EP0442839A2

Method for providing user access control within a distributed data processing system.

Abstract

The method of the present invention may be utilized to provide user access control for a plurality of resource objects within a distributed data processing system having a plurality of resource managers. A reference monitor service is established and a plurality of access control profiles are stored therein. Thereafter, selected access control profile information may be communicated between the reference monitor service and a resource manager in response to an attempted access of a particular resource object controlled by that resource manager. A resource manager may utilize this communication technique to retrieve, modify, or delete a selected access control profile, as desired. Further, the resource manager may utilize this communication technique to control access to a resource object by utilizing the information contained within the access control profile to determine if the requester is authorized to access the resource object and whether or not the requester has been granted sufficient authority to take selected actions with respect to that resource object. In a preferred embodiment of the present invention, each access control profile may include access control information relating to a selected user; a selected resource object; a selected group of users; a specified level of authority associated with a selected user; a selected set of resource objects; or, a predetermined set of resource objects and a selected list of users each authorized to access at least a portion of said predetermined set of resource objects.

EP0442839A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 25 January 2011, 15.7 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

9 claims: 1 independent, 8 dependent

  1. 1
    A method of providing user access control for a plurality of resource objects within a distributed data processing system having a plurality of resource managers associated with said plurality of resource objects, said method comprising the steps of:storing a plurality of access control profiles within a reference monitor service;establishing communication between said reference monitor service and said plurality of resource managers;and    controlling access to a selected resource object associated with a particular resource manager by means of a selected one of said plurality of access control profiles.
  2. 2
    The method of providing user access control for a plurality of resource objects within a distributed data processing system according to Claim 1 wherein said step of controlling access to a selected resource object associated with a particular resource manager by means of a selected one of said plurality of access control profiles comprises the step of retrieving a selected one of said plurality of access control profiles in response to an attempted access of said selected resource object.
  3. 3
    The method of providing user access control for a plurality of resource objects within a distributed data processing system according to Claim 1 wherein said step of controlling access to a selected resource object associated with a particular resource manager by means of a selected one of said plurality of access control profiles comprises the step of modifying said selected one of said plurality of access control profiles within said reference monitor service in response to a communication from a selected one of said plurality of resource managers.
  4. 4
    The method of providing user access control for a plurality of resource objects within a distributed data processing system according to Claim 1 wherein said step of controlling access to a selected resource object associated with a particular resource manager by means of a selected one of said plurality of access control profiles comprises the step of deleting said selected one of said plurality of access control profiles within said reference monitor service in response to a communication from a selected one of said plurality of resource managers.
  5. 5
    The method of providing user access control for a plurality of resource objects within a distributed data processing system according to Claim 1 wherein said step of controlling access to a selected resource object associated with a particular resource manager by means of a selected one of said plurality of access control profiles comprises the step of modifying said selected one of said plurality of access control profiles within said reference monitor service to grant access to a second selected resource object.
  6. 6
    The method of providing user access control for a plurality of resource objects within a distributed data processing system according to Claim 1 wherein said step of controlling access to a selected resource object associated with a particular resource manager by means of a selected one of said plurality of access control profiles comprises the step of modifying said selected one of said plurality of access control profiles within said reference monitor service to revoke access to a selected resource object.
  7. 7
    The method of providing user access control for a plurality of resource objects within a distributed data processing system according to Claim 1 wherein said step of controlling access to a selected resource object associated with a particular resource manager by means of a selected one of said plurality of access control profiles comprises the step of determining from said selected one of said plurality of access control profiles whether a selected user is authorized to access said selected resource object.
  8. 8
    The method of providing user access control for a plurality of resource objects within a distributed data processing system according to Claim 1 wherein said plurality of access control profiles each includes an indication of selected activities permitted with respect to a selected resource object by a particular user.
  9. 9
    The method of providing user access control for a plurality of resource objects within a distributed data processing system according to Claim 8 wherein said step of controlling access to a selected resource object associated with a particular resource manager by means of a selected one of said plurality of access control profiles comprises the step of determining from said selected one of said plurality of access control profiles whether a particular user is permitted to perform a selected activity with respect to said selected resource object.