EP0966822A2

Methods and apparatus for controlling access to information

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 9 March 2018, 8.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

143 claims: 57 independent, 86 dependent

  1. 1
    Claims of equivalent WO 9840992 A2 What is claimed is:1. An access filter that administers objects including a plurality of information resources and controls access by a user to an information resource of the plurality, the access filter comprising: access control information including access policy information including one or more explicit access policies that determine which information resources a given user may request access to and administrative policy information including one or more explicit administrative policies that deteπnine at least whether a user may administer an object;an access policy checker which responds to a request by a user to access a resource by denying the request if the access policy does not permit the access;and an administrative policy checker which responds to a request by a user to administer the object by denying the request if the administrative policy does not permit the request.
  2. 7
    The access filter set forth in any of claims 1 through 6 wherein:the object is an access policy.
  3. 8
    The access filter set forth in any of claims 1 through 6 wherein:the access control information defines user subsets of the users and information subsets of the information resources;and an access policy determines which information resource a user may access by defining which user subsets may access which information subsets.
  4. 16
    The access filter set forth in any one of claims 1 through 6 wherein:the objects are available resources in the virtual network.
  5. 17
    The access filter set forth in any one of claims 1 through 6 wherein:the objects are organized hierarchically;and an access policy for a given object applies to objects that are below the given object in the hierarchy to which the object belongs.
  6. 18
    The access filter set forth in any one of claims 1 through 6 wherein the access filter is one of a plurality thereof in a network;each access filter of the plurality has a local copy of the access control information;and the access policy checker in each access filter employs the local copy to check access.
  7. 21
    A data storage device for use in a system including a processor, the data storage device being characterized in that:the data storage device contains code which, when executed in the processor, implements the access filter set forth in any one of claims 1 through 6.
  8. 22
    The access filter set forth in any one of claims 1 through 6 wherein:the access filter is implemented as an application program executing under an operating system.
  9. 23
    The access filter set forth in any one of claims 1 through 6 wherein:the access filter is implemented as a component of an operating system.
  10. 24
    The access filter set forth in any one of claims 1 through 6 wherein:the access filter is implemented as a component of a router in the network.
  11. 25
    An access control system that controls access by users to information resources, the access control system comprising:access control information including an access policy that is defined using explicit definitions of user subsets of the users, explicit definitions of information subsets of the information resources, and explicit access policy definitions indicating which user subsets may access which information subsets;and an access policy checker which responds to a request by a user for access to an information resource by determining from the access policy the user subsets of which the user is a member, the information subsets of which the information resource is a member, and whether the explicit definitions permit access to an information subset of which the information resource is a member by a user subset to which the user belongs.
  12. 31
    The access control system set forth in any of claims 27 through 30 wherein:the object is a user subset.
  13. 32
    The access control system set forth in any of claims 27 through 30 wherein:the object is an information subset.
  14. 33
    The access control system set forth in any one of claims 27 through 30 wherein:the objects are available resources in a network.
  15. 34
    The access control system set forth in any one of claims 27 through 30 wherein:the objects are organized hierarchically;and an administrative policy for a given object applies to objects that are below the given object in the hierarchy to which the object belongs.
  16. 35
    The access control system set forth in any one of claims 27 through 30 wherein;the object is an access policy.
  17. 36
    A data storage device for use in a system including a processor, the data storage device being characterized in that:the data storage device contains code which, when executed in the processor, implements the access control system set forth in any one of claims 25 through 30.
  18. 37
    The access control system set forth in any one of claims 25 through 30 wherein:the access control system is implemented as an application program executing under an operating system.
  19. 38
    The access control system set forth in any one of claims 25 through 30 wherein:the access control system is implemented as a component of an operating system.
  20. 39
    The access control system set forth in any one of claims 25 through 30 wherein:the access control system is implemented as a component of a router in the network.
  21. 41
    An administrative access control system that controls administration of objects by administrative users, the system comprising:administrative policy that is defined using explicit definitions of administrative user subsets of the administrative users, explicit definitions of objects administered by the administrative access control system, and explicit administrative policy definitions of which user subsets may administer which objects;and an administrative policy checker which responds to a request by a user to administer an object by determining from the administrative policy whether the explicit administrative policy definitions permit an administrative user subset to which the user belongs to administer the object.
  22. 45
    The access control system set forth in any of claims 41 through 44 wherein:the object is a user subset.
  23. 46
    The access control system set forth in any of claims 41 through 44 wherein:the object is an information subset.
  24. 47
    The access control system set forth in any one of claims 41 through 44 wherein:the objects are available resources in a network.
