IP Library Granted Patent US 12683976
Granted Patent B2
US 12683976 · App. 18/422,966 · Granted Jul 14, 2026

System and method for continuous monitoring and revocation of device access authorization

Inventors: Jeremy Paul Bowers (Brighton, MI); Benjamin Roberto Magee (Ann Arbor, MI)
Assignee: Barracuda Networks, Inc.
H04L63/108H04L63/0892
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12683976
App. No.
18/422,966
Granted
Jul 14, 2026
Kind
B2
Abstract

A new approach is proposed to support an authorization server to continuously monitor and revoke device access authorization to a plurality of resources. A client device associated with a user or consumer first sends a request to the authorization server for authorization to access or perform certain operations on one or more resources. Upon receiving the request, the authorization server makes an initial authorization determination on whether to grant or deny the request for authorization to the one or more resources by the client device based on the type of the request and/or the one or more resources requested to access. After an initial authorization determination is made, the authorization server continues to monitor the resources being accessed and update the initial authorization determination to the client device in real time. An live update in the authorization determination is then provided to the client device in real time.

Claims (58)

1 . A system, comprising:

an authorization server configured to

accept a request from a client device associated with a user for authorization to access or perform certain operations on one or more resources;

make an initial authorization determination on whether to grant or deny the request for authorization to the one or more resources by the client device based on type of the request and/or the one or more resources requested to access;

under a continuous authorization mode, maintain a live connection to the client device after the initial authorization determination;

continue to monitor, via the live connection maintained with the client device, the one or more resources being accessed by the client device after the initial authorization determination is made;

responsive to a change in an access authorization determination for a given resource of the one or more resources, provide, in real-time and while maintaining the live connection with the client device, a live update of the change in the authorization determination to the client device accessing the given resource; and

reactivate an access authorization to the given resource within a predetermined interval of time, wherein, based on the access authorization being reactivated within a predetermined interval of time, the client device maintains access to the given resource and the authorization server maintains the live connection with the client device.

2 . The system of claim 1 , wherein:

each of the one or more resources is one of a device, an appliance, a machine, and a computing unit, wherein each of the one or more resources provides one or more functions and/or services.

3 . The system of claim 1 , wherein:

the authorization server is configured to operate in two modes: check-on-access authorization mode and continuous authorization mode.

4 . The system of claim 3 , wherein:

the authorization server is configured to check only at point in time of the request for authorization is received from the client device to determine if the client device can have access to the one or more resource or not under the check-on-access authorization mode.

5 . The system of claim 3 , wherein:

the authorization server is configured to communicate with and to obtain information from a point-in-time information service connected to the one or more resources, wherein such information is used to determine access authorization for the client device under the check-on-access authorization mode.

6 . The system of claim 5 , wherein:

the authorization server is configured to poll the point-in-time information service periodically, which yields the information for the check-on-access authorization mode.

7 . The system of claim 3 , wherein:

the authorization server is configured to maintain a live connection to the client device in order to monitor which of the one or more resources are currently in use or being accessed under the continuous authorization mode.

8 . The system of claim 7 , wherein:

the authorization server is configured to communicate with an external information service, which streams information used for authorization on a continual basis under the continuous authorization mode.

9 . The system of claim 1 , wherein:

the authorization server is configured not only to shut down access authorization to one or more resources for security implications but also to restore access authorization to the resource in a timely manner.

10 . The system of claim 1 , wherein:

the authorization server is configured to stream the live update to an external auditing service or authorization logging service.

11 . The system of claim 1 , wherein:

the authorization server is configured to permit live interactions with a permission scheme for access authorization control by the user.

12 . A computer-implemented method, comprising:

accepting, by an authorization server, a request from a client device associated with a user for authorization to access or perform certain operations on one or more resources;

making an initial authorization determination on whether to grant or deny the request for authorization to the one or more resources by the client device based on type of the request and/or the one or more resources requested to access;

under a continuous authorization mode, maintaining a live connection to the client device after the initial authorization determination;

continuing to monitor, via the live connection maintained with the client device, the one or more resources being accessed by the client device after the initial authorization determination is made;

responsive to a change in an access authorization determination for a given resource of the one or more resources, providing, in real-time and while maintaining the live connection with the client device, a live update of the change in the authorization determination to the client device accessing the given resource; and

reactivating an access authorization to the given resource within a predetermined interval of time, wherein, based on the access authorization being reactivated within a predetermined interval of time, the client device maintains access to the given resource and the authorization server maintains the live connection with the client device.

13 . The method of claim 12 , further comprising:

checking only at point in time of the request for authorization is received from the client device to determine if the client device can have access to the one or more resource or not under a check-on-access authorization mode.

14 . The method of claim 13 , further comprising:

communicating with and to obtain information from a point-in-time information service connected to the one or more resources, wherein such information is used to determine access authorization for the client device under the check-on-access authorization mode.

15 . The method of claim 14 , further comprising:

polling the point-in-time information service periodically, which yields the information for the check-on-access authorization mode.

16 . The method of claim 12 , further comprising:

maintaining a live connection to the client device in order to monitor which of the one or more resources are currently in use or being accessed under a continuous authorization mode.

17 . The method of claim 16 , further comprising:

communicating with an external information service, which stream information used for authorization on a continual basis under the continuous authorization mode.

18 . The method of claim 12 , further comprising:

not only shutting down access authorization to the one or more resources for security implications but also restoring access authorization to the resource in a timely manner.

19 . The method of claim 12 , further comprising:

streaming the live update to an external auditing service or authorization logging service.

20 . The method of claim 12 , further comprising:

permitting live interactions with a permission scheme for access authorization control by the user.

21 . A non-transitory storage medium having software instructions stored thereon that when executed cause an authorization server to:

accept a request from a client device associated with a user for authorization to access or perform certain operations on one or more resources;

make an initial authorization determination on whether to grant or deny the request for authorization to the one or more resources by the client device based on type of the request and/or the one or more resources requested to access;

under a continuous authorization mode, maintain a live connection to the client device after the initial authorization determination;

continue to monitor, via the live connection maintained with the client device, the one or more resources being accessed by the client device after the initial authorization determination is made;

responsive to a change in an access authorization determination for a given resource of the one or more resources, provide, in real-time and while maintaining the live connection with the client device, a live update of the change in the authorization determination to the client device accessing the given resource; and

reactivate an access authorization to the given resource within a predetermined interval of time, wherein, based on the access authorization being reactivated within a predetermined interval of time, the client device maintains access to the given resource and the authorization server maintains the live connection with the client device.