IP Library Granted Patent US 9,473,500
Granted Patent B1
US 9,473,500 · App. 15/050,994 · Granted Oct 18, 2016

Compliance validator for restricted network access control

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,473,500
App. No.
15/050,994
Granted
Oct 18, 2016
Kind
B1
Abstract

A method, system, and computer program product for detecting and enforcing compliance with access requirements for a computer system in a restricted computer network. A compliance validation configuration file is created for the computer system. A maintenance service utility is configured to launch a compliance validation executable file at a specified time during operation of the computer system. A digital hash is generated for the compliance validation executable file and for the compliance validation configuration file. A determination is made if the computer system or a computer system user is a member of a configured restricted group. If the computer system or the computer system user is a member of a configured restricted group, a determination is made if a directory site code for a subnet of the restricted computer network to which the computer system is connected corresponds to a configured and allowed site. If the directory site code does not correspond to a configured and allowed site, compliance with access requirements are enforced. Enforcement actions can include a forced logoff of the computer system user, and/or a forced shutdown of the computer system.

Claims (42)

1. A method, comprising:

determining if there are any updates at a location for either a compliance validation executable file or a compliance configuration file, based on a digital hash of the compliance validation executable file and the compliance validation configuration file;

automatically updating either the compliance validation executable file or the compliance validation configuration file, if any updates are available; and

removing the compliance validation executable file and the compliance validation configuration file from a computer system if:

the update file has been removed; and

either the computer system is not a member of a configured restricted group or a computer system user is not a member of the configured restricted group.

2. The method of claim 1 , comprising configuring a maintenance service utility to launch the compliance validation executable file at a specified time during operation of the computer system.

3. The method of claim 2 , wherein the step of configuring the maintenance service utility to launch a compliance validation executable file comprises selecting an activation time for the maintenance service utility.

4. The method of claim 1 , comprising generating the digital hash for the compliance validation executable file and the compliance validation configuration file.

5. The method of claim 1 , comprising determining if the computer system or the computer system user is a member of the configured restricted group.

6. The method of claim 5 , comprising if the computer system or the computer system user is a member of the configured restricted group, determining if a directory site code for a subnet of the restricted computer network to which the computer system is connected corresponds to a configured and allowed site.

7. The method of claim 6 , comprising enforcing compliance with access requirements if the directory site code does not correspond to the configured and allowed site.

8. The method of claim 7 , wherein the enforcing comprises at least one of:

automatically logging the user off the computer system;

automatically shutting down the computer system; and

displaying a message to the user that the computer system is not in compliance with access requirements for the restricted computer network.

9. The method of claim 1 , comprising determining if a compliance validation executable update file has been removed from the location.

10. A system, comprising:

a hardware processor that:

determines if there are any updates at a location for either a compliance validation executable file or a compliance configuration file, based on a digital hash of the compliance validation executable file and the compliance validation configuration file;

automatically updates either the compliance validation executable file or the compliance validation configuration file, if any updates are available; and

removes the compliance validation executable file and the compliance validation configuration file from a computer system if:

the update file has been removed; and

either the computer system or a computer system user is not a member of a configured restricted group.

11. The system of claim 10 , wherein the processor configures a maintenance service utility to launch the compliance validation executable file at a specified time during operation of the computer system.

12. The system of claim 11 , wherein the processor selects an activation time for the maintenance service utility when the maintenance service utility is configured.

13. The system of claim 10 , wherein the processor generates the digital hash for the compliance validation executable file and the compliance validation configuration file.

14. The system of claim 10 , wherein the processor determines if the computer system or the computer system user is a member of the configured restricted group.

15. The system of claim 14 , wherein the processor determines if a directory site code for a subnet of the restricted computer network to which the computer system is connected corresponds to a configured and allowed site if the computer system or the computer system user is a member of the configured restricted group.

16. The system of claim 15 , wherein the processor enforces compliance with access requirements if the directory site code does not correspond to the configured and allowed site.

17. The system of claim 16 , wherein the enforces compliance comprises at least one of:

automatically logs the user off the computer system;

automatically shuts down the computer system; and

displays a message to the user that the computer system is not in compliance with access requirements for the restricted computer network.

18. The system of claim 10 , wherein the processor determines if a compliance validation executable update file has been removed from the location.

19. A non-transitory computer program product comprising a computer readable medium having computer readable code embedded therein, the computer readable medium comprising:

program instructions that determine if there are any updates at a location for either a compliance validation executable file or a compliance configuration file, based on a digital hash of the compliance validation executable file and the compliance validation configuration file;

program instructions that automatically update either the compliance validation executable file or the compliance validation configuration file, if any updates are available;

program instructions that remove the compliance validation executable file and the compliance validation configuration file from a computer system if:

the update file has been removed; and

either the computer system is not a member of a configured restricted group or a computer system user is not a member of the configured restricted group.

20. The computer readable medium of claim 19 comprising program instructions that launch the compliance validation executable file at a specified time during operation of the computer system.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF THE PATENT ASSIGNMENT AGREEMENT DATED NOVEMBER 30, 2021 PREVIOUSLY RECORDED AT REEL: 058426 FRAME: 0791. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2022
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058736/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2021
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058426/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2021
From: FEESER, COLIN LEE; ONDRUS, ANTHONY WILLIAM; CANUP, MARK JACKSON
To: SOUTHERN COMPANY SERVICES, INC.
Reel/Frame 057495/0227 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2021
From: SOUTHERN COMPANY SERVICES, INC.
To: OPEN INVENTION NETWORK LLC
Reel/Frame 057522/0580 →