ENHANCED SECURITY FOR COMPUTER SYSTEM RESOURCES WITH A RESIURCE ACCESS AUTHORIZATION CONTROL FACILITY THAT CREATES FILES AND PROVIDES INCREASED GRANULARITY OF RESOURCE PERMISSION
Patent №
US 6,233,576
Granted
2001-05-15
Filed 1997
Owner
INTERNATIONAL BUSINESS MACHINES CORPORATION
Lab
AI components
3
kr · planning · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
08952256
Provided is a scheme for implementing flexible control of subject authorizations (i.e. the authorizations which users or processes have) to perform operations in relation to computer resources. The methods, computer systems and authorization facilities which are provided by the invention enhance the security provisions of operating systems which have only very limited authorization facilities, by mapping the available operating system permissions to specified resource authorities for each of a set of aspects or characteristics of a computer system resource. Thus, the standard operating system permissions (e.g. read, write, execute) can have different meanings for different resource aspects, and an individual subject can have separate authorization levels set for the different resource aspects. The mappings between authorities and the available permissions may be different for different types of resources. The invention provides great flexibility in setting the authorizations that a subject may have in relation to particular resources.
AI classification
Ownership
INTERNATIONAL BUSINESS MACHINES CORPORATION
assignment · 88920977
Assignors
LEWIS, JONATHAN RHYS
On an employer assignment, the assignors are typically the inventors.