Access control using identifiers in links
5 claims: 2 independent, 3 dependent
- 1コンピュータ実行可能命令を備えるコンピュータ可読記憶装置であって、前記命令はアクセスゲートウェイのプロセッサにより実行されると、前記プロセッサに、 前記アクセスゲートウェイにおいて、前記アクセスゲートウェイを介し 、ファイルサーバ上の 共有リソースへのアクセスを可能にする暗号トークンに関する要求を第1のコンピュータ装置から受信するステップと、 前記暗号トークンを リンクを用いて 送信するステップ であって、前記暗号トークンは前記リンクに埋め込まれ、前記暗号トークンは前記第1のコンピュータが前記共有リソースにアクセスするため、および、前記第1のコンピュータが前記暗号トークンを情報要素の一部として第2のコンピュータに与えるために前記アクセスゲートウェイから前記第1のコンピュータ装置に送信され、前記情報要素は暗号化されており、前記情報要素は前記第1のコンピュータによって生成され、アクセス制御スキームに関連付けられていることを特徴とするステップ と、 前記アクセスゲートウェイにおいて、前記暗号トークンを使用して前記共有リソースにアクセスする試行を 前記 第2のコンピュータ装置から受信するステップと、 前記アクセス制御スキームに基づき前記情報要素に関連付けられた第1の情報が前記第2のコンピュータ装置が前記共有リソースへのアクセスを許可したことを示し、前記暗号トークンに基づく第2の情報が前記第2のコンピュータ装置が前記共有リソースへのアクセスを許可したことを示したときに、 前記第2のコンピュータ装置による前記アクセスゲートウェイを介した前記共有リソースへのアクセスを容易にするステップ であって、前記第1のコンピュータ装置と前記第2のコンピュータ装置が別個のものであり、前記第1のコンピュータ装置と前記ファイルサーバが別個のものであり、前記第2のコンピュータ装置と前記ファイルサーバが別個のものであり、前記共有リソースと関連する前記暗号トークンが、前記第1のコンピュータ装置と前記第2のコンピュータ装置のための前記ファイルサーバに関連付けられていることを特徴とするステップと、 を含む処理を実行させることを特徴とするコンピュータ可読記憶装置。
- 2前記命令が前記プロセッサにより実行されると、前記プロセッサに、 前記暗号トークンがタイムスタンプを含むことを判定するステップと、 前記暗号トークンに関連している有効期間が経過したときに、前記暗号トークンを使用して前記共有リソースへのアクセスの試行を拒否するステップと をさらに含む処理を実行させることを特徴とする請求項1に記載のコンピュータ可読記憶装置。
- 3前記第1のコンピュータ装置または前記第2のコンピュータ装置は、デスクトップコンピュータ、ラップトップコンピュータ、パーソナルデジタルアシスタント、または携帯通信装置を含むことを特徴とする請求項1又は2に記載のコンピュータ可読記憶装置。
- 4前記アクセスゲートウェイを介し、ファイルサーバ上の共有リソースへのアクセスを可能にする暗号トークンに関する要求は、前記第1のコンピュータ装置上の第1の協力アプリケーションによってなされ、前記暗号トークンを使用して前記共有リソースにアクセスする試行は、前記第2のコンピュータ装置上の第2の協力アプリケーションによってなされることを特徴とする、請求項1~3のいずれか一項に記載のコンピュータ可読記憶装置。
- 5前記第1の協力アプリケーションまたは前記第2の協力アプリケーションは、電子メールアプリケーション、文書処理アプリケーション、表計算アプリケーション、プレゼンテーションアプリケーション、ウェブブラウザ、ファイル共有アプリケーション、およびマルチメディアアプリケーションを含むことを特徴とする、請求項4に記載のコンピュータ可読記憶装置。
Independent claims5
79 paragraphs, as filed
The present invention relates to access control using identifiers within links.
Enterprises face a number of challenges when trying to control access to sensitive information. For example, challenges include limiting access to specific resources to limited users, disabling users' access to resources when the role of users within the enterprise changes, and corporate security policies. It may include applying access control changes to corporate resources when changed.
Typically, an entity restricts access to resources on a need-to-know principle. That is, the enterprise typically creates a security policy that allows access only to users who need access to the resource and at the same time denies access to users who do not need access to the resource. Access control typically includes keeping an access list of authorized users for each resource and allowing only those authorized users to access each particular resource. The access list is updated by the resource owner or other authorized person when the company's security policy changes. Often, resource owners try to save time and money by listing more users in the access list than necessary and avoiding frequent updates to the access list. However, this practice poses a security vulnerability in the enterprise.
Companies often have multiple groups of professionals, such as business professionals, administrative professionals, and information technology (IT) professionals. In general, a company's access-controlled resources are controlled by the company's business professionals. However, most companies consider access control to be a technical task, so typically IT professionals, rather than business professionals, manage access lists for access-controlled resources. There is. This leads to inefficiencies in the processing of the business. The reason is that one group knows who should have access but cannot grant it, and the other group can grant access but who has access. Because I don't know what to do.
The present disclosure controls access to a shared resource by embedding an identifier in the link to the shared resource that permits access to the shared resource and forwarding this link to one or more destination computer devices. Is described. The owner of the resource or someone else who wants to grant access to the shared computer resource receives a resource access identifier, such as a random crypto token associated with the shared computer resource. This resource access identifier is embedded within a link to a shared computer resource, which link is placed within an information element such as an email, instant message or file. An access control scheme, such as a digital rights management (DRM) profile, is associated with the information element to generate a protected information element, which is then sent to the destination computer device.
The access control scheme associated with the protected information element can include a list of computer devices authorized to access the protected information element. If the list includes a destination computer device, the destination computer device can access the shared computer resource using the link and resource access identifier in the protected information element. The destination computer device can also allow the other computer device to access the shared computer resource by transferring the protected information element to the other computer device.
An overview of the invention is provided to provide in a simple form an excerpt of the concepts further described below in the detailed description of the invention. The outline of the present invention is not intended to identify the important or essential features of the present invention, nor is it intended to be used to limit the scope of the invention.
<figref num="1">FIG. 3 is a block diagram of a particular embodiment of an access control system using an identifier within a link.</figref><figref num="2">FIG. 3 is a block diagram of a particular embodiment of a resource access identifier that can be used to perform access control using an identifier within a link.</figref><figref num="3">FIG. 3 is a block diagram of a particular embodiment of a digital rights (DRM) profile that can be used in access control using identifiers within links.</figref><figref num="4">FIG. 3 is a block diagram of another particular embodiment of an access control system using an identifier within a link.</figref><figref num="5">FIG. 3 is a block diagram of another particular embodiment of an access control system using an identifier within a link.</figref><figref num="6">It is a flow diagram of a specific embodiment of an access control method using an identifier in a link.</figref><figref num="7">It is a flow diagram of another specific embodiment of an access control method using an identifier in a link.</figref><figref num="8">It is a flow diagram of a specific embodiment of the method of performing access control using an identifier in a link in an access gateway.</figref><figref num="9">It is a flow diagram of another specific embodiment of the method of performing access control using an identifier in a link in an access gateway.</figref><figref num="10">FIG. 6 is a block diagram of a computer environment that includes computer devices, computer program products, and computer devices that support embodiments of system components, as shown in Figure 1-9.</figref>
In certain embodiments, methods are disclosed that include receiving a resource access identifier associated with a shared computer resource such as an application, service, database, or file. This method also includes embedding a resource access identifier within a link to a shared computer resource and inserting the link within an information element. Examples of information elements include email, instant messaging, and files. This method involves associating an access control scheme with an information element to generate a protected information element, and sending the protected information element to a destination computer device.
In another particular embodiment, a system including a first computer device and a network interface is disclosed. The first computer device is configured to send and receive a request for a resource access identifier that allows access to a shared resource. The first computer device is configured to embed a resource access identifier in the link, insert the link in the information element, and associate the access control scheme with the information element. The network interface can send information elements to a second computer device. The second computer device can confirm that the access control scheme associated with the information element allows access to the information element. For example, if the access control scheme is a digital rights management (DRM) profile, the second computer device indicates that the second computer device is the owner of the shared resource, or You can see that the owner of the shared resource indicates that access to the shared resource has already been granted.
In another particular embodiment, a computer-readable medium is disclosed. The computer-readable medium, when executed by the processor of the access gateway, includes an instruction at the access gateway that causes the processor to receive a request for a cryptographic token from the first device. The requested cryptographic token allows the shared resource located on the file server to be accessed via the access gateway. The computer-readable medium also includes instructions that, when executed by the processor, cause the processor to send a cryptographic token from the access gateway to the first device. The computer-readable medium also includes an instruction at the access gateway that, when executed by the processor, causes the processor to receive an attempt from a second device to access a shared resource using a cryptographic token. The computer-readable medium also includes instructions that, when executed by the processor, facilitate the processor access to the shared resources by the second device through the gateway.
FIG. 1 shows a block diagram of a particular embodiment of access control system 100 using an identifier within a link. System 100 includes shared computer resources 102 and one or more computer devices. For example, in the particular embodiment shown in FIG. 1, system 100 includes a first computer device 110 and a second computer device 130. The shared computer resource 102 may be a file, application, service, database, or any other computer resource. The shared computer resource 102 can be accessed by both the first computer device 110 and the second computer device 130. In certain embodiments, the shared computer resource 102 is accessible by the first computer device 110 and the second computer device 130 via the network 104. For example, network 104 includes LAN (local area network) and WAN (wide area). network) or the internet. In certain embodiments, the shared computer resource 102 may be located on a file server, application server, or database server accessible via network 104.
The first computer device 110 transmits data to the second computer device 130 via the network interface 118 (eg, a protected information element 120 containing a resource access identifier 124 embedded in link 122). Can be configured to. By way of example, but not limited to, the protected information element 120 can be an email, an instant message, or a file. System 100 of FIG. 1 can provide access control using an identifier (eg, resource access identifier 124) within a link (eg, link 122).
The first computer device 110 is configured to request and receive the resource access identifier 124 associated with the shared computer resource 102. In certain embodiments, the resource access identifier 124 is associated with the shared computer resource 102 and is used to access the shared computer resource 102. The first computer device 110 may also include various logic modules that are configured to perform a particular function in the first computer device 110. For example, the first computer device 110 may include logic 112 that embeds a resource access identifier in a link, logic 114 that inserts a link in an information element, and logic 116 that associates an access control scheme with an information element. it can. In certain embodiments, the logic 116 that associates the access control scheme with the information element can be configured to associate the access control scheme with the information element to generate the protected information element 120. For example, logic 116 that associates an access control scheme with an information element can request the DRM server to generate a DRM profile for the information element. The first computer device 110 can transmit the protected information element 120 to the second computer device 130 via the network interface 118.
The protected information element 120 includes link 122, and the resource access identifier 124 is embedded within link 122. In certain embodiments, the protected information element 120 can be an email, instant message, or file, and the access control scheme can be a digital rights management (DRM) profile. In another particular embodiment, link 122 is a URL (uniform resource). It can be a locator), and the resource access identifier 124 can be a random cryptographic token embedded in the URL as a parameter of the URL. For example, if shared computer resource 102 is a document with the URL "https://fileserver.enterprise.com/viewfile.action?filename=businessplan.doc" and the resource access identifier is the random crypto token "cvtjofttqmbo", it is protected. The URL inserted in the information element can be "https://fileserver.enterprise.com/viewfile.action?filename=businessplan.doc&RA ID=cvtjofttqmbo".
The second computer device 130 may be configured to receive the protected information element 120 from the first computer device via the network interface 132. The second computer device 130 may also include various logical modules configured to perform a particular function. For example, the second computer device 130 may include logic 134 that confirms that the access control scheme allows access to the information element, and logic 136 that extracts the resource access identifier from the link. The second computer device 130 may be configured to access the shared computer resource 102 using the received resource access identifier 124.
In operation, the first computer device 110 may choose to allow the second computer device 130 to access the shared computer resource 102. To do so, the first computer device 110 can request and receive the resource access identifier 124 associated with the shared computer resource 102 from the shared computer resource 102. Upon receiving the resource access identifier 124, the logic 112 that embeds the resource access identifier in the link at the first computer device 110 can embed the resource access identifier 124 in the link 122. The logic 114 that inserts the link inside the information element can insert the link 122 (including the resource access identifier 124 embedded in it) inside the information element.
In certain embodiments, any computer device that has a link 122 that includes a resource access identifier 124 or a resource access identifier 124 can be used because the resource access identifier 124 can be used to access the shared resource 102. , Shared computer resource 102 may be accessible. Logic that associates an access control scheme with an information element on first computer device 110 to maintain specific control over which device may access the information element to extract link 122 or resource access identifier 124. 116 can associate an access control scheme with an information element to generate a protected information element 120. In certain embodiments, the access control scheme can include a list of devices that may access the protected information element 120. For example, the access control scheme can specify that the second computer device 130 may access the protected information element 120. Prevent unauthorized redistribution of protected information element 120 by using an access control scheme to prevent unauthorized recipients of protected information element 120 from accessing shared resource 102. You can also do it. The first computer device 110 can transmit the protected information element 120 to the second computer device 130 via the network interface 118.
