Authorization and access control system for access rights using relationship graphs
US-2024414161-A1 · Dec 12, 2024 · US
US10033742B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10033742-B2 |
| Application number | US-93453509-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 24, 2009 |
| Priority date | Mar 27, 2008 |
| Publication date | Jul 24, 2018 |
| Grant date | Jul 24, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An information processing apparatus for suitably registering policy information by considering an order of priority while reducing the burden on a user has the following structure. When policy information used for communication with an apparatus of a communication partner is to be registered in a storage unit, and when an address of the apparatus of the communication partner of the policy information to be registered in the storage unit is included in an address of an apparatus of a communication partner of policy information already stored in the storage unit, registering of the policy information to be registered so that an order of priority of the policy information to be registered in the storage unit is set lower than an order of priority of the policy information whose address includes the address of the apparatus of the communication partner of the policy information to be registered is restricted.
Opening claim text (preview).
The invention claimed is: 1. An information processing apparatus, comprising: a storage memory configured to store first information, the first information including at least a first order of priority, a first address indicating a single communication partner of the information processing apparatus, and first key information used for communication with the single communication partner; a registering unit configured to register second information to add the second information to the storage memory, the second information including at least a second address indicating a plurality of communication partners of the information processing apparatus, and second key information used for communication with the plurality of communication partners, and to obtain an input from a user to set a second order of priority of the second information to have higher priority than the first order of priority; a control unit configured to, in a case where the registering unit registers the second information, and the second key information used for communication with the plurality of communication partners and the registering unit obtains the input from the user to set the second order of priority of the second information to have the higher priority than the first order of priority, perform a process by an at least one hardware processor to configure the first order of priority of the first information, which includes the first address indicating the single communication partner and the second order of priority of the second information, wherein the first order of priority is configured to have a higher priority than the second order of priority; a selection unit configured to select information stored in the storage memory according to an order of priority included in the information, wherein in a case where an address of the single communication partner corresponds to both the first address and the second address, the selection unit selects the first information including a higher priority as information used for communication with the single communication partner; and a communication interface circuit configured to communicate with the single communication partner based on the selected first information, wherein the registering unit, the control unit and the selection unit are implemented by the hardware processor. 2. The information processing apparatus according to claim 1 , wherein the first information and the second information stored in the storage memory are used for communication using Security Architecture for Internet Protocol (IPSec) with the single communication partner. 3. The information processing apparatus according to claim 1 , wherein the first address and the second address stored in the storage memory are IP addresses. 4. The information processing apparatus according to claim 1 , further comprising a printing unit configured to perform a printing operation. 5. An information processing apparatus, comprising: a storage memory configured to store first information, the first information including at least a first address indicating a plurality of communication partners of the information processing apparatus and first key information used for communication with the plurality of communication partners; a registering unit configured to register second information to add the second information to the storage memory, the second information including at least a second address indicating the plurality of communication partners of the information processing apparatus, and second key information used for communication with the plurality of communication partners; a control unit configured to, in a case where the registering unit registers to add, to the storage memory which stores the first information including at least the first address indicating the plurality of communication partners and the first key information for the plurality of communication partners wherein the first key information and the second key information is not identical, the second information and the second key information used for communication with the plurality of communication partners, perform control so that the first key information of the first information, stored in the storage memory and the second key information of the second information, to be stored in the storage memory are identical; and a communication interface circuit configured to communicate with the plurality of communication partners based on the first information or the second information, wherein the registering unit and the control unit are implemented by at least one hardware processor. 6. The information processing apparatus according to claim 5 , wherein the control unit performs the control so that the second key information of the second information to be stored in the storage memory matches the first key information of the first information stored in the storage memory. 7. The information processing apparatus according to claim 5 , wherein the control unit performs the control so that the first key information of the first information stored in the storage memory matches the second key information of the second information to be stored in the storage memory. 8. The information processing apparatus according to claim 5 , further comprising: a display unit configured to display a screen to cause a user to select an operation of causing the second key information of the second information to be stored in the storage memory to match the first key information of the first information stored in the storage memory, or an operation of causing the first key information of the first information stored in the storage memory to match the second key information of the second information to be stored in the storage memory. 9. The information processing apparatus according to claim 5 , wherein the first information and the second information stored in the storage memory are used for communication using Security Architecture for Internet Protocol (IPSec) with the single communication partner. 10. The information processing apparatus according to claim 5 , wherein the first address and the second address stored in the storage memory are IP addresses. 11. A control method of an information processing apparatus performed by at least one hardware processor, comprising: storing first information, the first information including at least a first order of priority, a first address indicating a single communication partner of the information processing apparatus, and first key information used for communication with the single communication partner; registering second information to add the second information to a storage memory, the second information including at least a second address indicating a plurality of communication partners of the information processing apparatus, and second key information used for communication with the plurality of communication partners, and to obtain an input from a user to set a second order of priority of the second information to have higher priority than the first order of priority; performing control, in a case where the registering registers the second information, and the second key information used for communication with the plurality of communication partners and obtaining the input from the user to set the second order of priority of the second information to have the higher priority than the first order of priority, to configure the first order of priority of the first information, which includes the first address indicating the single communication partner and the second order of priority of the second information, wherein the first order of priority is configured to have a higher priority than the second order of priority; selectin
Entity profiles · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title
at the network layer · CPC title
involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.