Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Attribute-based access control" patented technology

Attribute-based access control (ABAC), also known as policy-based access control, defines an access control paradigm whereby access rights are granted to users through the use of policies which combine attributes together. The policies can use any type of attributes (user attributes, resource attributes, object, environment attributes etc.). This model supports Boolean logic, in which rules contain "IF, THEN" statements about who is making the request, the resource, and the action. For example: IF the requestor is a manager, THEN allow read/write access to sensitive data.

Method, apparatus, and computer-readable medium for compliance aware tokenization and control of asset value

An apparatus, computer-readable medium, and computer-implemented method to facilitate scalable compliance and issuer governance of decentralized financial transactions especially for the trade and transfer of tokenized securities. The resulting Compliance Aware Tokens contain the rulesets to restrict transactions and facilitate regulatory reporting and oversight. The embodied process, includes of a novel combination of compliance workflows, attribute verification tools, smart contracts and other ledger controls, provides a decentralized Attribute Based Access Control (ABAC) capability. ABAC patterns are extended to govern global financial transactions without the need for an active intermediary.
Owner:SECURRENCY INC

Access management for applications using attribute based access control

Systems and methods are described relating to a credential exchange service (service) for providing customizable access to protected resources. A service may receive a user token generated by an identity provider and a resource identifier and determine a set of attributes of the user based on information indicating the user's association with an account associated with the resource. The service may generate a session token for interacting with the resource by: generating a set of tags based on attributes of the user, and attaching the set of tags to the session token. Upon receiving a request to perform a first action with respect to the resource and the session token, the session token may be used to authorize the user to perform the first action by comparing the set of attributes from the set of tags from the session token to an access policy associated with the resource.
Owner:AMAZON TECH INC

Cloud disk data access control and authority management method and system based on zero-trust architecture

The invention provides a cloud disk data access control and authority management method and system based on a zero-trust architecture, and relates to the technical field of cloud computing, and the method comprises the steps: generating a real-time risk score through calculating a user access behavior deviation degree, a geographic position and a device fingerprint; reading the distributed permission strategy library in parallel by adopting a consistent Hash algorithm, and obtaining dynamic permission configuration; based on an attribute access control strategy, constructing a multi-dimensional permission decision matrix in combination with a data sensitivity label and an access environment context; and finally executing fine-grained access control and recording a verification process. According to the method, dynamic and continuous identity verification and refined authority control are realized, and the cloud disk data access security is remarkably improved.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Access management systems and methods in distributed environments

Approaches presented herein include integrating custom code and functions prior to policy invocation in a unified access management (UAM) system. UAM may be used to implement attribute based access control to evaluate different attributes for a given request. Systems and methods may call one or more dependent endpoints to execute a custom function prior to invoking a given access policy responsive to a user request. The custom function may route an input request to one or more dependent endpoints and generate a modified, enriched output. The modified, enriched output may then be provided as an input to the policy for evaluation. By using the modified, enriched output as an input attribute for the different access policies, generic policies may be established that are called and executed using a variety of different input attributes.
Owner:NVIDIA CORP

Systems and methods for attribute based access control on a data lake

Systems and methods for attribute based access control on a data lake. The systems and methods include receiving a data file and metadata associated with the data file, storing the data file in a database and storing the metadata in a data catalog. The metadata is assigned a domain access configuration and an attribute access configuration. The systems and methods further include receiving a query for the data file from a user, where the user is assigned a persona, where persona comprises a permission level. Syntax of the query is evaluated in addition to access to the query through steps including evaluating the permission level of the assigned persona against the domain access configuration and evaluating the permission level of the assigned persona against the attribute access configuration. In response to determining that the query fails to satisfy one or more of the evaluations, the query is then rejected.
Owner:WELLS FARGO BANK NA

Distributed Attribute Based Access Control as means of Data Protection and Collaboration in Sensitive (Personal) Digital Record and Activity Trail Investigations

A distributed system provides access by a principal to a resource associated with sensitive data. Micro-services in communication with an authorization engine each include a resource provider that receives a resource action request from the principal to access the resource, determines a context for the request, and transmits the context to the authorization engine in an authorization request. The authorization engine receives the authorization request, resolves the authorization request context against a plurality of pre-defined resource conditions, and responds to the resource provider with an authorization response of allow, deny, or allow-with-conditions. The context for the request includes metadata regarding attributes of the principal, and each of the resource conditions includes a logical expression operating upon the attributes.
Owner:PROOFPOINT INC

Data processing method, system and equipment based on attribute access control and medium

The invention relates to the technical field of information security, can be applied to the field of finance, and discloses a data processing method, system and device based on attribute access control and a medium, and the method comprises the steps: constructing authorization strategies based on attribute access control based on multi-dimensional attributes of insurance services; packaging the insurance data into each standardized data product associated with each authorization strategy according to a service function; receiving an access request of a user for the target standardized data product, and performing authorization judgment on the access request according to the target authorization strategy; when access is allowed, an encrypted access token is generated and returned to the user; generating a calling log according to the access of the user, and writing the calling log into a data tracking chain which cannot be tampered; an encrypted access result that embeds the interpretive metadata is returned in response to the access. Through data productization packaging, dynamic authorization of attribute access control, non-tampering call tracking and interpretive metadata embedding, a data system which meets industry compliance requirements and supports cross-department security sharing is constructed.
Owner:PING AN TECH (SHENZHEN) CO LTD

Systems and methods for attribute based access control on a data lake

Systems and methods for attribute based access control on a data lake. The systems and methods include receiving a data file and metadata associated with the data file, storing the data file in a database and storing the metadata in a data catalog. The metadata is assigned a domain access configuration and an attribute access configuration. The systems and methods further include receiving a query for the data file from a user, where the user is assigned a persona, where persona comprises a permission level. Syntax of the query is evaluated in addition to access to the query through steps including evaluating the permission level of the assigned persona against the domain access configuration and evaluating the permission level of the assigned persona against the attribute access configuration. In response to determining that the query fails to satisfy one or more of the evaluations, the query is then rejected.
Owner:WELLS FARGO BANK NA