Upon receiving the protected information element 120, the logic 134 confirms that the access control scheme allows access to the information element, the access control scheme associated with the protected information element 120 is the second. It can be confirmed that the computer device 130 enables access to the protected information element 120. For example, the logic 134 that verifies that the access control scheme allows access to the information element is listed in the access control scheme that the second computer device 130 is associated with the protected information element 120. You can confirm that you are there. If the second computer device 130 is listed in the access control scheme associated with the protected information element 120, the logic 136 that extracts the resource access identifier from the link is in the protected information element 120. The resource access identifier 124 can be extracted from the link 122 of. For example, in the above embodiment, the logic 136 that extracts the resource access identifier from the link uses the encryption token "cvtjofttqmbo" as the URL "https://fileserver.enterprise.com/viewfile.action?filename=businessplan.doc&RA ID=cvtjofttqmbo". Can be extracted from. The second computer device 130 can then access the shared computer resource 102 using the resource access identifier 124. In certain embodiments, instead of extracting the resource access identifier 124 from the link 122, the second computer device 130 can simply access the shared computer resource 102 via the link 122. The reason is that the resource access identifier 124 is embedded within the link 122. For example, the second computer device is simply the link "https://fileserver.enterprise.
In system 100 of FIG. 1, a computer device having access to a shared computer resource (eg, shared computer resource 102) selectively grants other computer devices access to the shared computer resource. It will be understood to make it possible. It is understood that System 100 in Figure 1 simplifies resource sharing by embedding a resource access identifier within the link to the resource, eliminating the need for shared computer resources to hold an access list. Will. Moreover, if the protected information element is accidentally transferred to an unauthorized computer device, this does not create a security issue. The reason is that unauthorized computer devices cannot access the protected information element because the unauthorized computer device is not in the access control scheme associated with the protected information element.
FIG. 2 is a block diagram of a particular embodiment of a resource access identifier 200 that can be used to perform access control using an identifier within a link. In an exemplary embodiment, the resource access identifier 200 includes the resource access identifier 124 of FIG.
The resource access identifier 200 can include information associated with the entity requesting the resource access identifier 200. For example, the resource access identifier 200 can include information 202 associated with the requesting computer device, information 204 associated with the requesting user, or any combination thereof. The information 202 associated with the requesting computer device can include the computer device's IP (internet protocol) address, computer device name, or any other information that can identify the computer device. The information 204 associated with the requesting user can include a user identifier, a username, a user email address, or any other information that can identify the user.
The resource access identifier 200 can also include information related to the rights granted to the receiver if the resource access identifier 200 is successfully used to access a shared computer resource. For example, the resource access identifier 200 can include read rights information 206, write rights information 208, change rights information 210, or any combination thereof. The read rights information 206 can include how many times the resource access identifier 200 can be used to read a shared computer resource and a particular portion of a shared computer resource that can be read. The write right information 208 can include how many times the resource access identifier 200 can be used to write to a shared computer resource and a particular portion of the shared computer resource that can be written. The change rights information 210 can include how many times the resource access identifier 200 can be used to change a shared computer resource and a particular portion of the shared computer resource that can be changed.
The resource access identifier 200 can also include a time stamp 212. The time stamp 212 can indicate when the resource access identifier 200 was requested, when the resource access identifier 200 was generated, or when the resource access identifier 200 was sent to the requesting computer device or user. In certain embodiments, if the resource access identifier 200 includes a time stamp 212, the resource access identifier 200 may become invalid after a predetermined period of time has elapsed from the time stamp 212. That is, the resource access identifier 200 can no longer be used to access the shared computer resource after a predetermined period of time has elapsed from the time stamp 212. For example, the resource access identifier 200 has a timestamp 212 of "January 1, 2009, 8:00 am", and the corporate security policy states that the resource access identifier may only be valid for 48 hours. If indicated, the resource access identifier 200 will be invalid at 8:00 am on January 3, 2009. If the enterprise wants to track a valid resource access identifier, setting the validity period of the resource access identifier facilitates the tracking process. The reason is that the entity only needs to track the resource access identifier for the validity period (for example, in the example above, the entity needs to track the resource access identifier 200 for only 48 hours. There will be).
The resource access identifier 200 can also include signature 214. Signature 214 can prevent unauthorized changes to the resource access identifier 200. For example, signature 214 is the first signature when the resource access identifier is generated. If the resource access identifier 200 is subsequently changed, signature 214 can automatically change from the first signature to a second signature that is different from the first signature. If the resource access identifier 200 is then used to access the shared computer resource, the access may be denied. The reason is that the signature 214 in the resource access identifier 200 does not match the first signature, that is, the signature 214 indicates that the resource access identifier 200 has been modified since it was generated. By way of example, but not limited to, signature 214 may be the hash value associated with the resource access identifier 200 or the checksum value associated with the resource access identifier 200.
In operation, the resource access identifier 200 is associated with a particular shared computer resource and is received by the first computer device that chooses to allow the second computer device to access the particular shared computer resource. sell. For example, the first computer device 110 in FIG. 1 can receive the resource access identifier 124 associated with the shared computer resource 102. After being received by the first computer device, the resource access identifier 200 may be embedded by the first computer device in a link to a particular shared computer resource. For example, the first computer device 110 in FIG. 1 can embed the resource access identifier 124 within the link 122. The resource access identifier 200 may also be used by a second computer device to access a particular shared computer resource. For example, the second computer device 130 in FIG. 1 can access the shared computer resource 102 using the resource access identifier 124.
It will be appreciated that the resource access identifier 200 can identify the device or user requesting the resource access identifier 200. If the requesting device or user is the owner of a shared computer resource associated with the resource access identifier 200, the resource access identifier 200 was transferred from one computer device to the other computer device after its generation. Even later, the resource access identifier 200 can be used to quickly identify the owner of a shared computer resource. It will also be appreciated that by including information about the right to read, write and modify, the resource access identifier 200 can eliminate the need for shared computer resources to track similar information. This reduces the amount of data and processing logic required for shared computer resources. It will also be appreciated that the resource access identifier 200 assists in security measures such as expiration dates and signatures to prevent unauthorized changes.
FIG. 3 is a block diagram of a particular embodiment of Digital Rights Management (DRM) Profile 300 that can be used in access control using identifiers within links. The DRM profile 300 contains information 302 associated with one or more owners of the information element, information 304 about one or more collaborators of the owner, and one or more access restrictions associated with the information element 306. Can be included. For example, a DRM profile can include access restrictions associated with an information element, such as whether the information element may be printed, copied, or deleted. In an exemplary embodiment, the DRM profile 300 is associated with the information element in the first computer device 110 by the logic that associates the access control scheme with the information element 116 of FIG. 1, and the protected information element 120 of FIG. To generate.
Information 302 associated with one or more owners of an information element can include an identifier associated with the user who generated the information element or an identifier associated with the computer device used to generate the information element. .. In an exemplary embodiment, the information 302 associated with one or more owners of the information element includes information indicating that the first computer device 110 in FIG. 1 is the owner of the protected information element 120. Can be done.
Information 304 about one or more collaborators of one or more owners can include an identifier associated with a user who should be granted access to the information element, rather than the owner of the information element. In an exemplary embodiment, information 304 relating to one or more collaborators of one or more owners is that the second computer device 130 of FIG. 1 is a collaborator of the first computer device 110 of FIG. , Can include information indicating that access to the information element should be granted.
