IP Library Patent Application 11761170
Patent Application
App. No. 11/761,170

ENTITY BASED ACCESS MANAGEMENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/761,170
Abstract

The subject disclosure pertains to systems and methods that facilitate entity-based for access management. Typically, access to one or more resources is managed based upon identifiers assigned to entities. Groups of identifiers can be assigned to access rights. An authority component can manage an exclusion group that excludes an entity, regardless of the identifier utilized by the entity. Access control components can utilize exclusion groups in access policies to define access rights to a resource.

Claims (27)

1 . A system that facilitates entity based management of access to resources, comprising:

an authority component that manages an exclusion group that consists of a set of identifiers and excludes an identifier associated with an entity, such that the entity is excluded from the exclusion group without regard to any other identifiers associated with the entity; and

an access control manager that utilizes an access policy to control access to a resource, the access policy utilizes the exclusion group to define an access right.

2 . The system of claim 1 , the exclusion group includes all members of a base group, except for the excluded identifier.

3 . The system of claim 1 , further comprising an access control list component that expresses the access policy in an access control list.

4 . The system of claim 1 , further comprising an access certificate component that generates a set of certificates that express the access policy.

5 . The system of claim 1 , the excluded identifier includes a global identifier specific to the authority component that issued the identifier.

6 . The system of claim 1 , the excluded identifier includes a local identifier specific to the entity with respect to the authority component.

7 . The system of claim 1 , further comprising an entity identifier component that creates the identifier associated with the entity, such that the identifier is unique with respect to the issuing authority component and consistent over time.

8 . The system of claim 7 , the entity identification component utilizes a biometric to verify the entity.

9 . The system of claim 1 , further comprising a data store that maintains information related to identifiers issued by the authority component and their associated entities.

10 . The system of claim 9 , the data store maintains information related previously issued identifiers to ensure that identifiers are consistent over time.

11 . The system of claim 1 , further comprising a group manager component that issues an identifier for the exclusion group that includes a global identifier specific to the authority component and a local identifier specific to the group with respect to the authority component.

12 . A methodology for managing access to at least one resource, comprising:

specifying an exclusion group that includes a set of identifiers and excludes an entity, where the entity is excluded from the exclusion group regardless of identifier utilized by the entity; and

defining access rights to a resource as a function of the exclusion group.

13 . The methodology of claim 12 , further comprising determining access to the resource as a function of membership in the exclusion group.

14 . The methodology of claim 12 , the exclusion group consists of a base group of identifiers and excludes an identifier associated with the entity.

15 . The methodology of claim 14 , further comprising selecting a base group as a function of desired probability of correct entity identification.

16 . The methodology of claim 15 , the probability is a function of a biometric used in entity identification.

17 . The methodology of claim 12 , further comprising utilizing the exclusion group in an access control list to express an access policy.

18 . The methodology of claim 12 , further comprising utilizing the exclusion group to generate a set of certificates that express an access policy.

19 . An apparatus that facilitates entity-based access management, comprising:

means for selecting a base group of at least one entity identity, the base group includes an identity associated with an entity to be excluded;

means for specifying an exclusion group that includes members of the base group and excludes the identity associated with the entity, such that the entity is not included in the exclusion group regardless of any other associated identities; and

means for controlling access to a resource as a function of the exclusion group.

20 . The apparatus of claim 19 , further comprising means for associating the entity with the identity, such that the identity is unique to the entity and consistent over time.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034766/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2007
From: ELLISON, CARL MELVIN; LEACH, PAUL J.; LAMPSON, BUTLER WRIGHT; DUNN, MELISSA W.; PANDYA, RAVINDRA NATH; KAUFMAN, CHARLES WILLIAM
To: MICROSOFT CORPORATION
Reel/Frame 019506/0585 →