Shadow satisfiability modulo theories solver systems
US-2024330709-A1 · Oct 3, 2024 · US
US10356100B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10356100-B2 |
| Application number | US-201816011481-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 18, 2018 |
| Priority date | Oct 23, 2006 |
| Publication date | Jul 16, 2019 |
| Grant date | Jul 16, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A container that manages access to protected resources using rules to intelligently manage them includes an environment having a set of software and configurations that are to be managed. A rule engine, which executes the rules, may be called reactively when software accesses protected resources. The engine uses a combination of embedded and configurable rules. It may be desirable to assign and manage rules per process, per resource (e.g. file, registry, etc.), and per user. Access rules may be altitude-specific access rules.
Opening claim text (preview).
We claim: 1. A method comprising: receiving a request for accessing one or more resources in a container, from a process of a stream-enabled application that is executed using a downloaded part of the stream-enabled application, when entire parts of the stream-enabled application have not been downloaded; in response to the request, determining whether access grant at a virtual demilitarized zone (DMZ) is required to allow access to the one or more resources in the container; when it is determined the access grant at the virtual DMZ is not required, allowing access to the one or more resources in the container, thereby enabling the stream-enabled application to continue; when it is determined the access grant at the virtual DMZ is required, determining, at the virtual DMZ, whether the access grant is given; when it is determined the access grant is given at the virtual DMZ, allowing access to the one or more resources in the container, thereby enabling the stream-enabled application to continue; when it is determined the access grant is not given at the virtual DMZ, restricting access to the one or more resources in the container; wherein the determining, at the virtual DMZ, whether the access grant is given comprises determining the access grant is given for each of access of a first type and access of a second type different from the first type, wherein access to the one or more resources in the container is allowed only for one or both of the first and second types for which the access grant is given; setting access control rules for the access grant based on an altitude value corresponding to an access privilege level. 2. The method of claim 1 , wherein access to the one or more resources in the container comprises a read access with respect to the one or more resources in the container. 3. The method of claim 1 , wherein access to the one or more resources in the container comprises a write access with respect to the one or more resources in the container. 4. The method of claim 3 , wherein the stream-enabled application is executed in a virtual environment that is inside the container. 5. The method of claim 3 , wherein the stream-enabled application is executed in a virtual environment that is outside the container. 6. The method of claim 3 , wherein the container is a first container and wherein the stream-enabled application is executed in a second container different from the first container. 7. The method of claim 3 , wherein the virtual DMZ is remote with respect to the container. 8. The method of claim 3 , wherein whether the access grant is given is determined at the virtual DMZ, based on one or more access control lists (ACLs). 9. A system comprising: at least one processor and memory storing instructions to instruct the at least one processor to: receive a request for accessing one or more resources in a container, from a process of a stream-enabled application that is executed using a downloaded part of the stream-enabled application, when entire parts of the stream-enabled application have not been downloaded; in response to the request, determine whether access grant at a virtual demilitarized zone (DMZ) is required to allow access to the one or more resources in the container; when it is determined the access grant at the virtual DMZ is not required, allow access to the one or more resources in the container, thereby enabling the stream-enabled application to continue; when it is determined the access grant at the virtual DMZ is required, determine, at the virtual DMZ, whether the access grant is given; when it is determined the access grant is given at the virtual DMZ, allow access to the one or more resources in the container, thereby enabling the stream-enabled application to continue; when it is determined the access grant is not given at the virtual DMZ, restrict access to the one or more resources in the container; determine the access grant is given for each of access of a first type and access of a second type different from the first type, and allow access to the one or more resources in the container only for one or both of the first and second types for which the access grant is given; set access control rules for the access grant based on an altitude value corresponding to an access privilege level. 10. The system of claim 9 , wherein access to the one or more resources in the container comprises a read access with respect to the one or more resources in the container. 11. The system of claim 9 , wherein access to the one or more resources in the container comprises a write access with respect to the one or more resources in the container. 12. The system of claim 9 , wherein the stream-enabled application is executed in a virtual environment that is inside the container. 13. The system of claim 9 , wherein the stream-enabled application is executed in a virtual environment that is outside the container. 14. The system of claim 9 , wherein the container is a first container and wherein the stream-enabled application is executed in a second container different from the first container. 15. The system of claim 9 , wherein the virtual DMZ is remote with respect to the container. 16. The system of claim 9 , wherein the instructions instruct the at least one processor to determine whether the access grant is given at the virtual DMZ, based on one or more access control lists (ACLs).
characterised by the conditions triggering a change of settings · CPC title
Access rights, e.g. capability lists, access control lists, access tables, access matrices · CPC title
to a system of files or objects, e.g. local or distributed file system or database · CPC title
Specific access rights for resources, e.g. using capability register · CPC title
involving simulating, designing, planning or modelling of a network · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.