The access restriction 306 associated with an information element indicates whether the owner of the information element may read, write, or modify the information element, and the collaborators of the owner of the information element provide information. It can include whether the element may be read, written, or modified. The access restriction 306 associated with an information element can include the maximum number of collaborators in the information element, how many times the information element may be transferred, and how many times the information element may be replicated. In an exemplary embodiment, the access restriction 306 associated with the information element may allow the first computer device 110 in FIG. 1 to transmit the protected information element 120 to the second computer device 130, and It can contain information indicating that the computer device 130 of 2 cannot transfer the protected information element 120.
In operation, the DRM profile 300 can be associated with a particular information element to generate a particular protected information element. For example, the owner of a resource is a list of owners (eg "Sam") and a group of owners (eg "Sales Department"), as well as a collaborator (eg "John") and a group of collaborators (eg "Financial Department"). ) Lists can be included in the DRM profile. Once generated, certain protection is provided only to the entities listed in Information 302 related to one or more owners of the information element or Information 304 related to one or more collaborators of the owner. DRM profile 300 can be used to limit access to information elements. DRM profile 300 can be used to prevent protected information elements from being improperly transferred or duplicated without permission.
It will be appreciated that the DRM profile 300 in Figure 3 can act as an access list for an information element by preventing entities that are neither owners nor collaborators from accessing the information element. When both the resource access identifier and the DRM profile 300 are embedded within the link, persistent protection of shared computer resources is achieved and the user simply extracts the link from the protected information element and is protected. It will be further understood that security cannot be circumvented simply by forwarding links that use no information elements. If the DRM profile 300 is embedded in a link with an embedded resource access identifier, it is allowed to use the "key" (ie, the embedded resource access identifier) and "key" to the shared computer resource. Both a list of people to do (ie, an embedded DRM profile) are included in the link. In certain embodiments, the DRM profile 300 is RMS (Rights Management) based on Microsoft's rights management service technology. Services) Profile.
FIG. 4 is a block diagram of another particular embodiment of access control system 400 using an identifier within a link. The system receives the first computer device 410, which is capable of transmitting the protected information element 420 to the second computer device 430, and the protected information element 420 from the second computer device 430. Includes a third computer device 450 and is capable of. The system also includes the shared computer resource 402 exemplified by the file server 404 accessible via the access gateway 460 by the first computer device 410, the second computer device 430, and the third computer device 450. In certain embodiments, the system also includes an audit engine 470 configured to receive information from the access gateway 460. In an exemplary embodiment, the first computer device 410 includes the first computer device 110 of FIG. 1, the second computer device 430 includes the second computer device 130 of FIG. 1, and the shared computer resource 402. Includes shared computer resource 102 in Figure 1. It should be noted that the particular configuration, including the computer equipment and one shared computer resource shown within the particular embodiment of FIG. 4, is merely exemplary, and the system 400 includes any number of computer equipment and It should be noted that shared computer resources may be included.
File server 404 may be configured to provide access to shared computer resource 402 through access gateway 460. In certain embodiments, file server 404 can also deny attempts to access shared resource 402 that have not been made through access gateway 460. Shared computer resource 402 in file server 404 can include files, applications, services, databases, data objects, or any other computer resource. In certain embodiments, the file server 404 may be accessible by an access gateway 460 via a network such as a LAN (local area network), WAN (wide area network) or the Internet.
The first computer device 410 may be configured to request and receive the resource access identifier 424 associated with the shared computer resource 402 in the file server 404 from the access gateway 460. The first computer device 410 embeds the received resource access identifier 424 in the link 422 to the shared computer resource 402 and inserts the link 422 in the information element (eg, email, instant message, or file). Can be configured in. The first computer device 410 may be configured to associate an access control scheme with an information element to generate a protected information element 420 and send the protected information element 420 to a second computer device 430. In an exemplary embodiment, the resource access identifier 424 comprises the resource access identifier 200 of FIG. 2, and the access control scheme comprises the DRM profile 300 of FIG.
The protected information element 420 can include the link 422 and the resource access identifier 424 can be embedded within the link 422. In an exemplary embodiment, the protected information element 420 includes the protected information element 120 of FIG. 1, the link 422 includes the link 122 of FIG. 1, and the resource access identifier 424 is the resource access identifier of FIG. Including 124.
Each of the second computer device 430 and the third computer device 450 is configured to ensure that the access control scheme associated with the protected information element 420 allows access to the protected information element 420. Can be done. In an exemplary embodiment, the second computer device 430 confirms that the information that identifies the second computer device 430 as the owner or collaborator for the protected information element 420 is in the DRM profile 300 of FIG. To do. In another exemplary embodiment, the third computer device 450 has information in the DRM profile 300 of FIG. 3 that identifies the third computer device 450 as the owner or collaborator with respect to the protected information element 420. To confirm. The second computer device 430 and the third computer device 450 are configured to use the link 422 and the resource access identifier 424 to request access to the shared computer resource 402 on the file server 404 via the access gateway 460. It may have been done.
The access gateway 460 may be configured to generate the resource access identifier 424 by the resource access identifier generation logic 462 and to transmit the generated resource access identifier 424 to the first computer apparatus 410. The access gateway 460 may be configured to receive access requests based on link 422 and resource access identifier 424 from other computer devices such as second computer device 430 and third computer device 450. The access gateway 460 may also be configured to facilitate access to the shared computer resource 402 on the file server 404 by the second computer device 430 and the third computer device 450. For example, if the shared computer resource 402 is a file, the access gateway 460 verifies that the resource access identifier 424 allows access to the shared computer resource 402, obtains a copy of the shared computer resource 402, and obtains a second copy. Send a copy of shared computer resource 402 to computer device 430 or third computer device 450. In another example, if the shared computer resource 402 is an application, service, or database, access gateway 4 60 confirms that the resource access identifier 424 allows access to the shared computer resource 402, and a second Open a network connection through access gateway 460 between computer device 430 or third computer device 450 and file server 404.
In certain embodiments where the access control scheme includes a list of devices initially allowed for a particular information element, but does not reflect subsequent changes to the list of allowed devices, the access gateway 460 cancels access. It also holds list 464. The access revocation list 464 can include a list of computer devices and users whose access to the shared computer resource 402 is prohibited even though the computer device and user have a valid resource access identifier. For example, if a third computer device 450 is listed in the access revocation list 464, an attempt by the third computer device 450 to access the shared computer resource 402 using another valid resource access identifier 424 is , Can be rejected. A particular computer device or a particular user may change the role of a particular device or user in an enterprise (for example, if a particular computer is no longer assigned to the owner of a particular resource, or a particular user). May be added to the access revocation list 464) when is no longer working in a group that needs access to a particular resource. Certain computer devices or certain users are on the access revocation list as a result of changes in the company's security policy (for example, a policy decision that users outside the company's financial department can no longer access payroll records). May be added.
