036
Issued Date
February 13, 2001
Link
Inventors
Kao; I-Lung (Round Rock, TX)
Map
Abstract
An access control mechanism using a grouping system whereby each group is assigned a unique prime number. The resource objects to be accessed are assigned a value that is determined by multiplying all of the group prime numbers from the groups that have access to that resource. Also, each user is assigned to one or more groups and each user has an access number that is a product of the prime numbers assigned to each group. When a particular user desires access to a particular resource object, the greatest common divisor between the resource product and the user product is determined. If the resulting greatest common divisor is greater than one, then the user is allowed access. If the greatest common divisor is one (the lowest prime), the user is denied access.
Drawing
User access to objects in group based access control based on result of greatest common divisor of assigned unique prime numbers of user and object - US Patent 6189036 Drawing
Drawing from US Patent 6189036
Tags:
Description:
Amusing 0%
Clever 0%
Complex 0%
Efficient 0%
Historic 0%
Important 0%
Innovative 0%
Interesting 0%
Practical 0%
Simple 0%
Number of Claims:
20
Comments:
no comments yet
Published
February 13, 2001
Application Number
09/187,070
Filed
November 5, 1998
US Classification
709/229   709/225
Int'l Classification
G06F   9/46   (20060101)  
Examiner
Attorney/Law Firm
USPTO Field of Search
709/229   709/225  
Related Patents
7178163 - Cross platform network authentication and authorization model - Owned by Microsoft Corporation (Redmond, WA)

A model for authentication and authorization of users and applications that use network services. A client requests a ticket by providing credentials (user ID and password), e.g., over HTTP/SOAP/XML in the UDDI framework. An authentication adapter in a receiving server deserializes the request into a data structure that provides access to the security ID and password attributes, and passes these attributes to an ID management system to perform authentication. The credentials also determine the user's or application's privileges. The authentication adapter constructs a ticket object for the client incorporating the privileges and other information, e.g., the security ID and a date/time stamp. The ticket object is serialized, encrypted, encoded for transmission and inserted into an appropriately-formatted XML message and returned to the requesting client. The client attaches the authentication ticket to subsequent service requests that require authentication. To validate the ticket, the ticket object is reconstructed from the request data.

6910041 - Authorization model for administration - Owned by International Business Machines Corporation (Armonk, NY)

An administration model is provided that uses access control lists to define permissions for users and groups of users. The model identifies a number of objects to be administered. Associated with each of these objects is a set of administrative operations that can be performed on the object. For each of these operations a permission in an access control list entry is defined. The protected resources are arranged in a hierarchical fashion and an access control list can be associated with any point in the hierarchy. The access control list provides fine-grained control over the protected resources. At the time an administrator requests to perform an operation, the administrator's identification is used to look up the prevailing access control list to determine whether the operation is permitted.

7389430 - Method for providing access control to single sign-on computer networks - Owned by International Business Machines Corporation (Armonk, NY)

A method for providing access control to a single sign-on computer network is disclosed. A user is assigned to multiple groups within a computer network. In response to an access request by the user, the computer network determines a group pass count based on a user profile of the user. The group pass count is a number of groups in which the access request meets all their access requirements. The computer network grants the access request if the group pass count is greater than a predetermined high group pass threshold value.

7263535 - Resource list management system - Owned by BellSouth Intellectual Property Corporation (Wilmington, DE)

A system for providing group accessibility is provided. A representative resource list management system includes a group management system operable to store a resource list for a user, and a service manager operable to detect a status of a contact associated with the resource list. The resource list includes at least one group, the at least one group including a plurality of contacts. The service manager is operable to update accessibility of the at least one group in response to at least one of the plurality of contacts being accessible on a network. Methods and other systems for resource list management are also provided.

7536392 - Network update manager - Owned by AT&T Intelllectual Property I, L.P. (Reno, NV)

Network resource management systems are provided. A representative network update manager includes an updater coupled to a persistent database and to an administrative application residing on an application server and a memory operable to store a plurality of delayed updates. The network update manager is preferably operable to receive at least one update from the administrative application and subsequently update the persistent database. Methods and other systems for network resource management are also provided.

Claims
Description
About| FAQs| Terms & Disclaimer| Link to Us| Contact Us