International Business Machines Corporation
Local evaluation of runtime authorization rules derived from externally-derived policy

Last updated:

Abstract:

An application-centric authorization model utilizes locally-evaluated rules derived from non-local policies and provided to the application via an authorization object, preferably in the subject's session context. Preferably, the approach does not involve a runtime determination regarding the policy or policies; rather, one or more existing policies are merely used to derive authorization rules associated with a subject, and which are then evaluated and enforced at runtime in a computationally-efficient manner within the local runtime context of the application or service.

Status:
Grant
Type:

Utility

Filling date:

10 May 2019

Issue date:

12 Oct 2021