In certain embodiments, system 400 of FIG. 4 assists in auditing and keeps track of resource access identifier requests and attempts to access shared computer resources using resource access identifiers. Audit engines such as the audit engine 470 can perform audits. If the system 400 of FIG. 4 includes an audit engine 470, the access gateway 460 may be configured to send one or more audit messages 466 to the audit engine 470. In certain embodiments, the access gateway 460 audits audit message 466 each time a resource access identifier is requested from the access gateway 460 and each time an attempt to access a shared computer resource is received at the access gateway 460. Send to engine 470. For example, in the access gateway 460, when the first computer device 410 requests the resource access identifier 424, the second computer device 430 attempts to access the shared computer resource 402, and the third computer device 450 Audit message 466 can be sent to audit engine 470 when attempting to access shared computer resource 402. In certain embodiments, the audit engine 470 is located at the access gateway 460 and the audit message 466 is an internal message of the access gateway 460.
Audit engine 470 can include audit log 472. In certain embodiments, audit log 472 makes an entry for resource access identifier request 473, successful resource access attempt 474, and failed resource access attempt 475, based on audit message 466 received from access gateway 460. Including. For example, an entry for resource access identifier request 473 can be generated when the first computer unit 410 requests resource access identifier 424 from access gateway 460, and an entry for successful resource access attempt 474 is for the second. Computer device 430 and third computer device 450 can be generated when the shared computer resource 402 is accessed through the access gateway 460. In the above example where the third computer device 450 is listed in the access revocation list 464, the entry to the failed resource access attempt 475 is that the access gateway 460 is to the shared computer resource 402 by the third computer device 450. Can be generated if an access attempt is denied.
In operation, the first computer device 410 may allow the second computer device 430 to access the shared computer resource 402 on the file server 404. To do so, the first computer unit 410 requests the resource access identifier from the access gateway 460 associated with the shared computer resource 402. In response to receiving a request from the first computer device 410, the access gateway 460 uses the resource access identifier generation logic 462 to generate the resource access identifier 424 and transfers the resource access identifier 424 to the first computer device 410. Can be sent. In certain embodiments, the access gateway 460 may reject this request if the first computer device 410 is listed in the access revocation list 464. By doing so, the access gateway 460 can prevent a computer device whose access right to the shared computer resource 402 that it owned has been revoked from allowing another computer device to access the shared computer resource 402. The access gateway 460 can also send one or more audit messages 466 to the audit engine 470 indicating that the first computer unit 410 has requested the resource access identifier 424, which is one of the audit logs 472. The corresponding entry for request 473 of the part resource access identifier can be generated.
The first computer device 410 embeds the received resource access identifier 424 in the link 422 to the shared computer resource 402, inserts the link 422 in the information element, and protects the access control scheme in association with the information element. The information element 420 can be generated and the protected information element 420 can be transmitted to the second computer device 430. In certain embodiments, the resource access identifier 424 is a random cryptographic token, the link 422 is a URL, and the random cryptographic token is embedded within the URL as a parameter of the URL. In another particular embodiment, the access control scheme associated with the protected information element 420 can be a DRM profile such as the DRM profile 300 of FIG. For example, in the example illustrated with reference to Figure 1, a URL with an embedded cryptographic token (ie, "https://fileserver.enterprise.com/viewfile.action?filename=businessplan.doc&RA" ID = cvtjofttqmbo ") is inserted in the email, the email is protected by the DRM profile, and the email can be sent. In certain embodiments, email protection using a DRM profile can encrypt email as described in more detail with reference to FIG. In another particular embodiment, the resource access identifier 424 is a collaboration application (email application, document processing application, spreadsheet application, presentation application, web browser, file sharing application, or Can be requested, received and embedded by (multimedia applications).
Upon receiving the protected information element 420, the second computer device 430 has access control schemes associated with the protected information element 420 that allow the second computer device 430 to access the protected information element 420. You can see what makes it possible. For example, the second computer device 430 detects that the protected information element 420 is encrypted and obtains a decryption key, as described in more detail with reference to FIG. The email can be decrypted. If the access control scheme allows access, the second computer unit 430 can request the access gateway 460 to provide access to the shared computer resource 402 using the resource access identifier 424, which allows access. Gateway 460 can facilitate access to shared computer resource 402. In certain embodiments, the access gateway 460 facilitates access to the shared computer resource 402 if the second computer device 430 is not listed in the access revocation list 464 and is accessed by the second computer device 430. Access to shared computer resource 402 can be denied if it is listed in Cancellation List 464. The access gateway 460 can also send one or more audit messages 466 to the audit engine 470 indicating whether the second computer unit 430 succeeded or failed to access the shared computer resource 402, the audit engine 470. Can generate a corresponding entry within the part of the successful resource access attempt 474 or the part of the unsuccessful resource access attempt 475 of audit log 472.
The second computer device 430 can also transfer the protected information element 420 to the third computer device 450. Upon receiving the protected information element 420, the third computer device 450 uses the access control scheme associated with the protected information element 420 to access the protected information element 420 by the third computer device 450. Can be confirmed to enable. If the access control scheme allows access, the third computer unit 450 can use the resource access identifier 424 to request access to the shared computer resource 402 from the access gateway 460, and the access gateway 460. Facilitates access to shared computer resource 402. In certain embodiments, the access gateway 460 facilitates access to the shared computer resource 402 if the third computer device 450 is not listed in the access revocation list 464 and is accessed by the third computer device 450. Denies access to shared computer resource 402 if it is listed in Cancellation List 464. The access gateway 460 can also send one or more audit messages 466 to the audit engine 470 indicating whether the third computer unit 450 succeeded or failed to access the shared computer resource 402, the audit engine 470. Can generate a corresponding entry within the part of the successful resource access attempt 474 or the part of the unsuccessful resource access attempt 475 of audit log 472.
It will be appreciated that System 400 in Figure 4 allows resource access identifiers to be transferred between different collaborators. It will also be appreciated that System 400 in Figure 4 can keep up with changes in user roles and organizational policies, as System 400 in Figure 4 allows access to be revoked. System 400 in Figure 4 assists in auditing how often, in what manner, and by whom shared resources are accessed, and provides transparency and accountability in the process of resource sharing. It will also be understood to assist in providing. In addition, System 400 in Figure 4 allows resource owners to determine which users or devices may access the resource, resulting in an improved need while maintaining the security policy of the entire enterprise. -Bring a to-know procedure.
FIG. 5 is a block diagram of another particular embodiment of access control system 500 using an identifier within a link. The system 500 of FIG. 5 has a first computer device 510 capable of transmitting the protected information element 520 to the second computer device and a third computer device 510 capable of receiving the protected information element 520 from the second computer device 530. Includes computer equipment 550. The system can receive DRM requests from each of the first computer device 510, the second computer device 530, and the third computer device 550 and send a DRM response to each of them Digital Rights Management (DRM). Also includes server 540. In an exemplary embodiment, the first computer device 510 is the first computer device 410 in FIG. 4, the second computer device 530 is the second computer device 430 in FIG. 4, and the third computer. The device 550 is the third computer device 450 of FIG.
