Techniques and system for specifying policies using abstractions
    2.
    发明授权
    Techniques and system for specifying policies using abstractions 有权
    使用抽象指定策略的技术和系统

    公开(公告)号:US09384360B2

    公开(公告)日:2016-07-05

    申请号:US11615477

    申请日:2006-12-22

    申请人: Keng Lim

    发明人: Keng Lim

    摘要: A policy language for an information management system allows specifying or more policies using policy abstractions. The policies and policy abstractions are decoupled from one another, so policies and policy abstractions may be specified and altered separately from each other. A policy may refer to any number of policy abstractions. Multiple policies may reference a single policy abstraction, and a change to that policy abstraction will result in multiple policies being changed. Further, policy abstractions may be nested, so one policy abstraction may reference another policy abstraction, and so forth.

    摘要翻译: 信息管理系统的策略语言允许使用策略抽象来指定或更多策略。 政策和政策抽象相互分离,政策和政策抽象可以彼此分开指定和改变。 政策可能涉及任何数量的政策抽象。 多个策略可以引用单个策略抽象,并且该策略抽象的改变将导致多个策略被改变。 此外,策略抽象可以嵌套,因此一个策略抽象可以引用另一个策略抽象,等等。

    Techniques and system to manage access of information using policies
    3.
    发明授权
    Techniques and system to manage access of information using policies 有权
    使用策略管理信息访问的技术和系统

    公开(公告)号:US09081981B2

    公开(公告)日:2015-07-14

    申请号:US11615604

    申请日:2006-12-22

    申请人: Keng Lim

    发明人: Keng Lim

    摘要: An information management system approves or denies user requests to access information of the system. The information includes all types of information including documents and e-mail. The information management system is driven using a policy language having policies and policy abstractions. The information management system may approve or deny many different types of requests including opening a document or file, copying a file, printing a file, sending an e-mail, reading an e-mail, cut and paste of a portion of a document, saving a document, executing an application on a file, and many others.

    摘要翻译: 信息管理系统批准或拒绝用户访问系统信息的请求。 信息包括所有类型的信息,包括文件和电子邮件。 信息管理系统采用具有策略和策略抽象的策略语言。 信息管理系统可以批准或拒绝许多不同类型的请求,包括打开文档或文件,复制文件,打印文件,发送电子邮件,阅读电子邮件,剪切和粘贴文档的一部分, 保存文档,在文件上执行应用程序等等。

    Enforcing access control policies on servers in an information management system
    6.
    发明授权
    Enforcing access control policies on servers in an information management system 有权
    在信息管理系统中对服务器实施访问控制策略

    公开(公告)号:US08677499B2

    公开(公告)日:2014-03-18

    申请号:US11928370

    申请日:2007-10-30

    申请人: Keng Lim

    发明人: Keng Lim

    IPC分类号: G06F17/30

    摘要: A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.

    摘要翻译: 一种使用集中管理的规则来控制文档访问和应用程序使用的方法和装置。 规则通过规则服务器存储和操纵在中央规则数据库中。 策略执行者安装在客户端系统和/或服务器上,并通过评估发送到策略执行者的规则,对直接用户文档访问和应用程序使用以及应用程序文档访问执行文档访问和应用程序使用控制。 规则服务器决定每个策略执行者需要哪些规则。 作为规则评估的一部分,政策执行者也可以履行义务和补救行动。 客户端系统和服务器上的策略执行器可以自主运行,评估当通过规则服务器停止通信时已收到的策略。

    Policy performance in an information management system
    7.
    发明授权
    Policy performance in an information management system 有权
    信息管理系统中的策略性能

    公开(公告)号:US08661003B2

    公开(公告)日:2014-02-25

    申请号:US13438753

    申请日:2012-04-03

    申请人: Keng Lim

    发明人: Keng Lim

    IPC分类号: G06F17/30

    摘要: In an information management system, policies are optimized before they are associated to a device in order to increase evaluation speed or reduce space requirements, or both. Optimization techniques may include common subexpression elimination, constant folding, constant propagation, comparison optimization, dead code or subexpression removal, map or lookup table generation, policy rewriting, redundant policy elimination, heuristic-based policy ordering, or policy-format transformation, and combinations of these.

    摘要翻译: 在信息管理系统中,策略在与设备相关联之前进行优化,以提高评估速度或减少空间要求,或两者兼而有之。 优化技术可以包括常见的子表达消除,常量折叠,恒定传播,比较优化,死码或子表达删除,映射或查找表生成,策略重写,冗余策略消除,基于启发式的策略排序或策略格式转换,以及组合 这些。

    Enforcing document control in an information management system
    9.
    发明授权
    Enforcing document control in an information management system 有权
    在信息管理系统中执行文档控制

    公开(公告)号:US08627490B2

    公开(公告)日:2014-01-07

    申请号:US11383159

    申请日:2006-05-12

    申请人: Keng Lim

    发明人: Keng Lim

    IPC分类号: G06F17/30

    摘要: A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.

    摘要翻译: 一种使用集中管理的规则来控制文档访问和应用程序使用的方法和装置。 规则通过规则服务器存储和操纵在中央规则数据库中。 策略执行者安装在客户端系统和/或服务器上,并通过评估发送到策略执行者的规则,对直接用户文档访问和应用程序使用以及应用程序文档访问执行文档访问和应用程序使用控制。 规则服务器决定每个策略执行者需要哪些规则。 作为规则评估的一部分,政策执行者也可以履行义务和补救行动。 客户端系统和服务器上的策略执行器可以自主运行,评估当通过规则服务器停止通信时已收到的策略。

    Enforcing application and access control policies in an information management system with two or more interactive enforcement points
    10.
    发明授权
    Enforcing application and access control policies in an information management system with two or more interactive enforcement points 有权
    在具有两个或多个交互执行点的信息管理系统中强制应用和访问控制策略

    公开(公告)号:US08407345B2

    公开(公告)日:2013-03-26

    申请号:US11928589

    申请日:2007-10-30

    申请人: Keng Lim

    发明人: Keng Lim

    摘要: A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.

    摘要翻译: 一种使用集中管理的规则来控制文档访问和应用程序使用的方法和装置。 规则通过规则服务器存储和操纵在中央规则数据库中。 政策执行者安装在客户端系统和/或服务器上,并通过评估发送给策略执行者的规则,对直接用户文档访问和应用程序使用以及应用程序文档访问执行文档访问和应用程序使用控制。 规则服务器决定每个策略执行者需要哪些规则。 作为规则评估的一部分,政策执行者也可以履行义务和补救行动。 客户端系统和服务器上的策略执行器可以自主运行,评估当通过规则服务器停止通信时已收到的策略。