IP Library Granted Patent US 7,366,812
Granted Patent B2
US 7,366,812 · App. 11/239,322 · Granted Apr 29, 2008

Determination of access rights to information technology resources

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,366,812
App. No.
11/239,322
Granted
Apr 29, 2008
Kind
B2
Abstract

A method, system, and firewall for controlling access to resources within an information technology (IT) system. Commands received from a requesting entity request access to a resource associated with each command. An assigned authority level of the requesting entity is identified. At least one required authority level of the requesting entity is determined for each command as a function of each command and a resource criticality classification of the resource associated with each command. The requesting entity is granted or denied the requested access to the resource associated with each command if a determination has been made that each condition of at least one specified condition has or has not been satisfied, respectively. The at least one specified condition is specific to each command and includes a condition of the assigned authority level matching or exceeding an authority level of the at least one required authority level of each command.

Claims (15)

1. A method for controlling access to resources within an information technology (IT) system in conjunction with executing a procedure that defines a plurality of commands, said method comprising:

receiving the plurality of commands from a requesting entity, each command requesting access to an associated resource in order to perform a function;

identifying an assigned authority level of the requesting entity;

determining at least one required authority level of the requesting entity for each command in order for the requesting entity to be granted access to the requested resource associated with said each command, said at least one required authority level for each command being determined as a function of said each command and a resource criticality classification of the resource associated with said each command;

granting the requesting entity said requested access to the resource associated with each command if a determination has been made that each condition of at least one specified condition has been satisfied, said at least one specified condition being specific to each command, said at least one specified condition comprising a condition of the assigned authority level matching or exceeding an authority level of the at least one required authority level of said each command;

denying the requesting entity said requested access if a determination has been made that each condition of said at least one specified condition has not been satisfied.

2. The method of claim 1 , said at least one condition not further comprising a condition of a specified prerequisite action having occurred prior to said receiving said each command.

3. The method of claim 1 , said at least one condition further comprising a condition of a specified prerequisite action having occurred prior to said receiving said each command.

4. The method of claim 1 , said receiving having occurred at a particular stage of the procedure, said at least one condition not further comprising a condition of said each command not being allowed to be performed at said particular stage of the procedure.

5. The method of claim 1 , said at least one condition further comprising a condition that is a function of a risk classification of said each command.

6. The method of claim 1 , wherein upon said denying access to the resource, said method further comprises generating an alert notifying the requesting entity of an alternative command or sequence of commands to be performed on the resource associated with each command.

7. The method of claim 1 , wherein each command has been placed in a work queue of the requesting entity, and wherein upon said denying access to the resource associated with said each command said method further comprises transmitting said each command to an alternative work queue for an attention of an entity with a higher assigned authority level than the assigned authority level of the requesting entity.

8. The method of claim 3 , said specified prerequisite action being a function of said resource criticality classification.

9. The method of claim 3 , said specified prerequisite action comprising a successful or unsuccessful response from an action on a resource in the IT system.

10. The method of claim 5 , said risk classification dynamically changing with time.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2010
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: TREND MICRO INCORPORATED
Reel/Frame 024434/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2005
From: LAMBOURN, SIMON KEITH; MISSEN, ANDREW DAVID; MORGAN, WILLIAM BRUCE, DECEASED, BY LEGAL REPRESENTATIVE, MORGAN, MARIAN; SIDFORD, GUY IAN TARRANT
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 016911/0720 →
Priority Claims (1)
GB 0425113.8 · Nov 13, 2004 · national
Continuity (1)
Related Publication 20060106917A1 · May 18, 2006