EP2863333B1

A method, an apparatus, a computer system, a security component and a computer readable medium for defining access rights in metadata-based file arrangement

Abstract

This record has no abstract on file.

EP2863333B1, drawing sheet 1
Sheet 1 of 9

Term

5 yearsleft in the term

Expires 28 September 2031.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

3 claims: 2 independent, 1 dependent

  1. 1
    A method for a computer system storing electronic objects being defined by metadata comprising one or more properties having values, wherein one or more of the electronic objects are associated with an access control list, said access control list defining a user of a client device authorized to access an electronic object and operations the user is authorized to perform on said electronic object, wherein the method comprises - receiving a request to access an electronic object (601) of said electronic objects from a client device;and - as a response to the received request, permitting the user of the client device to access the electronic object (601) according to said access control list;the method further comprising - said electronic object (601) referring by a property value of the metadata of said electronic object to a security component (603) comprising an attribute and access rights defined for said attribute;characterized in that the method further comprises - identifying a user being allowed to access the electronic object (601) from a metadata property value of another object, which another object is determined using the attribute, wherein said attribute is being formed of at least a first part defining a referring object and a second part defining a chain of references to properties of objects starting from said referring object, wherein a value of the referred-to property in the chain of references defines the next object having the next referred-to property, wherein the second-last reference in the chain of references defines said another object, and the last reference of the chain of references defines a property of said another object having a value that defines the user;and - propagating the security component to the access control list of said electronic object to give said access rights to the identified user.
  2. 2
    An apparatus comprising a processor, and memory storing electronic objects being defined by metadata comprising one or more properties having values, wherein one or more of the electronic objects are associated with an access control list, said access control list defining a user of a client device authorized to access an electronic object and operations the user is authorized to perform on said electronic object, said memory further including computer program code, wherein the memory and the computer program code are configured, with the processor, to cause the apparatus to - receive a request to access an electronic object (601) of said electronic objects from a client device;- as a response to the received request, to permit the user of the client device to access the electronic object (601) according to said access control list;- said electronic object (601) referring by a property value of the metadata of said electronic object to a security component (603) comprising an attribute and access rights defined for said attribute;characterized in that the apparatus is further caused - to identify a user being allowed to access the electronic object (601) from a metadata property value of another object, which another object is determined using the attribute, wherein said attribute is being formed of at least a first part defining a referring object and a second part defining a chain of references to properties of objects starting from said referring object, wherein a value of the referred-to property in the chain of references defines the next object having the next referred-to property, wherein the second-last reference in the chain of references defines said another object, and the last reference of the chain of references defines a property of said another object having a value that defines the user;and - to propagate the security component to the access control list of said electronic object to give said access rights to the identified user.