1. A method for authorizing a user comprising:
a) receiving from a user device a first request for a service of an application;
b) determining a user identifier associated with the user device;
c) determining an access right required to access the service without accessing the application;
d) determining if the user identifier is associated with the access right;
e) in response to a determination of the user identifier being associated with the access right, generating a second request for the service of the application, the second request being different from the first request;
f) sending the second request to the application;
g) accessing the application using one or more user credentials different from one or more credentials of the user device.
2. The method of claim 1, wherein determining if the user identifier is associated with the access right includes accessing an object associated with the service, the object being stored in a data store.
3. The method of claim 2, wherein accessing an object includes accessing an access control list associated with the object.
4. The method of claim 3, wherein the access control list is owned by the object.
5. The method of claim 3, wherein accessing an access control list includes accessing an access control list of another object.
6. The method of claim 5, further comprising determining the another object by determining a nearest ancestor of the object owning an access control list.
7. The method of claim 6, wherein the object is selected from a group comprising a system object, a system instance object, an entity object, a method object, a parameter object, and a parameter type object.
8. The method of claim 7, further comprising organizing the group of a system object, a system instance object, an entity object, a method object, a parameter object, and a parameter type object as a hierarchy, and wherein determining a nearest ancestor of the object includes based on the hierarchy, determining a higher level object associated with the object and owning an access control list.
9. The method of claim 3, wherein accessing an object includes accessing an access control entry associated with the access control list, the access control entry including at least one authorized user identifier associated with at least one authorized right of access.
10. The method of claim 9, wherein the at least one authorized right of access is selected from a group comprising a right to edit, a right to view, and a right to execute.
11. One or more computer readable media having stored thereon a data structure comprising:
a) a first data field containing data representing an object identifier, the object identifier indicating an available service of an application;
b) a second data field, associated with the first data field, containing data representing an access control list identifier;
c) a third data field, associated with the second data field, containing data representing an access control entry identifier;
d) a fourth data field, associated with the third data field, containing data representing a user identifier associated with an authorized user of the application; and
e) a fifth data field, associated with the third data field, containing data representing a right identifier indicating an authorized right of the authorized user to access the available service.
12. The one or more computer readable media of claim 11, wherein the access control list identifier references an access control list application program interface for checking access rights of a user to the application.
13. The one or more computer readable media of claim 11, wherein the access control entry identifier references an access control entry application program interface for verifying access rights based on the fourth and fifth data fields.
14. The one or more computer readable media of claim 11, wherein the object identifier identifies an object having a type selected from a group comprising a system object, a system instance object, an entity object, a method object, a parameter object, and a parameter type object.
15. One or more computer readable media containing computer readable instructions that, when implemented, perform a method comprising:
a) associating a service identifier with connection information, an authorized user identifier, and an access right indicator of the authorized user identifier, wherein the service identifier is associated with a service of at least one of a plurality of available applications providing services;
b) receiving a request for the service from a user device;
c) verifying that a user identifier associated with the user device matches the authorized user identifier without accessing the at least one of the plurality of available applications;
d) based on the access right indicator, verifying that the request for the service is allowed by the authorized right indicator without accessing the at least one of the plurality of available applications;
e) if the user identifier and the request are verified, accessing the at least one of the plurality of available applications using credentials different from user credentials of the user device; and
f) requesting the service from the at least one of the plurality of available applications.
16. The one or more computer readable media of claim 15, wherein associating a service identifier with an authorized user identifier and an access right indicator of the authorized user identifier includes associating the service identifier with an access control list and associating the access control list with an access control entry, the access control entry associating the authorized user identifier and the access right indicator.
17. The one or more computer readable media of claim 16, wherein associating the service identifier with an access control list includes creating a service object containing the access control list.
18. The one or more computer readable media of claim 16, wherein associating the service identifier with an access control list includes associating the service identifier with an application program interface for discovering a nearest ancestor object of the service identifier that contains the access control list.
19. The one or more computer readable media of claim 18, wherein discovering a nearest ancestor object includes walking up a predetermined object hierarchy associated with the service identifier and determining a nearest higher level object containing an access control list.
20. The one or more computer readable media of claim 15, further comprising associating the authorized user identifier and access right indicator with a child service indicator associated to the service indicator in accordance with a service hierarchy.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.