  25. 48
    The access control system set forth in any one of claims 41 through 44 wherein:the objects are organized hierarchically;and an administrative policy for a given object applies to objects that are below the given object in the hierarchy to which the object belongs.
  26. 49
    A data storage device for use in a system including a processor, the data storage device being characterized in that:the data storage device contains code which, when executed in the processor, implements the access control system set forth in any one of claims 41 through 42.
  27. 50
    The access control system set forth in any one of claims 41 through 43 wherein:the access control system is implemented as an application program executing under an operating system.
  28. 51
    The access control system set forth in any one of claims 41 through 43 wherein:the access control system is implemented as a component of an operating system.
  29. 52
    The access control system set forth in any one of claims 41 through 43 wherein:the access control system is implemented as a component of a router in the network.
  30. 53
    A graphical user interface for an access control system that controls access by users to information resources according to an access policy that is defined using explicit definitions of user subsets of the users, explicit definitions of information subsets of the information resources, and explicit access policy definitions indicating which user subsets may access which information subsets, the graphical user interface comprising:a display upon which is displayed a list of user subsets, a list of objects, and a list of access policies, and at least an indication of a create access policy operation;and a selection device for selecting a user subset from the list thereof, an information subset from the list thereof, and the indication of the create access policy operation, the access control system responding to the selection of the user subset, the information subset, and the indication of the new access policy operation by establishing a new access policy for the selected user subset and the selected information subset.
  31. 56
    The graphical user interface set forth in any one of claims 53 through 55 wherein:a user subset may itself have user subsets and an information subset may itself have information subsets;and the list of user subsets shows the subset relationships among user subsets and the list of information subsets shows the subset relationships among the information subsets.
  32. 57
    The graphical user interface set forth in any one of claims 53 through 55, the graphical user interface further comprising:an indication of an evaluate operation, the access control system responding to a selection of a user subset and a selection of the indication of the evaluate operation by the selection device by indicating the information subsets in the list thereof that the selected user subset may and/or may not access.
  33. 59
    The graphical user interface set forth in any one of claims 53 through 55, the graphical user interface further comprising:an indication of an evaluate operation, the access control system responding to a selection of an information subset and a selection of the indication of the evaluate operation by the selection device by indicating the user subsets in the list thereof that may and/or may not access the selected information subset.
  34. 61
    The graphical user interface set forth in any one of claims 53 through 55, the graphical user interface further comprising:an indication of an evaluate operation, the access control system responding to a selection of an access policy from the list thereof and a selection of the indication of the evaluate operation by the selection device by indicating the user subsets and information subsets in the lists thereof to which the selected policy applies.
  35. 62
    A data storage device for use in a system including a processor, the data storage device being characterized in that:the data storage device contains code which, when executed in the processor, implements the graphical user interface set forth in any one of claims 53 through 55.
  36. 63
    A graphical user interface for an administrative access control system that permits a user who belongs to an administrative subset of users to administer objects according to an administrative policy that is defined using explicit definitions of the objects and the administrative user subsets, the graphical user interface comprising:a display upon which is displayed a list which indicates objects that may be administered by the user and an indication of an administration operation;and a selection device for selecting an object subset from the list thereof and the indication of the administration operation, the administrative access control system responding to the selection of the object and the indication of the administer object operation by performing the administration operation with regard to the object.
  37. 65
    The graphical user interface of either claim 63 or 64 wherein:the objects are in the alternative user subsets, information subsets of information resources, and available resources.
  38. 66
    The graphical user interface of either claim 63 or 64 wherein:the appearance of an object on the list indicates whether the user may administer the object.
  39. 68
    Auser interface for a system in which access by users of the system to information resources in the system is mediated by an access control system which includes access control information that indicates access rights of users to resources, the user interface comprising:an access control information reader for responding to an identification of a user of the system by reading the access control information to determine at least those resources to which the user potentially has access and providing at least a list of those resources;and an interface display generator for responding to the list by generating a display which visually indicates those resources to which the user potentially has access.
  40. 78
    Apparatus for generating a display indicating resources in a system that can be accessed by a user of the system the resources being obtained for the user by a client in the system from a server in the system and access by the user to the resources being mediated by an access control system that includes access control information that indicates access rights by users to resources, the apparatus being located in the client and the apparatus comprising:a list produced by the access control system that indicates those resources that can potentially be accessed by the the user and an interface display generator that receives the list and responds thereto by generating a display which visually indicates those resources to which the user potentially has access.
  41. 91
    Apparatus that provides an information resource in response to a request from a user, the request including an identification of the user according to a mode of identification and the apparatus comprising:access control information including a sensitivity level associated with the resource and a trust level associated with the mode of identification;and an access checker which permits the apparatus to provide the resource only if the trust level for the mode of identification is sufficient for the sensitivity level of the resource.
