The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.
The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.
Patent No.:
Date of Patent:
Mar. 31, 2009
Filed:
Jul. 07, 2000
Eugene Amdur, Toronto, CA;
Andrew Flint, Oakville, CA;
Steven Lamb, Toronto, CA;
Steve Kotsopoulos, Toronto, CA;
Irving Reid, Toronto, CA;
C. Harald Koch, Scarborough, CA;
Andrzej Szyszkowski, Scarborough, CA;
Laryn-joe Fernandes, Ajax, CA;
Eugene Amdur, Toronto, CA;
Andrew Flint, Oakville, CA;
Steven Lamb, Toronto, CA;
Steve Kotsopoulos, Toronto, CA;
Irving Reid, Toronto, CA;
C. Harald Koch, Scarborough, CA;
Andrzej Szyszkowski, Scarborough, CA;
Laryn-Joe Fernandes, Ajax, CA;
Hewlett-Packard Development Company, L.P., Houston, TX (US);
Abstract
A security service of computer networks having a policy builder, an LDAP-compliant database, a validator and an API. The policy builder component provides a graphical user interface to be used by a policy manager to define access policies for users seeking to access network services and resources. The graphical user interface has a grid of nodes representing access policies. The grid is arranged to correspond to a defined tree structure representing services and resources and a business relationship tree structure representing users. The graphical user interface permits the policy manager to define policy builder plug-ins for access policy customization. The LDAP-compliant database maintains the policy builder plug-ins. The validator component receives requests from users and queries the LDAP-compliant database to obtain relevant access policies as defined by the policy manager. The system provides for double inheritance of access policies such that where there is no express definition of an access policy for a node, the access policies are propagated according to the hierarchical structures of the data. The validator includes validator plug-ins for carrying out access policies corresponding to the access policies defined by policy builder plug-ins.