The first computer device 510 provides the DRM server 540 with a list of devices permitted for the protected information element 520, and the protected information element 520 including a list of permitted devices. Protected information element 520 can be generated by requiring the DRM server to generate a DRM profile. In certain embodiments, the DRM profile can include the DRM profile 300 of FIG. The protected information element 520 can include a link 522 to the shared computer resource and a resource access identifier 524 associated with and embedded within the link 522. In an exemplary embodiment, the protected information element 520 is the protected information element 420 of FIG. 4, the link 522 is the link 422 of FIG. 4, and the resource access identifier 524 is the resource access identifier 424 of FIG. Is.
Both the second computer device 530 and the third computer device 550 make sure that the DRM profile associated with the protected information element 520 allows access to the protected information element 520. Can be configured in. In an exemplary embodiment, the second computer device 530 associates information that identifies the second computer device 530 as either the owner or collaborator with respect to the protected information element 520 with the protected information element 520. You can see that it is shown in the DRM profile shown. In another exemplary embodiment, the third computer device 550 has information that identifies the third computer device 550 as either the owner or collaborator with respect to the protected information element 520, the protected information element 520. You can see that it is shown in the DRM profile associated with.
The DRM server 540 can be configured to receive DRM requests and send DRM responses. A DRM request can include a list of authorized devices, a request to generate a DRM profile for the information element, or a request to confirm that a particular computer device is authorized to access the protected information element. .. The DRM response indicates that a DRM profile for a particular information element is being generated on the DRM server 540, whether a particular computer device is allowed access to the protected information element, and protection. It can contain one or more access restrictions on the information elements that have been made.
In operation, the first computer device 510 may choose to associate the information element with the DRM profile to generate a protected information element 520. To do so, the first computer device 510 can send a request to the DRM server 540 requesting that the information element generate a DRM profile, which grants access to the information element. Includes a list of devices that have been made. In response to receiving the request, the DRM server 540 generates a DRM profile for the information element and is used to encrypt the information element on the first computer device 510 to generate the protected information element 520. It is possible to send a DRM response containing a valid encryption key. The first computer device 510 can then transmit the protected information element 520 to the second computer device 530.
Upon receiving the protected information element 520, the second computer device 530 can determine that the protected information element 520 is encrypted and sends a DRM request for the decryption key to the DRM server 540. be able to. The DRM server 540 may receive a DRM request for the decryption key from the second computer device 530 to determine if the second computer device 530 is listed in the DRM profile for the protected information element 520. it can. In certain embodiments, the DRM server 540 determines that the second computer device 530 is allowed access to the protected information element 520 and sends a DRM response containing the decryption key to the second computer device. Send to 530. In another particular embodiment, the DRM server 540 determines that the second computer device 530 is not authorized to access the protected information element 520 and sends a DRM response indicating access denial. ..
The second computer device 530 can transfer the protected information element 520 to the third computer device 550. Upon receiving the protected information element 520, the third computer device 550 can determine that the protected information element 520 is encrypted and sends a DRM request for the decryption key to the DRM server 540. be able to. The DRM server 540 can receive a DRM request for the decryption key from the third computer device 550 and determines if the third computer device 550 is listed in the DRM profile for the protected information element 520. be able to. In certain embodiments, the DRM server 540 determines that the third computer device 550 is authorized to access the protected information element 520 and sends a DRM response containing the decryption key to the third computer device. Send to 550. In another particular embodiment, the DRM server 540 determines that the third computer device 550 is not authorized to access the protected information element 520 and sends a DRM response indicating access denial. ..
It will be understood that the system 500 in FIG. 5 centralizes access control of information elements in the DRM server and simplifies the logic in the computer equipment. For example, if the DRM server 540 in Figure 5 is used, the logic for associating the access control scheme with the information element 116 in Figure 1 simply sends a DRM request to the DRM server 540 and associates the DRM profile with the information element. It is possible to confirm that the DRM profile association requested by receiving the DRM response from the DRM server 540 is completed.
FIG. 6 is a flow diagram of a specific embodiment of the access control method 600 using the identifier in the link. In an exemplary embodiment, the method can be performed by a computer such as the first computer device 110 in FIG. 1, the first computer device 410 in FIG. 4, or the first computer device 510 in FIG. Method 600 includes receiving the resource access identifier associated with the shared computer resource at reference number 602. For example, in FIG. 1, the first computer device 110 can receive the resource access identifier 124 associated with the shared computer resource 102. Method 600 also includes embedding the resource access identifier within the link to the shared computer resource at reference number 604 and inserting the link within the information element at reference number 606. For example, in FIG. 1, the first computer device 110 can embed the resource access identifier 124 in the link 122 to the shared computer resource 102 and insert the link 122 in the information element.
Method 600 also includes associating an access control scheme with the information element at reference number 608 to generate a protected information element. For example, in FIG. 1, the first computer device 110 can associate an access control scheme with an information element that includes a link 122 with an embedded resource access identifier 124 to generate a protected information element 120. .. Method 600 also includes sending the protected information element at reference number 610 to the destination computer device. For example, in FIG. 1, the first computer device 110 can transmit the protected information element 120 to the second computer device 130 via the network interface 118.
It will be appreciated that Method 600 in Figure 6 enables access control using identifiers within the link. It will also be appreciated that method 600 of FIG. 6 achieves access control without transmitting shared computer resources from one computer device to the other. Instead, a protected information element that is a link with an embedded resource access identifier and contains a link to a shared computer resource is transmitted. For example, instead of transmitting multiple shared documents, an email or instant message that is a link with an embedded resource access identifier and contains one or more links to the shared document may be transmitted. Since information elements are usually significantly smaller than shared resources, this reduces the amount of data transmitted between computer devices to achieve access control.
FIG. 7 is a flow diagram of another particular embodiment of access control method 700 using an identifier within a link. In an exemplary embodiment, the method can be performed by a computer device such as the first computer device 110 in FIG. 1, the first computer device 410 in FIG. 4, or the first computer device 510 in FIG. Method 700 includes receiving a resource access identifier associated with a shared computer resource at reference number 702. For example, in FIG. 4, the first computer apparatus 410 can receive the resource access identifier 424 associated with the shared computer resource 402 from the access gateway 460. Method 700 also includes embedding the resource access identifier at reference number 704 in the URL to the shared computer resource as a parameter of that URL. For example, in FIG. 4, the first computer device 410 can embed the resource access identifier 424 as a parameter of link 422 in link 422, where link 422 is a URL. This method also includes inserting the URL into an information element (eg, email, instant message, or file) at reference number 706. For example, the first computer device 410 in FIG. 4 can insert a URL into an information element.
Method 700 also includes associating a digital rights management (DRM) profile with an information element at reference number 708 to generate a protected information element. For example, the first computer device 410 in FIG. 4 can generate the protected information element 420 in FIG. 4 by requiring the DRM server 540 in FIG. 5 to generate a DRM profile for the information element. .. This method also includes embedding the DRM profile in the URL at reference number 710. For example, the first computer device 410 in FIG. 4 can receive the generated DRM profile from the DRM server 540 in FIG. 5, and can embed a copy of the DRM profile 300 in FIG. 3 in the URL. Method 700 also includes sending the protected information element at reference number 712 to the destination computer device. For example, in FIG. 4, the first computer device 410 can transmit the protected information element 420 to the second computer device 430.