  42. 95
    The apparatus set forth in any one of claims 91 through 94 wherein:the request is transferred via a path in a network;the access control information further includes a path trust level associated with the path, the access checker further determining whether to permit the apparatus to provide the resource on the basis of the path trust level.
  43. 96
    The apparatus set forth in any one of claims 91 through 94 wherein:the access control information further includes an encryption trust level associated with an encryption method, the access checker further deteπnining whether to permit the apparatus to provide the resource on the basis of the encryption trust level of the encryption method used to encrypt the access request.
  44. 98
    The apparatus set forth in any one of claims 91 through 94 wherein:the access request is transferred via a path in a network;and the access control information further includes a path trust level associated with the path and an encryption trust level associated with an encryption method, the access checker further permitting the apparatus to provide the resource only if either the path trust level is sufficient for the sensitivity level or the access request has been encrypted with an encryption method whose encryption trust level is sufficient for the sensitivity level.
  45. 106
    Apparatus that provides an information resource via a path through a network to a user in response to a request from the user, the apparatus comprising:access control information including a sensitivity level associated with the resource, a path trust level associated with the path, and an encryption trust level associated with an encryption method;and an access checker which permits the apparatus to provide the resource only if either the path trust level is sufficient for the sensitivity level or the encryption trust level is sufficient for the sensitivity level and the request is encrypted with the encryption method.
  46. 112
    The apparatus set forth in any one of claims 106 through 111 wherein:the path trust level is subject to change;and the access checker checks the path trust level for every request.
  47. 117
    An improved access filter of the type which receives an access request via a network, the access request requesting access by a user to an information resource, the access control system making a determination whether the user may have access to the resource, and the improved access filter having the improvement comprising:an access check confirmer that determines whether another access control system in the network has already made the deterrnination, the access check confirmer causing the access filter to make the determination only if the determination has not already been made by another access filter.
  48. 120
    The access filter set forth in any of claims 117 through 119 wherein:as part of handling the returned data from the access request, the access filter further checks the data for a virus and does not allow any virus laden data to be returned to the requestor.
  49. 121
    An improved access filter which is used together with a plurality of other access filters in a network that further includes clients and servers that provide information resources to the clients via a path in the network in response to an access request from a user on a client, the access filters each being capable of making a determination whether the access request should be allowed, and if the request is to be allowed, encrypting the request, the access filter having the improvement comprising:an access check confirmer that determines whether another access filter has already made the determination and when that is the case, passing the encrypted request along the path without decrypting the request.
  50. 129
    The access filter set forth in any one of claims 124 through 127 wherein:each of the access filters has a key for encrypting requests to be decrypted by the access filter;each of the access filters has routing information from which the last access filter can be determined and key information which gives the access filter access to the key belonging to the last access filter;and the key belonging to the last access filter is used in encrypting the access request.
  51. 130
    The access filter set forth in any one of claims 124 through 127 wherein:the server that provides the resource has a key for encrypting requests to be decrypted by the server;the access filter nearest the server has key information which gives the access filter access to the public key belonging to the server;and the access filter nearest the server reencrypts the access request using the key belonging to the server.
  52. 131
    An access filter which is used as one of a plurality of access filters in a network, the access filter serving to make a deterrnination whether a request for access by a user to an information resource will be permitted and the network fiirther including a client from which the user makes the request via a path in the network that includes at least one of the acess filters and a server that provides the information resource in response to the request, the access filter comprising:a local copy of access control information that indicates whether the user may access the resource;an access checker which employs the local copy to make the determination;and an access check confirmer that determines whether another access filter in the path has already made the determination and only causes the access checker to make the determination if no other access filter has done so.
  53. 136
    The access filter set forth in any one of claims 131 through 135 further comprising:an authenticator for making an authentication for the request;when the determination is that the request will be permitted, the access filter employs the authenticator to produce authentication information that authenticates the request and adds the authentication information to the request;and the access check confirmer determines from the added authentication information whether another access filter has already made the determination.
  54. 140
    A data storage device for use in a system including a processor, the data storage device being characterized in that:the data storage device contains code which, when executed in the processor, implements the access filter set forth in any one of claims 117, 121, or 131.
  55. 141
    The access filter set forth in any one of claims 117, 121, or 131 wherein:the access filter is implemented as an application program executing under an operating system.
  56. 142
    The access filter set forth in any one of claims 117, 121, or 131 wherein:the access filter is implemented as a component of an operating system.
  57. 143
    The access filter set forth in any one of claims 117, 121, or 131 wherein:the access filter is implemented as a component of a router in the network.
Independent claims57