IP Library Granted Patent US 8,458,230
Granted Patent B2
US 8,458,230 · App. 13/526,480 · Granted Jun 4, 2013

System and method for flexible security access management in an enterprise

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,458,230
App. No.
13/526,480
Granted
Jun 4, 2013
Kind
B2
Abstract

Some embodiments provide a method and system for flexibly managing access to enterprise resources. To flexibly manage security, some embodiments secure the enterprise resources and provide a security access manager (SAM) to control access to the secured resources. The SAM controls access to the enterprise and the secure resources through one or more configurable management modules of the SAM. Each management module of the SAM is configurable to facilitate control over different security services of an enterprise security hierarchy (e.g., authentication, authorization, role mapping, etc.). Specifically, each management module is configurable to leverage security services that are provided by different security systems. In some embodiments, the management module is configured to interface with one or more adapters in order to establish the interfaces, logic, and protocols necessary to leverage the security functionality of such security systems.

Claims (28)

1. For a security access manager for use in a data management system that manages access to data resources of an enterprise, a method for securing access to the data resources, said method comprising:

providing a first security module for authenticating an identity of a user of a client application by (i) accessing an external user directory that is a part of an existing security system of the enterprise which operates outside of the data management system and (ii) verifying the identity of the user against the external user directory;

providing a second security module for alternatively authenticating the identity of the user of the client application by (i) accessing an internal user directory that is a part of the data management system and (ii) verifying the identity of the user against the internal user directory;

providing a third security module for authorizing the user to access a set of secured data resources by accessing a first policy data store that is a part of the data management system upon verification of the identity of the user with the first or second security module; and

providing a fourth security module for alternatively authorizing the user to access the set of secured data resources by accessing a second policy data store that is a part of the existing enterprise security system,

wherein said first, second, third, and fourth modules are modules of the security access manager.

2. The method of claim 1 , wherein the first security module is for performing a first level authentication of the identity of the user and the second security module is for performing a second level authentication of the identity of the user upon failure to authenticate the identity of the user against the external user directory.

3. The method of claim 1 , wherein the first security module authenticates the identity of the user by interfacing with an adapter module that converts a messaging format of the security access manager to a messaging format of the existing security system.

4. The method of claim 1 , wherein the identity of the user comprises a plurality of identifiers, wherein the first security module verifies the identity of the user using a first identifier and the second security module verifies the identity of the user using a second different identifier.

5. The method of claim 4 , wherein the first identifier is a user name and the second identifier is an email address, wherein the first security module performs a first level authentication by verifying the user name against the external user directory, wherein the second security module performs a second level authentication by verifying the email address against the internal user directory.

6. The method of claim 4 , wherein the first identifier is an email address and the second identifier is a user name, wherein the first security module performs a first level authentication by verifying the email address against the external user directory, wherein the second security module performs a second level authentication by verifying the user name against the internal user directory.

7. The method of claim 1 , wherein the third and fourth security modules are for performing a first subset of authorization services to authorize the user to access the set of secured data resources, the method further comprising providing a fifth security module for performing a second subset of authorization services to authorize the user to access the set of secured data resources.

8. The method of claim 7 , wherein the first subset of authorization services comprises policy-based access control services, and the second subset of authorization services comprises role-based access control services.

9. The method of claim 1 , wherein the external user directory is an external user directory developed by a third party independent of the data management system.

10. A non-transitory computer readable storage medium storing a data management system having:

a security access manager for securing access to data resources of an enterprise, the security access manager comprising:

a first security module for authenticating an identity of a user of a client application by (i) accessing an external user directory that is a part of an existing security system of the enterprise which operates outside of the data management system and (ii) verifying the identity of the user against the external user directory;

a second security module for alternatively authenticating the identity of the user of the client application by (i) accessing an internal user directory that is a part of the data management system and (ii) verifying the identity of the user against the internal user directory;

a third security module for authorizing the user to access a set of secured data resources by accessing a first policy data store that is a part of the data management system upon verification of the identity of the user with the first or second security module; and

a fourth security module for alternatively authorizing the user to access the set of secured data resources by accessing a second policy data store that is a part of the existing security system, wherein said first, second, third, and fourth modules are modules of the security access manager.

11. The non-transitory computer readable storage medium of claim 10 , wherein the first security module is for performing a first level authentication of the identity of the user and the second security module is for performing a second level authentication of the user upon failure to authenticate the identity of the user against the external user directory.

12. The non-transitory computer readable storage medium of claim 10 , wherein the data management system comprises a Customer Relationship Management (CRM) system of the enterprise and said security access manager manages access to data resources accessed by said CRM system.

13. The non-transitory computer readable storage medium of claim 10 , wherein the data management system comprises an Enterprise Resource Planning (ERP) system of the enterprise and said security access manager manages access to data resources accessed by said ERP system.

14. The non-transitory computer readable storage medium 10 further comprising a management module for distributing requests to the first and second security modules, wherein each request comprises an identity of a user to be authenticated.

15. The non-transitory computer readable storage medium 14 , wherein the management module is further for managing responses received from the first and second security modules.

16. The non-transitory computer readable storage medium 10 , wherein the third and fourth security modules are for performing a first subset of authorization services to authorize the user to access the set of secured data resources, wherein the security access manager further comprises a fourth fifth security module for performing a second subset of authorization services to authorize the user to access the set of secured data resources.

17. The non-transitory computer readable storage medium of claim 10 , wherein the first security module authenticates the identity of the user by interfacing with an adapter module that converts a messaging format of the security access manager to a messaging format of the existing security system.

18. The non-transitory computer readable storage medium of claim 10 , wherein the external user directory is an external user directory developed by a third party independent of the data management system.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: JPMORGAN CHASE BANK, N.A.
To: INFORMATICA LLC
Reel/Frame 073597/0722 →
RELEASE OF SECURITY INTEREST Recorded Oct 29, 2021
From: NOMURA CORPORATE FUNDING AMERICAS, LLC
To: INFORMATICA LLC
Reel/Frame 057973/0496 →
RELEASE OF SECURITY INTEREST Recorded Oct 29, 2021
From: NOMURA CORPORATE FUNDING AMERICAS, LLC
To: INFORMATICA LLC
Reel/Frame 057973/0507 →
SECURITY INTEREST Recorded Oct 29, 2021
From: INFORMATICA LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057973/0568 →
SECURITY INTEREST Recorded Feb 26, 2020
From: INFORMATICA LLC
To: NOMURA CORPORATE FUNDING AMERICAS, LLC
Reel/Frame 052022/0906 →
NOTICE OF SUCCESSION OF AGENCY Recorded Feb 25, 2020
From: BANK OF AMERICA, N.A.
To: NOMURA CORPORATE FUNDING AMERICAS, LLC
Reel/Frame 052018/0070 →
SECURITY AGREEMENT Recorded Aug 6, 2015
From: INFORMATICA CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 036294/0701 →