It will be appreciated that Method 700 in Figure 7 provides lasting protection for shared computer resources accessible through the URL by embedding both the resource access identifier and the DRM profile within the URL. .. In certain embodiments, the resource access identifier and DRM profile can be combined and embedded within the link as a join parameter to the URL, so that the resource access identifier is extracted from the link without the DRM profile being extracted. Not so, and vice versa. By preventing one of the resource access identifier and DRM profile from being extracted without the other being extracted, method 700 in FIG. 7 allows the user to simply extract the resource access identifier from the link. You can prevent circumventing security by inserting that resource access identifier into a new link and forwarding the new link in an unprotected information element.
FIG. 8 shows a flow diagram of a particular embodiment of method 800 for implementing access control using an identifier in a link at an access gateway. In an exemplary embodiment, method 800 can be performed by the access gateway 460 of FIG. Method 800 includes receiving a request at reference number 802 for a cryptographic token that allows access to a shared resource located on a file server through an access gateway. This request is sent by the first device and received at the access gateway. For example, in FIG. 4, the access gateway 460 can receive a request for the resource access identifier 424 from the first computer device 410, where the resource access identifier 424 is a cryptographic token. Method 800 also includes sending a cryptographic token from the access gateway to the first device at reference number 804. For example, in FIG. 4, the access gateway 460 can send the resource access identifier 424 (eg, a cryptographic token) to the first computer device 410. Method 800 also includes receiving at the access gateway an attempt to access a shared resource using a cryptographic token from a second computer device at reference number 806. For example, in FIG. 4, the access gateway 460 can receive an access request from the second computer device 430, and the access request is generated using the resource access identifier 424, which is a cryptographic token. Method 800 also includes facilitating access to the shared lease by the second device through the access gateway at reference number 808. For example, in FIG. 4, the access gateway 460 can facilitate access between the second computer device 430 and the shared resource 402 via the access gateway 460.
Method 800 in Figure 8 gives the access gateway to the shared resource because the access gateway is capable of both generating a resource access identifier for the shared resource and facilitating access to the shared resource. It will be appreciated that it makes it possible to control access. Since cryptographic tokens are difficult to decrypt, it will be appreciated that Method 800 in Figure 8 adds security to the resource identifier by generating the resource access identifier as a cryptographic token.
FIG. 9 is a flow diagram of another particular embodiment of method 900 for implementing access control using an identifier within a link at an access gateway. In an exemplary embodiment, method 900 can be performed at access gateway 460 in FIG. Method 900 includes receiving a request at reference number 902 for a cryptographic token that allows access to a shared resource located on a file server through an access gateway. The request is sent by the first cooperating application in the first device and received by the access gateway. Collaborative applications include, but are not limited to, e-mail applications, document processing applications, table computing applications, presentation applications, web browsers, file sharing applications, and multimedia applications. For example, in FIG. 4, the access gateway 460 can receive a request for the resource access identifier 424 from the first cooperating application in the first computer device 410. Method 900 also includes sending a cryptographic token from the access gateway to the first device at reference number 904. For example, in FIG. 4, the access gateway 460 can transmit the resource access identifier 424 to the first computer device 410.
Method 900 also includes receiving at reference number 906 an attempt to access a shared resource using a cryptographic token at the access gateway. This request is transmitted by a second cooperating application in the second device. For example, in FIG. 4, the access gateway 460 can receive an access request from a second cooperating application in the second computer device 430, where the access request uses the resource access identifier 424.
Method 900 includes determining at reference number 908 whether the second device is listed in the access revocation list. In certain embodiments, the access revocation list can include a list of users, a list of devices, a list of corporate job titles, or any combination thereof. For example, in FIG. 4, the access gateway 460 can determine whether the second computer device 430 is listed in the access revocation list 464. If it is determined that the second device is listed in the access revocation list, method 900 proceeds to reference number 914, where an attempt to access a shared resource that uses a cryptographic token is denied. For example, in FIG. 4, if the second computer device 430 is listed in the access revocation list 464, the access gateway 460 denies the access request from the second cooperating application on the second computer device 430. can do.
If it is determined that the second device is not listed in the access revocation list, method 900 proceeds to reference number 910 to determine if the cryptographic token contains a time stamp. For example, in FIG. 4, if the second computer device 430 is not listed in the access cancellation list 464, the access gateway 460 determines whether the resource access identifier includes a time stamp such as the time stamp 212 in FIG. be able to. If it is determined that the cryptographic token does not contain a time stamp, method 900 proceeds to reference number 916 and access to the shared resource by the second device is facilitated through the access gateway. For example, in FIG. 4, if the resource access identifier 424 does not include the time stamp 212 of FIG. 2, the access gateway 460 facilitates access to the shared computer resource 402 by the second computer apparatus 430 via the access gateway 460. Can be.
If it is determined that the cryptographic token contains a time stamp, method 900 proceeds to reference number 912 and includes determining if the validity period has expired. For example, in FIG. 4, if the resource access identifier 424 includes the time stamp 212 of FIG. 2, the access gateway 460 depends on whether the validity period from the time shown in the time stamp 212 of FIG. 2 has elapsed. It can be determined whether the resource access identifier 424 has elapsed. If it is determined that the validity period has expired, Method 900 ends with reference number 914 and attempts to access the shared resource using crypto tokens are denied. For example, when the validity period has expired, the access gateway 460 of FIG. 4 can deny the access request from the second cooperating application in the second computer device 430. If it is determined that the validity period has not expired, Method 900 ends with reference number 916 by facilitating access to the shared resource by the second device through the access gateway. For example, in FIG. 4, if the predetermined validity period has not elapsed, the access gateway 460 can facilitate access to the shared computer resource 402 by the second computer device 430 via the access gateway 460.
It will be appreciated that Method 900 in Figure 9 allows the resource owner to revoke the prior permission to access the shared resource by using the access revocation list. Method 900 in Figure 9 allows the automatic expiration of a resource access identifier, so that the resource owner is the "old" resource access used by someone who would no longer be a collaborator of the resource owner. You don't have to worry about identifiers.
FIG. 10 shows a block diagram of computer environment 1000, which includes computer equipment 1010, computer program products, and system components according to the present disclosure that can assist in embodiments of computer implementation methods. In an exemplary embodiment, the computer apparatus 1010 can include an access gateway such as the access gateway 460 of FIG. In another exemplary embodiment, the computer apparatus 1010 can include the computer apparatus 110 or 130 of FIG. 1, the computer apparatus 410, 430 or 450 of FIG. 4, and the computer apparatus 510, 530 or 550 of FIG. In another exemplary embodiment, the computer apparatus 1010 can include the DRM server 540 of FIG. For example, the computer device 1010 can be a desktop computer, a laptop computer, a collaboration server, a personal digital assistant, or a mobile communication device.
