IP Library › Granted Patent US 9,659,166
Granted Patent B2
US 9,659,166 · App. 14/609,578 · Granted May 23, 2017

Risk-based credential management

Inventors: Leigh T. Doddy (Sunbury, AU); Christopher J. Hockings (Burleigh Waters, AU); Dinesh T. Jain (Pune, IN); Philip A. J. Nye (Southport, AU)
Assignee: International Business Machines Corporation
G06F21/45H04L63/10H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,659,166
App. No.
14/609,578
Granted
May 23, 2017
Kind
B2
Abstract

Risk-based credential management is provided. A request to checkout credentials is received. The credentials are associated with at least one managed resource. A risk value of the request is determined. The determination of the risk value is based, at least in part, on risk information of the requesting device. A determination is made whether to deny the request based, at least in part, on the risk value and a first predetermined threshold of a checkout policy.

Claims (26)

1. A computer program product for credential management, the computer program product comprising: a computer readable storage medium and program instructions stored on the computer readable storage medium, the program instructions comprising:

program instructions to receive, from a requesting device, a request to checkout credentials, wherein the credentials are associated with at least one managed resource;

program instructions to determine a risk value of the request, wherein the determination of the risk value is based, at least in part, on risk information of the requesting device; and

program instructions to determine whether to deny the request based, at least in part, on the risk value and a first predetermined threshold of a checkout policy by classifying certain types of malware of the requesting device.

2. The computer program product of claim 1 , wherein the program instructions to determine whether to deny the request further comprise:

program instructions to determine that the risk value violates the first predetermined threshold and, in response, deny the request; and

program instructions to determine that the risk value does not violate the first predetermined threshold and, in response, grant the request.

3. The computer program product of claim 2 , the program instructions to determine whether to deny the request is further based on a security status of each of the at least one managed resources.

4. The computer program product of claim 3 , the program instructions further comprising:

program instructions to, responsive to determining that the security status indicates that a first managed resource of the at least one managed resource is compromised, deny the request.

5. The computer program product of claim 1 , wherein the credentials authorize access to the at least one managed resource associated with the credentials.

6. The computer program product of claim 1 , wherein the risk value is based, at least in part, on one or more types of risk information that are specified by the checkout policy.

7. A computer system for credential management, the computer system comprising:

one or more computer processors; one or more computer readable storage media;

program instructions stored on the computer readable storage media for execution by at least one of the one or more processors, the program instructions comprising:

program instructions to receive, from a requesting device, a request to checkout credentials, wherein the credentials are associated with at least one managed resource;

program instructions to determine a risk value of the request, wherein the determination of the risk value is based, at least in part, on risk information of the requesting device; and

program instructions to determine whether to deny the request based, at least in part, on the risk value and a first predetermined threshold of a checkout policy by classifying certain types of malware of the requesting device.

8. The computer system of claim 7 , wherein the program instructions to determine whether to deny the request further comprise:

program instructions to determine that the risk value violates the first predetermined threshold and, in response, deny the request; and

program instructions to determine that the risk value does not violate the first predetermined threshold and, in response, grant the request.

9. The computer system of claim 8 , the program instructions to determine whether to deny the request is further based on a security status of each of the at least one managed resources.

10. The computer system of claim 9 , the program instructions further comprising:

program instructions to, responsive to determining that the security status indicates that a first managed resource of the at least one managed resource is compromised, deny the request.

11. The computer system of claim 7 , wherein the credentials authorize access to the at least one managed resource associated with the credentials.

12. The computer system of claim 7 , wherein the risk value is based, at least in part, on one or more types of risk information that are specified by the checkout policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2015
From: DODDY, LEIGH T.; HOCKINGS, CHRISTOPHER J.; JAIN, DINESH T.; NYE, PHILIP A.J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 034850/0852 →
Continuity (1)
Related Publication 20160224781A1 · Aug 4, 2016