US2007157297A1PendingUtilityA1

System and method for server security and entitlement processing

Assignee: BEA SYSTEMS INCPriority: Jun 11, 2001Filed: Mar 14, 2007Published: Jul 5, 2007
Est. expiryJun 11, 2021(expired)· nominal 20-yr term from priority
Inventors:Paul Patrick
G06F 2221/2145G06F 21/6245G06F 2221/2141
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A pluggable architecture allows security and business logic plugins to be inserted into a security service hosted by a server, and to control access to one or more secured resources on that server, on another server within the security domain, or between security domains. The security service may act as a focal point for security enforcement, and access rights determination, and information used or determined within one login process can flow transparently and automatically to other login processes. Entitlements denote what a particular user may or may not do with a particular resource, in a particular context. Entitlements reflect not only the technical aspects of the secure environment (the permit or deny concept), but can be used to represent the business logic or functionality required by the server provider. In this way entitlements bridge the gap between a simple security platform, and a complex business policy platform.

Claims

exact text as granted — not AI-modified
1 . A method for determining user entitlements to access protected resources in a secure environment, comprising: 
 receiving an access request from a user application to access a protected resource, by invoking a security service with the access request and a callback;    determining user entitlements to access the protected resource, wherein the determining includes polling a plurality of security providers that may be plugged into the security service, and wherein the plurality of security providers use a callback handler to request context information from an application container for the access request;    making a decision at the security service based on the user entitlements to permit or deny the access request; and    the steps of either 
 (a) communicating a permitted access request to the protected resource, or  
 (b) denying a denied access request to the protected resource.  
   
   
   
       2 . The method of  claim 1  wherein if the access request is permitted, user entitlements also determine a type of access available to a user of the protected resource.  
   
   
       3 . The method of  claim 2  wherein the type of access includes any of view, modify, delete, or copy, any part or all of the protected resource.  
   
   
       4 . The method of  claim 1  wherein information about user entitlements can be communicated from a first security realm to a second security realm.  
   
   
       5 . The method of  claim 4  wherein additional information from a first security realm can be used to modify the user entitlements, prior to communicating the information about user entitlements from the first security realm to the second security realm.

Join the waitlist — get patent alerts

Track US2007157297A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.