IP Library Granted Patent US 8,205,092
Granted Patent B2
US 8,205,092 · App. 11/768,755 · Granted Jun 19, 2012

Time-based method for authorizing access to resources

Assignee: Novell, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,205,092
App. No.
11/768,755
Granted
Jun 19, 2012
Kind
B2
Abstract

Upon receiving a request for access to a resource, a current clock value is determined. Based on information including the resource, the identity of the user requesting the access, and the current clock value, the system identifies applicable access controls. If the applicable access controls indicate that the user can be granted access to the resource at the current time, the request is granted. Otherwise, the request is denied.

Claims (73)

1. An apparatus, comprising:

a machine;

a resource accessible via the machine to which a user wants access;

at least one access control structure associated with the resource and a group identifier, the access control structure one of a plurality of access control structures associated with the resource and a plurality of group identifiers, the access control structure including time values when access to the resource is to be granted for a particular access level, said access level drawn from a set including read access, write access, execute access, read/write access, read/execute access, write/execute access, and read/write/execute access, the group identifier identifying a group including at least said user identified by a user identifier and a second user identified by a second user identifier; and

an access control logic to determine whether said user, as a member of group identified by said group identifier, is to be granted access to the resource based on the access control structures and a current clock value.

2. An apparatus according to claim 1 , further comprising a clock operative to generate said current clock value.

3. An apparatus according to claim 1 , further comprising a request receiver to receive a request from said user to access the resource.

4. An apparatus according to claim 3 , wherein the access control logic is operative to grant said user, as a member of said group identified by said group identifier, access to the resource if said current clock value satisfies a time value in one of the access control structures.

5. An apparatus according to claim 4 , wherein:

the request receiver is operative to receive said request from said user to access the resource using an access type; and

the access control logic is operative to grant said user, as a member of said group identified by said group identifier, access to the resource if said current clock value satisfies said time value in one of the access control structures and said access type matches the access level in the one of the access control structures.

6. An apparatus according to claim 4 , wherein the access control logic is operative to deny said request if the access control structures do not permit said user, as a member of said group identified by said group identifier, access to the resource.

7. An apparatus according to claim 1 , wherein:

the access control logic includes an access control structure selector operative to select applicable access control structures from the at least one access control structure based on said current clock value; and

the access control logic is operative to determine whether said user, as a member of said group identified by said group identifier, is to be granted access to the resource based on said applicable access control structures and said current clock value.

8. An apparatus according to claim 1 , further comprising an authorization unit to process a login request from said user.

9. An apparatus according to claim 1 , wherein the resource is remote from the machine.

10. An apparatus according to claim 1 , further comprising a second access control structure of said plurality of access control structures associated with the resource and a second group identifier of said plurality of group identifiers, wherein said second group identifier identifies a second group including at least said user identified by said user identifier and a third user identified by a third user identifier.

11. A method for controlling user access to a resource in a computer, the method comprising:

receiving a request from a user to specifically access the resource using an access type, the user a member of a group including at least the user identified by a user identifier and a second user identified by a second user identifier;

determining a current clock value;

identifying at least one access controls applicable to the resource for the group based on the current clock value, the access control one of a plurality of access controls associated with the resource and a plurality of group identifiers, each of the access controls including an access level, the access level drawn from a set including read access, write access, execute access, read/write access, read/execute access, write/execute access, and read/write/execute access; and

granting the user access to the resource if the applicable access controls in relation to the current clock value and the applicable access level permit the group access to the resource using the access type.

12. A method according to claim 11 , further comprising denying the user access to the resource if the applicable access controls do not permit the group access to the resource.

13. A method according to claim 11 , further comprising receiving a login request from the user prior to receiving the request.

14. A method according to claim 13 , wherein receiving a login request includes:

determining a second current clock value of the login request;

identifying a time-based login limitation for the user; and

determining if the user is permitted to login based on the second current clock value and the time-based login limitation for the user.

15. A method according to claim 11 , wherein:

determining a current clock value includes determining a current date; and

identifying access controls applicable to the resource for the group based on the current clock value includes identifying access controls applicable to the resource for the group based on the current date.

