Managing Inter-Object Operations in a Domain Role-Based Access Control (RBAC) System
An approach is provided in which an information handling system receives a request from a subject to perform an operation between a first object and a second object. The first object belongs to a first set of domains and the second object belongs to a second set of domains. The information handling...
Gespeichert in:
Hauptverfasser: | , , |
---|---|
Format: | Patent |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | An approach is provided in which an information handling system receives a request from a subject to perform an operation between a first object and a second object. The first object belongs to a first set of domains and the second object belongs to a second set of domains. The information handling system determines whether a set of common domains exist between first set of domains and the second set of domains that meet an inter-domain restriction that is imposed on the subject, which requires that the first set of domains and the second set of domains have at least one domain in common. The information handling system, in turn, performs the operation based on the determination. |
---|