IP Library Granted Patent US 9,432,404
Granted Patent B1
US 9,432,404 · App. 14/014,359 · Granted Aug 30, 2016

System for managing access to protected resources

Inventor: Michael W. Roegner (Plano, TX)
Assignee: Jericho Systems Corporation
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,432,404
App. No.
14/014,359
Granted
Aug 30, 2016
Kind
B1
Abstract

A rules evaluation engine that controls user's security access to enterprise resources that have policies created for them. This engine allows real time authorization process to be performed with dynamic enrichment of the rules if necessary. Logging, alarm and administrative processes for granting or denying access to the user are also realized. The access encompasses computer and physical access to information and enterprise spaces.

Claims (31)

1. A system for managing requests, the system comprising:

a policy enforcement point, implemented on one or more servers, configured to intercept communications;

a policy repository;

one or more security servers configured to:

receive requests for authorization from the policy enforcement point;

retrieve, from the policy repository, a dynamically-loadable security access policy associated with one or more protected resources, wherein the dynamically-loadable security access policy comprises one or more rules;

determine at least one attribute required by at least one of the rules of the dynamically-loadable security access policy retrieved from the policy repository and associated with the one or more protected resources:

for at least one of the attributes required by a rule of the dynamically-loadable security access policy retrieved from the policy repository and associated with the one or more protected resources, determine whether an attribute value must be requested;

request at least one of the attribute values that must be requested from a remote data source;

retrieve from the remote data source the at least one of the attribute values:

evaluate the security access policy retrieved from the policy repository and associated with the one or more protected resources using the at least one of the attribute values from the remote data source; and

return an authorization decision to the policy enforcement point.

2. The system of claim 1 , wherein the security access policy determines authorization to access an internal network.

3. The system of claim 1 , wherein the security access policy determines authorization to access a document.

4. The system of claim 1 , wherein the remote data source is an LDAP directory.

5. The system of claim 1 , wherein the remote data source is an SQL database.

6. The system of claim 1 , wherein the remote data source is a human resources database.

7. A method to process requests, the method comprising:

receiving, by a security server, an authorization request from a policy enforcement point;

retrieving from a policy repository a dynamically-loadable security access policy associated with one or more protected resources, wherein the dynamically-loadable security access policy comprises one or more rules;

determining at least one attribute required by at least one of the rules of the dynamically-loadable security access policy retrieved during said retrieving from the policy repository, and associated with the one or more protected resources;

determining, for at least one of the attributes retrieved during said retrieving from the policy repository, and associated with the one or more protected resources required by a rule of the dynamically-loadable security access policy, whether an attribute value must be requested;

requesting at least one of the attribute values that must be requested from a remote data source;

retrieving from the remote data source the at least one of the attribute values;

evaluating the dynamically-loadable security access policy retrieved during said retrieving from the policy repository, and associated with the one or more protected resources using at least one of the attribute values from the remote data source; and

returning an authorization decision to the policy enforcement point.

8. The method of claim 7 , wherein the policy determines authorization to access an internal network.

9. The method of claim 7 , wherein the dynamically-loadable security access policy determines authorization to access a document.

10. The method of claim 7 , wherein the remote data source is an LDAP directory.

11. The method of claim 7 , wherein the remote data source is an SQL database.

12. The method of claim 7 , wherein the remote data source is a human resources database.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: BIN 2020, SERIES 550 ALLIED SECURITY TRUST I
To: CROWDSTRIKE, INC.
Reel/Frame 058310/0455 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2020
From: JERICHO SYSTEMS CORPORATION
To: BIN 2020, SERIES 550 OF ALLIED SECURITY TRUST I
Reel/Frame 052831/0119 →
Continuity (3)
Continuation 12658421 · Feb 11, 2010
Continuation 10755173 · Jan 9, 2004
Provisional Application 60438972 · Jan 9, 2003