Invention Grant
- Patent Title: System and method for evaluating a reverse query
-
Application No.: US14748903Application Date: 2015-06-24
-
Publication No.: US09646164B2Publication Date: 2017-05-09
- Inventor: Erik Rissanen , Pablo Giambiagi
- Applicant: AXIOMATICS AB
- Applicant Address: SE Stockholm
- Assignee: AZIOMATICS AB
- Current Assignee: AZIOMATICS AB
- Current Assignee Address: SE Stockholm
- Agency: Buchanan Ingersoll & Rooney P.C.
- Priority: SE1051394 20101230
- Main IPC: G06F17/00
- IPC: G06F17/00 ; H04L29/06 ; G06F21/62

Abstract:
Real-time techniques for determining all access requests to an attribute-based access control policy which evaluate to a given decision, “permit” or “deny”. The policy is enforced to control access to one or more resources in a computer network. In one embodiment, a method includes: (i) receiving a reverse query and a set of admissible access requests, each of which includes one or more attributes in the policy and values of these; (ii) extracting attributes to which all access requests in the set assign identical values; (iii) reducing the ABAC policy by substituting values for the extracted attributes; (iv) caching the policy as a simplified policy; (v) translating the simplified policy and the given decision into a satisfiable logic proposition; (vi) deriving all solutions satisfying the proposition; and (vi) extracting, based on the solutions, all access requests from the set for which the policy yields the given decision.
Public/Granted literature
- US20150295939A1 SYSTEM AND METHOD FOR EVALUATING A REVERSE QUERY Public/Granted day:2015-10-15
Information query