1. A data transfer system comprising a data transfer apparatus and a data-recording apparatus, wherein said data transfer apparatus comprises:
primary-recording-medium driving means for recording and reproducing data onto and from a primary recording medium;
storage controlling means for controlling said primary-recording-medium driving means to store content data in an encrypted state and a first content identifier generated uniquely to said content data onto said primary recording medium;
communication means for carrying out a variety of data communications including transfers of content data with said data-recording apparatus; and
transfer management means for managing rights to transfer content data and for managing transfer rights of content data already transferred to said data recording apparatus by using a generated table for associating said first content identifier with a second content identifier received from said data-recording apparatus and generated by said data-recording apparatus for said content data already transferred to said data-recording apparatus; and wherein said data-recording apparatus comprises:
communication means for carrying out data communications including exchanges of content data with said data transfer apparatus;
secondary-recording-medium driving means for recording and reproducing data onto and from a secondary recording medium;
decryption means for decrypting encrypted content data received from said data transfer apparatus, putting said content data in an unencrypted state;
recording controlling means for controlling said secondary-recording-medium driving means to record said encrypted content data decrypted by said decryption means onto said secondary recording medium;
identifier generation means for generating a second content identifier of said content data from said content data in said unencrypted state; and
identifier-transmission controlling means for requesting said communication means to transmit said second content identifier generated by said identifier generation means to said data transfer apparatus.
2. A data transfer system according to claim 1, wherein said transfer management means manages said rights to transfer content data by managing the number of allowable transfers of content data to said data-recording apparatus.
3. A data transfer system according to claim 1, wherein, when a right to reproduce content data from said secondary recording medium is lost for said content data recorded on said secondary recording medium, said transfer management means requests said data-recording apparatus to transmit said second content identifier generated for said content data and, after using said table for collation of said second content identifier received from said data-recording apparatus, updates said right to transfer said content data.
4. A data transfer system according to claim 1, wherein said identifier generation means extracts a portion of said content data from a sampling point determined on the basis of the length of said content data, and generates a second content identifier by carrying out a process using said extracted portion.
5. A data transfer system according to claim 4, wherein a point or a plurality of points other than a start and an end of content data are used as said sampling points for generating a second content identifier of said content data.
6. A data transfer system according to claim 1, wherein:
when said content data is received from said data transfer apparatus, said identifier generation means extracts a portion from said sampling point in said content data on a data path ending with an operation to record said content data decrypted by said decryption means onto said secondary recording medium, and generates a second content identifier by carrying out a process using said extracted portion; and
upon completion of a transfer of said content data from said data transfer apparatus, said identifier-transmission controlling means requests said communication means to transmit said second content identifier generated by said identifier generation means to said data transfer apparatus.
7. A data transfer system according to claim 1, wherein, with said secondary recording medium for recording contents mounted on said data-recording apparatus:
said secondary-recording-medium driving means reproduces a portion from a sampling point in one of said contents recorded in said secondary recording medium and stores said portion in a storage means in advance for each of said contents;
when a request for said second content identifier of one of said contents recorded in said secondary recording medium is received from said data transfer apparatus, said identifier generation means generates said second content identifier by carrying out a process using extracted portion of said sampling point already stored in said storage means; and
said identifier-transmission controlling means requests said communication means to transmit said second content identifier generated by said identifier generation means to said data transfer apparatus.
8. A data transfer system according to claim 1, wherein, with said secondary recording medium for recording contents mounted on said data-recording apparatus:
said secondary-recording-medium driving means reproduces a portion from a sampling point in one of said contents data recorded in said secondary recording medium, said identifier generation means uses said reproduced portion in a process to generate said second content identifier to be stored in a storage means in advance for each of said contents; and
when a request for said second content identifier of one of said contents recorded in said secondary recording medium is received from said data transfer apparatus, said identifier-transmission controlling means requests said communication means to transmit said second content identifier already stored in said storage means to said data transfer apparatus.
9. A data transfer apparatus comprising:
primary-recording-medium driving means for recording and reproducing data onto and from a primary recording medium;
storage controlling means for storing encrypted content data and first content identifier generated inherently for the content data onto said primary recording medium;
communication means for carrying out a variety of data communications including transfers of content data with an external data-recording apparatus; and
transfer management means for managing rights to transfer content data and for managing transfer rights of content data already transferred to said external data-recording apparatus by using a generated table for associating said first content identifier with a second content identifier received from said external data-recording apparatus and generated by said data-recording apparatus for said content data already transferred to said data-recording apparatus.
10. A data transfer apparatus according to claim 9, wherein said transfer management means manages said rights to transfer content data by managing the number of allowable transfers of content data to said external data-recording apparatus.
11. A data transfer apparatus according to claim 9, wherein, when a right to reproduce content data from said secondary recording medium is lost for said content data recorded on said secondary recording medium, said transfer management means requests said external data-recording apparatus to transmit said second content identifier generated for said content data and, after using said table for collation of said second content identifier received from said data-recording apparatus, updates said right to transfer said content data.