Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5 results about "Attribute-based access control" patented technology

Attribute-based access control (ABAC), also known as policy-based access control, defines an access control paradigm whereby access rights are granted to users through the use of policies which combine attributes together. The policies can use any type of attributes (user attributes, resource attributes, object, environment attributes etc.). This model supports Boolean logic, in which rules contain "IF, THEN" statements about who is making the request, the resource, and the action. For example: IF the requestor is a manager, THEN allow read/write access to sensitive data.

Cloud disk data access control and authority management method and system based on zero-trust architecture

The invention provides a cloud disk data access control and authority management method and system based on a zero-trust architecture, and relates to the technical field of cloud computing, and the method comprises the steps: generating a real-time risk score through calculating a user access behavior deviation degree, a geographic position and a device fingerprint; reading the distributed permission strategy library in parallel by adopting a consistent Hash algorithm, and obtaining dynamic permission configuration; based on an attribute access control strategy, constructing a multi-dimensional permission decision matrix in combination with a data sensitivity label and an access environment context; and finally executing fine-grained access control and recording a verification process. According to the method, dynamic and continuous identity verification and refined authority control are realized, and the cloud disk data access security is remarkably improved.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Access management systems and methods in distributed environments

Approaches presented herein include integrating custom code and functions prior to policy invocation in a unified access management (UAM) system. UAM may be used to implement attribute based access control to evaluate different attributes for a given request. Systems and methods may call one or more dependent endpoints to execute a custom function prior to invoking a given access policy responsive to a user request. The custom function may route an input request to one or more dependent endpoints and generate a modified, enriched output. The modified, enriched output may then be provided as an input to the policy for evaluation. By using the modified, enriched output as an input attribute for the different access policies, generic policies may be established that are called and executed using a variety of different input attributes.
Owner:NVIDIA CORP

Systems and methods for attribute based access control on a data lake

Systems and methods for attribute based access control on a data lake. The systems and methods include receiving a data file and metadata associated with the data file, storing the data file in a database and storing the metadata in a data catalog. The metadata is assigned a domain access configuration and an attribute access configuration. The systems and methods further include receiving a query for the data file from a user, where the user is assigned a persona, where persona comprises a permission level. Syntax of the query is evaluated in addition to access to the query through steps including evaluating the permission level of the assigned persona against the domain access configuration and evaluating the permission level of the assigned persona against the attribute access configuration. In response to determining that the query fails to satisfy one or more of the evaluations, the query is then rejected.
Owner:WELLS FARGO BANK NA

Data processing method, system and equipment based on attribute access control and medium

The invention relates to the technical field of information security, can be applied to the field of finance, and discloses a data processing method, system and device based on attribute access control and a medium, and the method comprises the steps: constructing authorization strategies based on attribute access control based on multi-dimensional attributes of insurance services; packaging the insurance data into each standardized data product associated with each authorization strategy according to a service function; receiving an access request of a user for the target standardized data product, and performing authorization judgment on the access request according to the target authorization strategy; when access is allowed, an encrypted access token is generated and returned to the user; generating a calling log according to the access of the user, and writing the calling log into a data tracking chain which cannot be tampered; an encrypted access result that embeds the interpretive metadata is returned in response to the access. Through data productization packaging, dynamic authorization of attribute access control, non-tampering call tracking and interpretive metadata embedding, a data system which meets industry compliance requirements and supports cross-department security sharing is constructed.
Owner:PING AN TECH (SHENZHEN) CO LTD

Systems and methods for attribute based access control on a data lake

Systems and methods for attribute based access control on a data lake. The systems and methods include receiving a data file and metadata associated with the data file, storing the data file in a database and storing the metadata in a data catalog. The metadata is assigned a domain access configuration and an attribute access configuration. The systems and methods further include receiving a query for the data file from a user, where the user is assigned a persona, where persona comprises a permission level. Syntax of the query is evaluated in addition to access to the query through steps including evaluating the permission level of the assigned persona against the domain access configuration and evaluating the permission level of the assigned persona against the attribute access configuration. In response to determining that the query fails to satisfy one or more of the evaluations, the query is then rejected.
Owner:WELLS FARGO BANK NA