IP Library Granted Patent US 9,390,276
Granted Patent B2
US 9,390,276 · App. 14/041,203 · Granted Jul 12, 2016

Flexible role based authorization model

Inventors: Don Paul Steiner (Centerville, OH); Bruce Daniel Maxfield (Liberty Township, OH); William Donald Kilgallon (Lebanon, OH)
Assignee: LexisNexis, a division of Reed Elsevier Inc.
G06F21/604G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,390,276
App. No.
14/041,203
Granted
Jul 12, 2016
Kind
B2
Abstract

Systems and methods described herein relate to role-based authorization systems which allow customization of role templates as well as the ability, using roles, for one user to act on behalf of another user.

Claims (28)

1. A computer machine system comprising one or more computer machines wherein said computer machine system further comprises:

at least one computer memory comprising a rights database configured to store:

a set of roles, wherein each role is associated with one or more capabilities;

a set of user identifiers, wherein each user identifier is associated with:

a specific user;

one or more roles from said set of roles; and

one or more capabilities from each of said roles;

at least one policy decision point configured to authorize a service request received from a policy enforcement point, wherein:

said policy decision point determines if a first set of capabilities allocated to a first role, wherein said first role is specified in a request header associated with said service request, matches a set of required privileges necessary to perform said service request;

said request header comprises said first role and a second role, wherein said first role is assigned to a first user and said second role is assigned to a second user, and wherein said second user is acting on behalf of said first user;

said policy decision point determines if a second set of capabilities allocated to the first user, wherein said first user is specified in said request header, acting as said first role matches said set of required privileges necessary to perform said service request; and

said policy decision point determines if a third set of capabilities, assigned to said second role and associated with said second user, matches said set of required privileges necessary for said second user to perform said service request on behalf of said first user in said first role.

2. A computer machine system as claimed in claim 1 wherein said policy enforcement point comprises a resource-based web service further comprising a set of content and report functionality.

3. A computer machine system as claimed in claim 1 wherein said second user's role is defined according to the capabilities associated with a customer care representative.

4. A computer machine system as claimed in claim 3 wherein said second user is not able to authenticate as the first user.

5. A computer machine implemented authorization process comprising:

receiving a service request at a policy enforcement point computer machine, from an application, comprising a first request header identifying:

a first user and a first role, wherein a first set of capabilities associated with said first user are a subset of a second set of capabilities associated with said first role, and

a second user and a second role, wherein the second role corresponds to a selected capacity in which the second user is acting;

sending an authorization request to a policy decision point further comprising a second request header identifying:

said first user and said first role, and

said second user and said second role;

receiving, from said policy decision point, an authorization or a denial to perform one or more aspects of said service request wherein said service request may only be granted for a specific set of capabilities defined in a computer memory for both said first user and said first role; and

receiving, from said policy decision point, an authorization or denial to perform one or more aspects of said service request wherein said service request may only be granted for a specific set of capabilities defined in a computer memory for some combination of said first and second users and said first and second roles,

wherein said second user is acting on behalf of said first user in said first role.

6. A computer machine implemented authorization process as claimed in claim 5 wherein: said first role was selected by said first user from a set of possible roles assigned to said first user.

7. A computer machine implemented authorization process as claimed in claim 5 wherein: said first role was selected by said policy decision point, from a set of possible roles assigned to said first user, according to a least privilege principle.

8. A computer machine implemented authorization process as claimed in claim 5 wherein said policy enforcement point receives said denial if said service request requires a different role.

Assignments (2)
CHANGE OF NAME Recorded Dec 3, 2019
From: LEXISNEXIS; REED ELSEVIER INC.
To: RELX INC.
Reel/Frame 051198/0325 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2013
From: STEINER, DON PAUL; MAXFIELD, BRUCE DANIEL; KILGALLON, WILLIAM DONALD
To: LEXISNEXIS, A DIVISION OF REED ELSEVIER INC.
Reel/Frame 031308/0656 →
Continuity (1)
Related Publication 20150095968A1 · Apr 2, 2015