16. A method according to claim 11 , wherein:

determining a current clock value includes determining a current time; and

identifying access controls applicable to the resource for the group based on the current clock value includes identifying access controls applicable to the resource for the group based on the current time.

17. A method according to claim 1 , further comprising:

identifying a third access control applicable to the resource for a second group based on the current clock value, wherein the user is a member of the second group including the user and a third user; and

granting the user access to the resource if the third access control in relation to the current clock value and the applicable access level permits the third group access to the resource using the access type.

18. A memory for storing data for access on a computer system, comprising:

a data structure stored in the memory, the data structure including:

an access level for a specific resource, the access level drawn from a set including read access, write access, execute access, read/write access, read/execute access, write/execute access, and read/write/execute access;

a group identifier identifying a group including at least a user identified by a user identifier and a second user identified by a second user identifier; and

a clock interval during which the access level for said resource is permitted,

wherein the data structure is one of a plurality of access control structures for the resource associated with one of a plurality of group identifiers.

19. A memory according to claim 18 , wherein the clock interval includes a time interval identifying hours of a day when the access level for said resource is permitted.

20. A memory according to claim 19 , wherein the clock interval further includes a date interval identifying dates on a calendar when the access level for said resource is permitted.

21. A memory according to claim 18 , wherein the clock interval includes a date interval identifying dates on a calendar when the access level for said resource is permitted.

22. A memory according to claim 18 , wherein the data structure further includes an identifier for the data structure.

23. A memory according to claim 18 , wherein the data structure further includes an identifier for said resource.

24. A memory according to claim 18 , the memory further comprising a second data structure stored in the memory, the second data structure comprising:

a second access level for a specific resource, the second access level drawn from a set including read access, write access, execute access, read/write access, read/execute access, write/execute access, and read/write/execute access;

a second group identifier identifying a second group including at least the user identified by the user identifier and a third user identified by a third user identifier; and

a clock interval during which the access level for said resource is permitted.

25. An article, comprising a non-transitory storage medium, said non-transitory storage medium having stored thereon instructions, that, when executed by a machine, result in:

receiving a request from a user to specifically access a resource using an access type, the user a member of a group including at least the user identified by a user identifier and a second user identified by a second user identifier;

determining a current clock value;

identifying at least one access controls applicable to the resource for the group based on the current clock value, the access control one of a plurality of access controls associated with the resource and a plurality of group identifiers, each of the access controls including an access level, the access level drawn from a set including read access, write access, execute access, read/write access, read/execute access, write/execute access, and read/write/execute access; and

granting the user access to the resource if the applicable access controls in relation to the current clock value and the applicable access level permit the group access to the resource using the access type.

26. An article according to claim 25 , said non-transitory storage medium having stored thereon further instructions that, when executed by said machine, result in denying the user access to the resource if the applicable access controls do not permit the group access to the resource.

27. An article according to claim 25 , said non-transitory storage medium having stored thereon further instructions that, when executed by said machine, result in receiving a login request from the user prior to receiving the request.

28. An article according to claim 27 , wherein receiving a login request includes:

determining a second current clock value of the login request;

identifying a time-based login limitation for the user; and

determining if the user is permitted to login based on the second current clock value and the time-based login limitation for the user.

29. An article according to claim 25 , wherein:

determining a current clock value includes determining a current date; and

identifying access controls applicable to the resource for the group based on the current clock value includes identifying access controls applicable to the resource for the group based on the current date.

30. An article according to claim 25 , wherein:

determining a current clock value includes determining a current time; and

identifying access controls applicable to the resource for the group based on the current clock value includes identifying access controls applicable to the resource for the group based on the current time.

31. An article according to claim 25 , said non-transitory storage medium having stored thereon further instructions that, when executed by said machine, result in:

identifying a third access control applicable to the resource for a second group based on the current clock value, wherein the user is a member of the second group including the user and a third user; and

granting the user access to the resource if the third access control in relation to the current clock value and the applicable access level permits the third group access to the resource using the access type.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2007
From: STOKES, RANDALL K
To: NOVELL, INC.
Reel/Frame 019481/0619 →
Continuity (1)
Related Publication 20090007229A1 · Jan 1, 2009