IP Library Granted Patent US 7,886,053
Granted Patent B1
US 7,886,053 · App. 12/560,388 · Granted Feb 8, 2011

Self-management of access control policy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,886,053
App. No.
12/560,388
Granted
Feb 8, 2011
Kind
B1
Abstract

A self access management system allows users to self-grant access rights to resources. An access policy specifies which users have what levels of access to which resources. In addition to specifying conventional access rights, the access policy specifies that at least one user has self management rights to at least one resource. A request from a user to access a resource to which the user does not have conventional access rights is received. The access policy is consulted, to determine whether the user has self management rights to the resource. If so, it is further determined whether criteria specified by the self management rights for accessing the resource are met. Responsive to the criteria being met, the access policy is updated to grant the user access rights to the resource, according to the terms of the self management rights.

Claims (60)

1. A computer implemented method for allowing self-granting of access rights to network resources, the method comprising the steps of:

receiving, by a computer, an access control policy specifying which of a plurality of users have what access rights to which of a plurality of network resources, the access control policy specifying that at least one user has self management rights to at least one network resource;

receiving, by a computer, a request from a user to access at least one network resource to which the user does not have conventional access rights;

determining, by a computer, based on the access control policy, that the user has self management rights to the at least one network resource;

determining, by a computer, whether criteria specified by the self management rights for accessing the at least one network resource are met; and

determining, by a computer, whether to grant the user access rights to the at least one network resource responsive to whether criteria specified by the self management rights for accessing the at least one network resource are met.

2. The method of claim 1 wherein receiving, by a computer, a request from a user to access at least one network resource to which the user does not have conventional access rights further comprises:

receiving, by a computer, a request from a user to self-grant access rights to the at least one network resource.

3. The method of claim 1 wherein receiving, by a computer, a request from a user to access at least one network resource to which the user does not have conventional access rights further comprises:

intercepting, by a computer, a request from a user to be granted access rights to the at least one network resource.

4. The method of claim 1 wherein determining, by a computer, whether criteria specified by the self management rights for accessing the at least one network resource are met further comprises:

determining, by a computer, whether the user occupies a specific position within an enterprise organizational structure.

5. The method of claim 1 wherein determining, by a computer, whether criteria specified by the self management rights for accessing the at least one network resource are met further comprises:

determining, by a computer, that the user requires a reference from a second user with access rights to the at least one network resource.

6. The method of claim 5 further comprising:

responsive to receiving a reference from a second user with access rights to the at least one network resource, determining, by a computer, that the criteria specified by the self management rights for accessing the at least one network resource are met.

7. The method of claim 5 further comprising:

responsive to not receiving a reference from a second user with access rights to the at least one network resource, determining, by a computer, that the criteria specified by the self management rights for accessing the at least one network resource are not met.

8. The method of claim 1 further comprising:

responsive to determining, by a computer, that the criteria specified by the self management rights for accessing the at least one network resource are met, updating the access control policy, by a computer, to grant the user access rights to the at least one network resource, according to terms of the self management rights.

9. The method of claim 8 wherein updating the access control policy, by a computer, to grant the user access rights to the at least one network resource, according to the terms of the self management rights, further comprises:

updating the access control policy, by a computer, to grant the user access rights to the at least one network resource for a limited duration of time, according to the terms of the self management rights.

10. The method of claim 9 further comprising:

responsive to occurrence of the limited duration of time, updating the access control policy, by a computer, to terminate the access rights granted to the user to the at least one network resource.

11. The method of claim 8 wherein updating the access control policy, by a computer, to grant the user access rights to the at least one network resource, according to the terms of the self management rights, further comprises:

updating the access control policy, by a computer, to grant the user limited access rights to the at least one network resource, according to the terms of the self management rights.

12. The method of claim 1 further comprising:

automatically sending, by a computer, an indication to a third party that the user requested self management rights to the at least one network resource.

13. The method of claim 1 further comprising:

automatically sending, by a computer, an indication to a third party that the user successfully obtained access to the at least one network resource by using self management rights.

14. At least one non-transitory computer readable storage medium storing a computer program product for allowing self-granting of access rights to network resources, the computer program product comprising:

program code for receiving an access control policy specifying which of a plurality of users have what access rights to which of a plurality of network resources, the access control policy specifying that at least one user has self management rights to at least one network resource;

program code for receiving a request from a user to access at least one network resource to which the user does not have conventional access rights;

program code for determining, based on the access control policy, that the user has self management rights to the at least one network resource;

program code for determining whether criteria specified by the self management rights for accessing the at least one network resource are met; and

program code for determining whether to grant the user access rights to the at least one network resource responsive to whether criteria specified by the self management rights for accessing the at least one network resource are met.

15. The computer program product of claim 14 wherein the program code for determining whether criteria specified by the self management rights for accessing the at least one network resource are met further comprises:

program code for determining whether the user occupies a specific position within an enterprise organizational structure.

16. The computer program product of claim 14 wherein the program code for determining whether criteria specified by the self management rights for accessing the at least one network resource are met further comprises:

program code for determining that the user requires a reference from a second user with access rights to the at least one network resource;

program code for, responsive to receiving a reference from a second user with access rights to the at least one network resource, determining that the criteria specified by the self management rights for accessing the at least one network resource are met; and

program code for, responsive to not receiving a reference from a second user with access rights to the at least one network resource, determining that the criteria specified by the self management rights for accessing the at least one network resource are not met.

17. The computer program product of claim 14 further comprising:

program code for, responsive to determining that the criteria specified by the self management rights for accessing the at least one network resource are met, updating the access control policy to grant the user access rights to the at least one network resource, according to terms of the self management rights;

program code for updating the access control policy to grant the user access rights to the at least one network resource for a limited duration of time, according to the terms of the self management rights;

program code for, responsive to occurrence of the limited duration of time, updating the access control policy to terminate the access rights granted to the user to the at least one network resource; and

program code for updating the access control policy to grant the user limited access rights to the at least one network resource, according to the terms of the self management rights.

18. The computer program product of claim 14 further comprising:

program code for automatically sending an indication to a third party that the user requested self management rights to the at least one network resource.

19. The computer program product of claim 14 further comprising:

program code for automatically sending an indication to a third party that the user successfully obtained access to the at least one network resource by using self management rights.

20. A computer system configured to allow self-granting of access rights to network resources, the computer system comprising:

a processor;

a system memory;

an access rights receiving module configured to receive an access control policy specifying which of a plurality of users have what access rights to which of a plurality of network resources, the access control policy specifying that at least one user has self management rights to at least one network resource; and

a self access granting module configured to:

1) receive a request from a user to access at least one network resource to which the user does not have conventional access rights;

2) determine, based on the access control policy, that the user has self management rights to the at least one network resource;

3) determine whether criteria specified by the self management rights for accessing the at least one network resource are met; and

4) determine whether to grant the user access rights to the at least one network resource responsive to whether criteria specified by the self management rights for accessing the at least one network resource are met.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2009
From: NEWSTADT, KEITH; GIBSON, DOUGLAS
To: SYMANTEC CORPORATION
Reel/Frame 023529/0022 →