IP Library Granted Patent US 9,842,220
Granted Patent B1
US 9,842,220 · App. 14/683,441 · Granted Dec 12, 2017

Systems and methods of secure self-service access to content

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,842,220
App. No.
14/683,441
Granted
Dec 12, 2017
Kind
B1
Abstract

In one embodiment, a method is performed by a computer system. The method includes receiving a request from a user to access particular content. The method further includes determining a trust measure of the user, wherein the trust measure is based, at least in part, on an analysis of logged user-initiated communication events of the user on a plurality of communications platforms. In addition, the method includes accessing a self-service access policy applicable to the particular content. Further, the method includes ascertaining, from the self-service access policy, a trust threshold applicable to the particular content. Moreover, the method includes, responsive to a determination that the trust measure fails to satisfy the trust threshold, automatically denying access by the user to the particular content.

Claims (69)

1. A method comprising, by a computer system:

receiving a request from a user to access particular content;

in response to the request:

determining a trust measure of the user, wherein the trust measure is based, at least in part, on an analysis of logged user-initiated communication events of the user on a plurality of communications platforms, wherein the trust measure is variable over time in relation to the logged user-initiated communication events;

wherein the determining the trust measure comprises:

enumerating historical data loss prevention (DLP) policy violations by the user on the plurality of communications platforms;

determining a communication profile of the user based, at least in part, on the logged user-initiated communication events;

determining directory-services information for the user from a directory service; and

quantitatively evaluating a combination of the DLP policy violations, the communication profile, and the directory-services information via one or more rules, wherein the trust measure comprises a numerical result of the quantitatively evaluating;

accessing a self-service access policy applicable to the particular content;

ascertaining, from the self-service access policy, a trust threshold applicable to the particular content; and

responsive to a determination that the trust measure fails to satisfy the trust threshold, automatically denying access by the user to the particular content.

2. The method of claim 1 , wherein the enumerating comprises enumerating quasi-violations by the user on the plurality of communications platforms.

3. The method of claim 1 , wherein the determining the communication profile of the user comprises:

accessing event-assessment data for the logged user-initiated communication events, wherein each user-initiated communication event relates to at least one communication of a plurality of communications, wherein the event-assessment data comprises information related to a content-based classification of each of the plurality of communications;

determining event-context information for each of the logged user-initiated communication events, the event-context information comprising user-identification information, user-location information, event-timing information, and user-device identification information;

correlating the event-assessment data to a plurality of user contexts, each user context defined by a distinct subset of the event-context information;

associating at least one user-communication pattern with each user context based, at least in part, on the correlated event-assessment data; and

generating the communication profile using a result of the associating.

4. The method of claim 1 , wherein the determining the communication profile comprises accessing a pre-processed communication profile of the user.

5. The method of claim 1 , wherein the quantitatively evaluating comprises:

determining trust values for the historical DLP violations, the communication profile, and the directory-services information; and

wherein the trust measure is based on a combination of the trust values.

6. The method of claim 1 , wherein the determining the trust measure comprises accessing a pre-processed trust measure in memory.

7. The method of claim 1 , comprising, responsive to a determination that the trust measure satisfies the trust threshold, automatically granting access by the user to the particular content.

8. The method of claim 7 , wherein the automatically granting comprises causing the user to be added to an access control list for the particular content.

9. The method of claim 1 , wherein the trust measure comprises an allocation of virtual currency.

10. The method of claim 9 , comprising:

responsive to a determination that the trust measure satisfies the trust threshold, automatically granting access by the user to the particular content; and

decrementing the trust measure by a configurable amount.

11. The method of claim 1 , comprising:

determining information related to a current user context of the user; and

responsive to a determination that the current user context comprises an outlier condition, denying access by the user to the particular content regardless of the trust measure.

12. An information handling system comprising at least one processor coupled to a memory, wherein the at least one processor is operable to implement a method comprising:

receiving a request from a user to access particular content;

in response to the request:

determining a trust measure of the user, wherein the trust measure is based, at least in part, on an analysis of logged user-initiated communication events of the user on a plurality of communications platforms, wherein the trust measure is variable over time in relation to the logged user-initiated communication events;

wherein the determining the trust measure comprises:

enumerating historical data loss prevention (DLP) policy violations by the user on the plurality of communications platforms;

determining a communication profile of the user based, at least in part, on the logged user-initiated communication events;

determining directory-services information for the user from a directory service; and

quantitatively evaluating a combination of the DLP policy violations, the communication profile, and the directory-services information via one or more rules, wherein the trust measure comprises a numerical result of the quantitatively evaluating;

accessing a self-service access policy applicable to the particular content;

ascertaining, from the self-service access policy, a trust threshold applicable to the particular content; and

responsive to a determination that the trust measure fails to satisfy the trust threshold, automatically denying access by the user to the particular content.

13. The information handling system of claim 12 , wherein the enumerating comprises enumerating quasi-violations by the user on the plurality of communications platforms.

14. The information handling system of claim 12 , wherein the determining the communication profile of the user comprises:

accessing event-assessment data for the logged user-initiated communication events, wherein each user-initiated communication event relates to at least one communication of a plurality of communications, wherein the event-assessment data comprises information related to a content-based classification of each of the plurality of communications;

determining event-context information for each of the logged user-initiated communication events, the event-context information comprising user-identification information, user-location information, event-timing information, and user-device identification information;

correlating the event-assessment data to a plurality of user contexts, each user context defined by a distinct subset of the event-context information;

associating at least one user-communication pattern with each user context based, at least in part, on the correlated event-assessment data; and

generating the communication profile using a result of the associating.

15. The information handling system of claim 12 , wherein the determining the communication profile comprises accessing a pre-processed communication profile of the user.

16. The information handling system of claim 12 , wherein the quantitatively evaluating comprises:

determining trust values for the historical DLP violations, the communication profile, and the directory-services information; and

wherein the trust measure is based on a combination of the trust values.

17. The information handling system of claim 12 , wherein the determining the trust measure comprises accessing a pre-processed trust measure in memory.

18. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

receiving a request from a user to access particular content;

in response to the request:

determining a trust measure of the user, wherein the trust measure is based, at least in part, on an analysis of logged user-initiated communication events of the user on a plurality of communications platforms, wherein the trust measure is variable over time in relation to the logged user-initiated communication events;

wherein the determining the trust measure comprises:

enumerating historical data loss prevention (DLP) policy violations by the user on the plurality of communications platforms;

determining a communication profile of the user based, at least in part, on the logged user-initiated communication events;

determining directory-services information for the user from a directory service; and

quantitatively evaluating a combination of the DLP policy violations, the communication profile, and the directory-services information via one or more rules, wherein the trust measure comprises a numerical result of the quantitatively evaluating;

accessing a self-service access policy applicable to the particular content;

ascertaining, from the self-service access policy, a trust threshold applicable to the particular content; and

responsive to a determination that the trust measure fails to satisfy the trust threshold, automatically denying access by the user to the particular content.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044719/0565 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 035860 FRAME 0878 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040027/0158 →
RELEASE OF REEL 035860 FRAME 0797 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040028/0551 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 035858 FRAME 0612 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040017/0067 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035860/0878 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035860/0797 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035858/0612 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2015
From: BRISEBOIS, MICHEL ALBERT; JOHNSTONE, CURTIS T.; LE RUDULIER, OLIVIER
To: DELL SOFTWARE INC.
Reel/Frame 035401/0264 →