Invention Grant
- Patent Title: Data access security
- Patent Title (中): 数据访问安全
-
Application No.: US11245776Application Date: 2005-10-06
-
Publication No.: US08225104B1Publication Date: 2012-07-17
- Inventor: Sourabh Satish
- Applicant: Sourabh Satish
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Fenwick & West LLP
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
An execution environment of a computer computes an initial effective permissions set for managed code based on user identity evidence, code evidence and/or a security policy and executes the code with this permissions set. If the managed code requests a data access, the execution environment considers data evidence that indicates the trustworthiness of the requested data. The data evidence can be based on the source of the data, the location of the data, the content of the data itself, or other factors. The execution environment computes a new effective permissions set for the managed code based on the data evidence and the security policy. This new effective permissions set is applied to the managed code while the code accesses the data. The execution environment restores the initial permissions set once the managed code completes the data access.
Information query