IP Library Granted Patent US 9,450,940
Granted Patent B2
US 9,450,940 · App. 14/612,983 · Granted Sep 20, 2016

Intelligent system for enabling automated secondary authorization for service requests in an agile information technology environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,450,940
App. No.
14/612,983
Granted
Sep 20, 2016
Kind
B2
Abstract

A service request for a managed computer system is received and once a primary authorization for same has been given, a secondary authorization management system (SAMS) determines whether or not the service request requires secondary authorization. This determination is made according to a context of the managed computer system and an authorization profile for the received service request. If needed, the SAMS resolves the secondary authorization request and returns the resolution decision.

Claims (22)

1. A method comprising:

receiving, by an access control system, a service request for at least one managed computer system from an entity, the entity having an access right for requesting the received service request of the managed computer system;

subsequent to the service request receiving a primary authorization, determining dynamically, according to a context of the managed computer system and an authorization profile for the received service request, by the access control system that the service request requires secondary authorization, the authorization profile for the received service request being retrieved from at least one knowledge system associated with the managed computer system;

sending, by the access control system and based upon the determination, the service request and a secondary authorization request to a secondary authorization management system;

resolving, by the secondary authorization management system, the secondary authorization request;

returning, by the secondary authorization management system, a resolution of the secondary authorization request to the access control system;

logging the context for the managed computer system, the service request, a secondary authorization result, and a service request result;

identifying a pattern and adding the pattern to the at least one knowledge system with the secondary authorization result; and

determining whether to provide the secondary authorization result in response to a secondary authorization request for another received service request based upon a comparison with the identified pattern.

2. The method of claim 1 , wherein said resolution of the secondary authorization request depends upon resolution of one or more contingencies.

3. The method of claim 2 , further comprising receiving from the at least one knowledge system information indicative of whether the one or more contingencies were met.

4. The method of claim 1 , wherein the at least one knowledge system comprises at least one of an internal knowledge system, an authorization profile knowledge system, an external authorization system, a capacity management system, a licensing server, and a change management system.

5. The method of claim 1 , wherein the at least one context comprises an external consideration for the managed computer system.

6. The method of claim 1 , wherein the entity comprises a computer resource within the managed computer system.

7. A system comprising a managed computer system, an access control system and a secondary authorization management system,

wherein the access control system comprises at least one hardware processor that is configured to (i) receive a service request for at least one managed computer system from an entity, the entity having an access right for requesting the received service request of the managed computer system, (ii) subsequent to the service request receiving a primary authorization, dynamically determine, according to a context of the managed computer system and an authorization profile for the received service request, that the service request requires secondary authorization, the authorization profile for the received service request being retrieved from at least one knowledge system associated with the managed computer system, and (iii) send, based upon the determination, the service request and a secondary authorization request to a secondary authorization management system; and

wherein the secondary authorization management system comprises at least one hardware processor that is configured to (i) resolve the secondary authorization request; (ii) return a resolution of the secondary authorization request to the access control system; (iii) log the context for the managed computer system, the service request, a secondary authorization result, and a service request result; (iv) identify a pattern and adding the pattern to the at least one knowledge system with the secondary authorization result; and (v) determine whether to provide the secondary authorization result in response to a secondary authorization request for another received service request based upon a comparison with the identified pattern.

8. The system of claim 7 , wherein said resolution of the secondary authorization request depends upon resolution of one or more contingencies.

9. The system of claim 8 , wherein the secondary authorization management system is further configured to receive from the at least one knowledge system information indicative of whether the one or more contingencies were met.

10. The system of claim 7 , wherein the at least one knowledge system comprises at least one of an internal knowledge system, an authorization profile knowledge system, an external authorization system, a capacity management system, a licensing server, and a change management system.

11. The system of claim 7 , wherein the at least one context comprises an external consideration for the managed computer system.

12. The system of claim 7 , wherein the entity comprises a computer resource within the managed computer system.

Assignments (6)
SECURITY INTEREST Recorded Mar 27, 2024
From: ENTRUST CORPORATION
To: BMO BANK N.A., AS COLLATERAL AGENT
Reel/Frame 066917/0024 →
MERGER Recorded Mar 18, 2024
From: HYTRUST, INC.
To: ENTRUST CORPORATION
Reel/Frame 066806/0262 →
SECURITY AGREEMENT Recorded Feb 1, 2021
From: HYTRUST, INC.
To: BMO HARRIS BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 055190/0660 →
TERMINATION OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 7, 2021
From: SILICON VALLEY BANK
To: HYTRUST, INC.
Reel/Frame 054925/0059 →
SECURITY INTEREST Recorded Sep 24, 2019
From: HYTRUST, INC.
To: SILICON VALLEY BANK
Reel/Frame 050474/0933 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2015
From: BELOV, BORIS; PRAFULLCHANDRA, HEMMA; RANGARAJAN, GOVINDARAJAN
To: HYTRUST, INC.
Reel/Frame 034879/0257 →