EP1320012A2

System and method for providing distributed access control to secured items

Abstract

The present invention relates to a system and method for providing distributed access control. A number of local servers are employed to operate largely on behalf of a central server responsible for centralized access control management. Such a distributed fashion ensures the dependability, reliability and scalability of the access control management undertaking by the central server. According to one embodiment, a distributed access control system that restricts access to secured items can include at least a central server having a server module that provides overall access control, and a plurality of local servers. Each of the local servers can include a local module that provides local access control. The access control, performed by the central server or the local servers, operates to permit or deny access requests to the secured items by requestors.

EP1320012A2, drawing sheet 1
Sheet 1 of 33

Term

Term ended

Projected expiry passed 11 December 2022, 3.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 6 independent, 4 dependent

  1. 1
    A distributed access control system that restricts access to secured items, said system comprising:- a central server having a server module that provides overall access control;and a plurality of local servers coupled to the central server, each of said local servers including a local module that provides local access control to groups of designated users,    wherein the access control, performed by said central server or said local servers, operates to permit or deny access requests to the secured items by requestors in accordance with access privileges granted to the requestor and access rules in the secured items.
  2. 4
    A distributed access control system as recited in any preceding claim, wherein, when the access requests are processed in said local servers, the requestors gain access to the secured items without having to access said central server when the access privileges of the requestors are permitted by the access rules in the secured items.
  3. 5
    A distributed access control system as recited in any preceding claim, wherein the local module is a copy or a subset of the server module so that any of the local modules can operate independent of said central server and other of said local servers.
  4. 6
    A distributed access control system as recited in any preceding claim wherein each of the secured items is secured in a file structure including a security information portion and an encrypted data portion, the security information portion being encrypted and controlling restrictive access to the encrypted data portion can only be accessed by a requestor with an authenticated user key, upon successful access to the security information portion that includes a set of access rules and a file key, the file key can only be obtained to decrypt the encrypted data portion when the access rules are successfully measured against access privilege of the requestor.
  5. 7
    A method used in a distributed access control system, the method comprising:- providing overall access control in a central server;and providing local access control to groups of designated users respectively in local servers, wherein the local servers are coupled to the central server;wherein the access control, performed by said central server or said local servers, operates to permit or deny access requests to the secured items by requestors in accordance with access privileges granted to the requestor and access rules in the secured items.
  6. 10
    A method as recited in any one of claims 7 to 9, wherein each of the secured items is secured in a file structure including a security information portion and an encrypted data portion, the security information portion being encrypted and controlling restrictive access to the encrypted data portion can only be accessed by a requestor with an authenticated user key, upon successful access to the security information portion that includes a set of access rules and a file key, the file key can only be obtained to decrypt the encrypted data portion when the access rules are successfully measured against access privilege of the requestor.