Computer equipment 1010 typically includes at least one processor 1020 and system memory 1030. Depending on the exact configuration and type of access gateway, system memory 1030 stores volatile (random access memory or RAM, etc.), non-volatile (read-only memory or ROM, flash memory, and even when power is not provided. It can be a similar memory device that keeps the data in place, etc.), or some combination of the two. System memory 1030 typically includes operating system 1032, one or more application platforms 1034, one or more applications 1036, and can include program data 1038. In certain embodiments, the system memory 1030 can include the resource access identifier generation logic 462 of FIG. 4 and the access revocation list 464 of FIG.
Computer device 1010 can also have additional features or functions. For example, computer device 1010 can include removable and / or non-detachable additional data storage devices such as magnetic disks, optical disks, tapes, and standard size or small flash memory cards. Such additional storage media are shown in FIG. 10 by the removable storage medium 1040 and the non-detachable storage medium 1050. Computer storage media are volatile and / or non-volatile, as well as removable and / or removable, implemented in any method or technique for storing information such as computer-readable instructions, data structures, program components or other data. Can include non-volatile media. The system memory 1030, the removable storage medium 1040, and the non-detachable storage medium 1050 are all examples of computer storage media. Computer storage media are not limited, but are RAM, ROM, and EEPROM (electrically erasable programmable read-only). memory), flash memory or other memory technology, CD (compact disk), DVD (digital versatile disk) or other optical storage medium, magnetic cassette, magnetic tape, magnetic tissue storage medium or other magnetic storage medium device, or Includes any other medium that can be used to store the desired information and is accessible by computer device 1010.
Computer device 1010 allows one or more communication connections that allow computer device 1010 to communicate with one or more client computer systems or other computer devices 1070, such as other servers, over a wired or wireless network. Including 1060. In certain embodiments where the computer device 1010 includes an access gateway 460, the computer device 1010 is a first computer 410 in FIG. 4, a second computer device 430 in FIG. 4, a third computer device 450 in FIG. 4, FIG. It can communicate with 4 file servers 404 and the audit engine 470 in Figure 4. One or more communication connections 1060 is an example of a communication medium. By way of example, but not limited to, communication media can include wired networks such as wired networks, i.e. direct wired connections, as well as wireless media such as acoustic, RF, infrared, and other wireless media. .. However, it will be understood that not all of the components or devices described in FIG. 10 or described in the paragraph above are required to support the embodiments described herein. ..
The description of the embodiments described herein is intended to provide an overall understanding of the structure of the various embodiments. This description is not intended to provide a complete description of all the elements and features of the devices and systems that utilize the structures or methods described herein. Many other embodiments will be apparent to those skilled in the art who have referred to this disclosure. Other embodiments may be utilized and may be derived from the present disclosure, and structural and logical substitutions and modifications may be made without departing from the scope of the present disclosure. Therefore, the disclosure and drawings should be considered exemplary rather than limiting.
Those skilled in the art will appreciate the various exemplary logical blocks, configurations, modules, circuits, algorithm steps described in connection with the embodiments disclosed herein, including electronic hardware, computer software, or both. It will further clarify that it may be implemented as a combination. To articulate compatibility between this hardware and software, various exemplary components, blocks, configurations, modules, circuits, or steps have been generally described for these features. Whether such functionality is implemented in hardware or as software depends on the specific application or design constraints given to the entire system. Those skilled in the art may implement the features described in various ways for each particular application, but such implementation decisions should not be construed as causing deviations from the scope of this disclosure. ..
The steps of the method described in relation to the embodiments disclosed herein are either embodied directly in hardware, embodied in a software module executed by a processor, or. It may be embodied in a combination of these two. Software modules include RAM (random access memory), flash memory, ROM (read only memory), registers, hard disks, removable disks, CD-ROMs, or any other type of storage medium known in the art. It may be in a computer-readable medium of. Since the exemplary storage medium is coupled with the processor, the processor is capable of reading information from the storage medium and writing information to the storage medium. In an alternative example, the storage medium may be integral to the processor, or the processor and storage medium may be present as separate components within the access gateway or computer system.
Although specific embodiments have been exemplified and described herein, any configuration designed and later devised to achieve the same or similar objectives is a particular embodiment set forth herein. May be replaced with morphology. The present disclosure is intended to include any and all subsequent indications or variations of various embodiments.
The abstracts of this disclosure are provided with the understanding that they are not used to interpret or limit the scope or meaning of the claims. In addition, in embodiments for carrying out the invention described above, various features may be grouped or described within a single embodiment to simplify the disclosure. The present disclosure should not be construed as indicating that embodiments of the present invention require more features than those explicitly listed in each claim. Rather, as the appended claims indicate, the invention can cover less than all of the features of any of the disclosed embodiments.
The above description of the embodiments of the present disclosure is provided to allow one of ordinary skill in the art to carry out or use the embodiments of the present disclosure. Various variations on these embodiments are readily understood by those of skill in the art and the overall principles set forth herein are applicable to other embodiments without departing from the scope of the present disclosure. It may be. Therefore, this disclosure is not intended to be limited to the embodiments set forth herein, but with the broadest scope consistent with the principles and novel features defined by the appended claims. It should be.
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP11237969A | Cites | Japan |
| JP2007149010A | Cites | Japan |
| JP2005157881A | Cites | Japan |
| US20050120211A1 | Cites | United States of America |
| US20080027868A1 | Cites | United States of America |
| US20080154778A1 | Cites | United States of America |
12 members in 5 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 12396500 | United States of America | – | |
| 39650009 | United States of America | A | |
| 39650009 | United States of America | A | |
| 12396500 | – | – | – |
| US20090396500 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| US2010228989A1 | United States of America | A1 | |
| WO2010101788A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2010101788A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP2404258A2 | European Patent Office (EPO) | A2 | |
| CN102341807A | China | A | |
| JP2012519906A | Japan | A | |
| EP2404258A4 | European Patent Office (EPO) | A4 | |
| US8719582B2 | United States of America | B2 | |
| CN102341807B | China | B | |
| JP2015146208A | Japan | A | |
| JP5980366B2This record | Japan | B2 | |
| EP2404258B1 | European Patent Office (EPO) | B1 |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 5980366
- Publication, DOCDB
- 5980366
- Publication, EPODOC
- JP5980366B
- Application
- 62493
- Application, DOCDB
- 2015062493
- Application, EPODOC
- JP20150062493
Titles2
- Japanese
- リンク内の識別子を使用したアクセス制御
- English
- Access control using identifiers in links
Classification
- CPC, 13
- G06F21/10
- G06F2221/2101
- G06F2221/2137
- G06F2221/2151
- H04L9/3213
- H04L9/3271
- H04L9/3297
- H04L2209/603
- G06F21/6209
- G06Q20/341
- G07F7/1008
- H04L63/0428
- H04L63/083
- IPC, 2
- G06F21 62
- G06F21 10
