IP Library › Granted Patent US 9,672,348
Granted Patent B2
US 9,672,348 · App. 14/722,194 · Granted Jun 6, 2017

Risk-based credential management

Inventors: Leigh T. Doddy (Sunbury, AU); Christopher J. Hockings (Burleigh Waters, AU); Dinesh T. Jain (Pune, IN); Philip A. J. Nye (Southport, AU)
Assignee: International Business Machines Corporation
G06F21/45H04L63/10H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,672,348
App. No.
14/722,194
Granted
Jun 6, 2017
Kind
B2
Abstract

Risk-based credential management is provided. A request to checkout credentials is received. The credentials are associated with at least one managed resource. A risk value of the request is determined. The determination of the risk value is based, at least in part, on risk information of the requesting device. A determination is made whether to deny the request based, at least in part, on the risk value and a first predetermined threshold of a checkout policy.

Claims (14)

1. A method for credential management, the method comprising:

receiving, by one or more hardware processors, from a requesting device, a request to checkout credentials; wherein the credentials are associated with at least one managed resource;

determining, by one or more hardware processors, a risk value of the request, wherein the determination of the risk value is based, at least in part, on risk information of the requesting device; and

determining, by one or more hardware processors, whether to deny the request based, at least in part, on the risk value and a first predetermined threshold of a checkout policy by classifying certain types of malware of the requesting device.

2. The method of claim 1 , wherein determining whether to deny the request comprises:

determining, by one or more processors, that the risk value violates the first predetermined threshold and, in response, denying the request.

3. The method of claim 2 , wherein determining, by one or more processors, whether to deny the request is further based on a security status of each of the at least one managed resources.

4. The method of claim 3 , further comprising:

responsive to determining that the security status indicates that a first managed resource of the at least one managed resource is compromised, denying, by one or more processors, the request.

5. The method of claim 1 , wherein determining whether to deny the request comprises:

determining, by one or more processors, that the risk value does not violate the first predetermined threshold and, in response, granting the request.

6. The method of claim 1 , wherein the credentials authorize access to the at least one managed resource associated with the credentials.

7. The method of claim 1 , wherein the risk value is based, at least in part, on one or more types of risk information that are specified by the checkout policy.

8. The method of claim 7 , wherein the one or more types of risk information identify at least one of: data of the requesting device that matches a malware definition, a version of each of a plurality of programs installed on the requesting device, and a security patch installed on the requesting device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2015
From: DODDY, LEIGH T.; HOCKINGS, CHRISTOPHER J.; JAIN, DINESH T.; NYE, PHILIP A.J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 035717/0749 →
Continuity (2)
Continuation 14609578 · Jan 30, 2015
Related Publication 20160226914A1 · Aug 4, 2016