IP Library Granted Patent US 9,438,559
Granted Patent B1
US 9,438,559 · App. 14/014,354 · Granted Sep 6, 2016

System for managing access to protected resources

Inventor: Michael W. Roegner (Plano, TX)
Assignee: Jericho Systems Corporation
H04L63/02H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,438,559
App. No.
14/014,354
Granted
Sep 6, 2016
Kind
B1
Abstract

A rules evaluation engine that controls user's security access to enterprise resources that have policies created for them. This engine allows real time authorization process to be performed with dynamic enrichment of the rules if necessary. Logging, alarm and administrative processes for granting or denying access to the user are also realized. The access encompasses computer and physical access to information and enterprise spaces.

Claims (32)

1. A system for managing requests from at least one external network, the system comprising:

a firewall configured to determine one or more resources a requestor is attempting to access;

a policy repository;

one or more security policy management servers configured to:

receive an authorization request from the firewall, wherein the request comprises information about the requestor and a resource name;

retrieve, from the policy repository, a dynamically-loadable security access policy associated with the named resource, wherein the dynamically-loadable security access policy comprises one or more rules that indicate conditions under which a request to perform an action on the resource should be granted;

determine at least one attribute required by at least one of the rules of the dynamically-loadable security access policy retrieved from the policy repository and associated with the named resource:

for at least one of the attributes required by a rule of the dynamically-loadable security access policy retrieved from the policy repository and associated with the named resource, determine whether an attribute value must be requested from a remote data source;

request at least one of the attribute values required by a rule of the dynamically-loadable security access policy retrieved from the policy repository and associated with the named resource that must be requested from the remote data source;

retrieve from the remote data source the at least one of the attribute values; evaluate the dynamically-loadable security access policy retrieved from the policy repository and associated with the named resource using the at least one of the attribute values from the remote data source; and

return an authorization decision to the firewall.

2. The system of claim 1 , wherein the dynamically-loadable security access policy determines authorization to access an internal network.

3. The system of claim 1 , wherein the dynamically-loadable security access policy determines authorization to access a document.

4. The system of claim 1 , wherein the remote data source is an LDAP directory.

5. The system of claim 1 , wherein the remote data source is an SQL database.

6. The system of claim 1 , wherein the remote data source is a human resources database.

7. The system of claim 1 , wherein the determination of the one or more resources by the firewall further comprises using one or more transactional headers.

8. A method to process requests from at least one external network, the method comprising:

receiving an authorization request from a firewall configured to determine one or more resources a requestor is attempting to access, wherein the request comprises information about the requestor and a resource name;

retrieving from a policy repository a dynamically-loadable security access policy associated with the named resource, wherein the dynamically-loadable security access policy comprises one or more rules that indicate conditions under which a request to perform an action on the resource should be granted;

determining at least one attribute required by at least one of the rules of the dynamically-loadable security access policy retrieved from the policy repository during said retrieving and associated with the named resource;

determining, for at least one of the attributes required by a rule of the dynamically-loadable security access policy retrieved from the policy repository during said retrieving and associated with the named resource, whether an attribute value must be requested from a remote data source;

requesting at least one of the attribute values that must be requested from the remote data source;

retrieving from the remote data source the at least one of the attribute values; evaluating, by a security policy management server, the dynamically-loadable security access policy retrieved from the policy repository during said retrieving and associated with the named resource using the at least one of the attribute values from the remote data; and

returning an authorization decision to the firewall.

9. The method of claim 8 , wherein the dynamically-loadable security access policy determines authorization to access an internal network.

10. The method of claim 8 , wherein the dynamically-loadable security access policy determines authorization to access a document.

11. The method of claim 8 , wherein the remote data source is an LDAP directory.

12. The method of claim 8 , wherein the remote data source is an SQL database.

13. The method of claim 8 , wherein the remote data source is a human resources database.

14. The system of claim 1 wherein said one or more security policy management servers is configured to at least one of the attributes required by a rule of the dynamically-loadable security access policy, to dynamically determine whether an attribute value must be requested from a remote data source.

15. The method of claim 8 wherein said determining whether an attribute value must be requested comprises dynamically determining whether an attribute value must be requested.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: BIN 2020, SERIES 550 ALLIED SECURITY TRUST I
To: CROWDSTRIKE, INC.
Reel/Frame 058310/0455 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2020
From: JERICHO SYSTEMS CORPORATION
To: BIN 2020, SERIES 550 OF ALLIED SECURITY TRUST I
Reel/Frame 052831/0119 →
Continuity (3)
Continuation 12658421 · Feb 11, 2010
Continuation 10755173 · Jan 9, 2004
Provisional Application 60438972 · Jan 9, 2003