Claims
- 1. A method for specifying a security policy, said method comprising:
transmitting a hierarchical security program object (HSPO) comprising at least a first class of security attributes; determining that a first entity corresponds to said class; determining from the HSPO a set of security attributes for the entity; assigning the set of security attributes to the entity; and enforcing the set of security attributes on the entity.
- 2. The method as recited in claim 1 wherein the HSPO is transmitted from a head-end to a client device.
- 3. The method as recited in claim 1 wherein said HSPO is downloaded to a client device via a computer network.
- 4. The method as recited in claim 1 wherein the HSPO is received in a client device, and wherein the method further comprises programming a default HSPO into the client device.
- 5. The method as recited in claim 1 wherein the HSPO defines a second class of security attributes, said second class being a parent class of the first class, and wherein the set of security attributes comprises a union of the first class of security attributes and the second class of security attributes.
- 6. The method as recited in claim 5, wherein the first class comprises an advertisement class and the second class comprises a network class.
- 7. The method as recited in claim 5, wherein the classes are defined by a security policy maker associated with a source of the HSPO.
- 8. The method as recited in claim 5, wherein the HSPO classes are defined by a security policy maker located in a client device which receives the transmitted HSPO.
- 9. A computer readable medium comprising program instructions, wherein the program instructions are executable to:
transmit a hierarchical security program object (HSPO) comprising at least a first class of security attributes; determine that a first entity corresponds to said class; determine from the HSPO a set of security attributes for the entity; assign the set of security attributes to the entity; and enforce the set of security attributes on the entity.
- 10. The computer readable medium as recited in claim 9, wherein the HSPO is transmitted from a head-end to a client device.
- 11. The computer readable medium as recited in claim 9, wherein said HSPO is downloaded to a client device via a computer network.
- 12. The computer readable medium as recited in claim 9, wherein the HSPO is received in a client device, and wherein the program instructions are further executable to program a default HSPO into the client device.
- 13. The computer readable medium as recited in claim 9, wherein the HSPO defines a second class of security attributes, said second class being a parent class of the first class, and wherein the set of security attributes comprises a union of the first class of security attributes and the second class of security attributes.
- 14. The computer readable medium as recited in claim 13, wherein the first class comprises an advertisement class and the second class comprises a network class.
- 15. The computer readable medium as recited in claim 13, wherein the classes are defined by a security policy maker associated with a source of the HSPO.
- 16. The computer readable medium as recited in claim 13, wherein the HSPO classes are defined by a security policy maker located in a client device which receives the transmitted HSPO.
- 17. A system comprising:
a server configured to transmit a hierarchical security program object (HSPO) comprising at least a first class of security attributes; and a client device coupled to receive the HSPO, wherein the client device is configured to:
determine that a first entity corresponds to said class; determine from the HSPO a set of security attributes for the entity; assign the set of security attributes to the entity; and enforce the set of security attributes on the entity.
- 18. The system as recited in claim 17, wherein said client device includes a storage configured to store a default HSPO.
- 19. The system as recited in claim 17, wherein the HSPO defines a second class of security attributes, said second class being a parent class of the first class, and wherein the set of security attributes comprises a union of the first class of security attributes and the second class of security attributes.
- 20. The system as recited in claim 17, wherein the security attributes are defined by a policy maker within either the server or the client device.
- 21. A device comprising:
a receiver configured to receive a hierarchical security program object (HSPO) comprising at least a first class of security attributes; and storage configured to store the HSPO; wherein the device is configured to:
determine that a first entity corresponds to said class; determine from the HSPO a set of security attributes for the entity; assign the set of security attributes to the entity; and enforce the set of security attributes on the entity.
- 22. The device as recited in claim 21, wherein the HSPO is transmitted from a head-end.
- 23. The device as recited in claim 21, wherein the HSPO is received via a computer network.
- 24. The device as recited in claim 21, wherein the HSPO defines a second class of security attributes, said second class being a parent class of the first class, and wherein the set of security attributes comprises a union of the first class of security attributes and the second class of security attributes.
- 25. The device as recited in claim 24, wherein the first class comprises an advertisement class and the second class comprises a network class.
CROSS REFERENCE TO RELATED APPLICATIONS
[0001] This application claims benefit of priority to Provisional Application Serial No. 60/360,100 filed Feb. 27, 2002.
Provisional Applications (1)
|
Number |
Date |
Country |
|
60360100 |
Feb 2002 |
US |