IP Library Granted Patent US 8,595,799
Granted Patent B2
US 8,595,799 · App. 13/449,908 · Granted Nov 26, 2013

Access authorization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,595,799
App. No.
13/449,908
Granted
Nov 26, 2013
Kind
B2
Abstract

Methods, systems, and computer-readable media with executable instructions stored thereon for managing access authorization to hardware and data resources. A method includes defining a property of a hardware and/or data resource. This example method further includes defining a role such that each defined role can be applied to different users without modification, defining a security domain for the property of the resource in the context of a user-role assignment and assigning a role to a user in a context of the defined security domain.

Claims (28)

1. A method for managing access authorization to hardware and data resources, comprising:

using an access engine having a processing resource to execute computer readable instructions stored on a non-transitory medium to:

define a property of a resource;

define a role having permissions, wherein each defined role can be reused with different users without modification;

define a security domain for the property of the resource;

assign the defined role to a user in a context of the defined security domain wherein the context of the defined security domain restricts a permission of the defined role assigned to the user; and

assign a purpose, a condition, and a location attribute to a user-role assignment, wherein the attribute applies to all permissions for the user-role assignment rather than on a permission by permission basis.

2. The method of claim 1 , wherein defining a role includes defining a role including at least one of an administrate role and a viewer role.

3. The method of claim 2 , wherein the method includes assigning a permission to a role, wherein assigning a permission includes at least one of an edit and view permission and a view only permission.

4. A non-transitory computer-readable medium storing a set of instructions executable by a computer, wherein the set of instructions are executed by the computer to:

define a property of a network resource;

define a tenant as associated with the property of the resource;

define a role having permissions, wherein each defined role can be reused with different users without modification;

define a security domain for the property of the resource;

assign the defined role to a user in the context of the defined security domain;

assign at lease one of a purpose, a condition, and a location attribute to a user-role assignment; and

assign the defined security domain to the tenant along with the assigned user-role assignment, wherein the defined security domain restricts a permission of the defined role in the user-role assignment rather than on a permission by permission basis.

5. The non-transitory computer readable medium of claim 4 , wherein the set of instructions are executed to define a security domain include associating a user to a role in defining a security domain in connection with each user of a tenant.

6. The non-transitory computer readable medium of claim 5 , wherein the set of instructions are executed to create the user-role association upon at least one of creating a new tenant, defining a new security domain, adding a new user, removing a user, defining a new role associated with a user.

7. A system for managing access authorization to hardware and data resources, the system comprising:

an access control engine having:

a processing resource; and

a non-transitory computer readable medium, wherein the non-transitory computer readable medium includes instructions segmented into a number of modules, the number of modules including:

a role module including instructions executed by the processing resource to define a role having permissions, wherein each defined role can be reused with different users without modification;

a security domain module including instructions executed by the processing resource to define a security domain according to a property of a resource in a context of a user-role assignment such that the defined security domain distinguishes between different resource scopes according to a classification of resources;

a permission module including instructions executed by the processing resource to grant a role to a user in the context of the security domain; and

an attribute module including instructions executed by the processing resource to assign a purpose, a condition, and a location attribute to a user-role assignment such that the attribute applies to all permissions for the user-role assignment rather than on a permission by permission basis.

8. The system of claim 7 , wherein the security domain module includes instructions executed to distinguish between different classifications of resources selected from a region, a tenant, and a company.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 063546/0181) Recorded Jun 21, 2024
From: BARCLAYS BANK PLC
To: MICRO FOCUS LLC
Reel/Frame 067807/0076 →
SECURITY INTEREST Recorded Aug 30, 2023
From: MICRO FOCUS LLC
To: THE BANK OF NEW YORK MELLON
Reel/Frame 064760/0862 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0181 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0190 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0230 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →