IP Library Patent Application 15087484
Patent Application
App. No. 15/087,484

ACCESS CONTROL POLICY SELECTION BASED UPON USER CLASSIFICATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/087,484
Abstract

A method includes receiving, at a server, a request from a user to access an enterprise network system using a client device. The user is authenticated by receiving first unique enterprise credentials from the user. The user's access to a plurality of services external to the enterprise network system is facilitated, in response to receiving the unique enterprise credentials from the user, wherein each of the plurality of services requires respective unique services credentials associated with the user, for access. A selection of one of the plurality of services is received from the user. It is determined whether the user is classified as a privileged user or a non-privileged user. The method includes selecting between first and second policies depending upon the determination whether the user is classified as a privileged user or a non-privileged user. The first policy may include recording a session between the user and the selected one of the plurality of services, at the server. The second policy may comprise monitoring the session between the user and the selected one of the plurality of services, at the client device, in order to identify an anomaly.

Claims (79)

1 . A method for access control, comprising:

receiving, at a server, a request from a user to access an enterprise network system using a client device;

authenticating the user by receiving first unique enterprise credentials from the user;

facilitating the user's access to a plurality of services external to the enterprise network system, in response to receiving the unique enterprise credentials from the user, wherein each of the plurality of services requires respective unique services credentials associated with the user, for access;

receiving, from the user, a selection of one of the plurality of services;

determining whether the user is classified as a privileged user or a non-privileged user;

selecting between first and second policies depending upon the determination whether the user is classified as a privileged user or a non-privileged user;

wherein the first policy comprises recording a session between the user and the selected one of the plurality of services, at the server; and

wherein the second policy comprises monitoring the session between the user and the selected one of the plurality of services, at the client device, in order to identify an anomaly.

2 . The method of claim 1 , further comprising:

determining that the user is a privileged user;

applying the first policy in response to determining that the user is a privileged user; and

instantiating a recording session at the server to record the session between the user and the selected one of the plurality of services, at the server.

3 . The method of claim 1 , further comprising:

determining that the user is a non-privileged user;

applying the second policy in response to determining that the user is a non-privileged user;

monitoring the session at the client in order to detect the anomaly;

detecting the anomaly; and

taking an action in response to detecting the anomaly.

4 . The method of claim 3 , further comprising:

transmitting a client application from the server to the client device, in response to receiving the request from the user to access the enterprise network system using the client device; and

wherein the client application is operable to, upon receiving an instruction from the server, monitor the session between the user and the selected one of the plurality of services, at the client device, in order to identify the anomaly.

5 . The method of claim 3 , wherein the action comprises terminating the session between the user and the service.

6 . The method of claim 3 , wherein the anomaly comprises a destination change of the service and the action comprises terminating the session between the user and the service.

7 . The method of claim 3 , wherein the action comprises instantiating a recording session at the server to record the session between the user and the selected one of the plurality of services, at the server.

8 . The method of claim 1 , further comprising:

determining the respective unique credentials associated with the user, for the selected one of the plurality of services;

establishing a connection between the server and the selected one of the plurality of services, using the respective unique credentials associated with the user; and

providing the user with access to the selected one of the plurality of services, through the connection between the server and the selected one of the plurality of services.

9 . The method of claim 8 , further comprising dynamically modifying the respective unique credentials associated with the user, in response to determining that the session is complete.

10 . A computer configured to access a storage device, the computer comprising:

a processor; and

a non-transitory, computer readable storage medium storing computer-readable instructions that when executed by the processor cause the computer to perform:

receiving, at a server, a request from a user to access an enterprise network system using a client device;

authenticating the user by receiving first unique enterprise credentials from the user;

facilitating the user's access to a plurality of services external to the enterprise network system, in response to receiving the unique enterprise credentials from the user, wherein each of the plurality of services requires respective unique services credentials associated with the user, for access;

receiving, from the user, a selection of one of the plurality of services;

determining whether the user is classified as a privileged user or a non-privileged user;

selecting between first and second policies depending upon the determination whether the user is classified as a privileged user or a non-privileged user;

wherein the first policy comprises recording a session between the user and the selected one of the plurality of services, at the server; and

wherein the second policy comprises monitoring the session between the user and the selected one of the plurality of services, at the client device, in order to identify an anomaly.

11 . The computer of claim 10 , wherein the computer-readable instructions further cause the computer to perform:

determining that the user is a privileged user;

applying the first policy in response to determining that the user is a privileged user; and

instantiating a recording session at the server to record the session between the user and the selected one of the plurality of services, at the server.

12 . The computer of claim 10 , wherein the computer-readable instructions further cause the computer to perform:

determining that the user is a non-privileged user;

applying the second policy in response to determining that the user is a non-privileged user;

monitoring the session at the client in order to detect the anomaly;

detecting the anomaly; and

taking an action in response to detecting the anomaly.

13 . The computer of claim 12 , wherein the computer-readable instructions further cause the computer to perform:

transmitting a client application from the server to the client device, in response to receiving the request from the user to access the enterprise network system using the client device; and

wherein the client application is operable to, upon receiving an instruction from the server, monitor the session between the user and the selected one of the plurality of services, at the client device, in order to identify the anomaly.

14 . The computer of claim 12 , wherein the action comprises terminating the session between the user and the service.

15 . The computer of claim 12 , wherein the anomaly comprises a destination change of the service and the action comprises terminating the session between the user and the service.

16 . The computer of claim 12 , wherein the action comprises instantiating a recording session at the server to record the session between the user and the selected one of the plurality of services, at the server.

17 . The computer of claim 10 , wherein the computer-readable instructions further cause the computer to perform:

determining the respective unique credentials associated with the user, for the selected one of the plurality of services;

establishing a connection between the server and the selected one of the plurality of services, using the respective unique credentials associated with the user; and

providing the user with access to the selected one of the plurality of services, through the connection between the server and the selected one of the plurality of services.

18 . The computer of claim 17 , wherein the computer-readable instructions further cause the computer to perform:

dynamically modifying the respective unique credentials associated with the user, in response to determining that the session is complete.

19 . A computer program product comprising:

a computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code comprising:

computer-readable program code configured to receive, at a server, a request from a user to access an enterprise network system using a client device;

computer-readable program code configured to authenticate the user by receiving first unique enterprise credentials from the user;

computer-readable program code configured to facilitate the user's access to a plurality of services external to the enterprise network system, in response to receiving the unique enterprise credentials from the user, wherein each of the plurality of services requires respective unique services credentials associated with the user, for access;

computer-readable program code configured to receive, from the user, a selection of one of the plurality of services;

computer-readable program code configured to determine whether the user is classified as a privileged user or a non-privileged user;

computer-readable program code configured to select between first and second policies depending upon the determination whether the user is classified as a privileged user or a non-privileged user;

wherein the first policy comprises recording a session between the user and the selected one of the plurality of services, at the server; and

wherein the second policy comprises monitoring the session between the user and the selected one of the plurality of services, at the client device, in order to identify an anomaly.

20 . The computer program product of claim 19 , further comprising:

computer-readable program code configured to determine that the user is a non-privileged user;

computer-readable program code configured to apply the second policy in response to determining that the user is a non-privileged user;

computer-readable program code configured to monitor the session at the client in order to detect the anomaly;

computer-readable program code configured to detect the anomaly; and

computer-readable program code configured to take an action in response to detecting the anomaly.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2016
From: MAPLE, RYAN W.; SUIT, JOHN M.; ROSEN, MORDECAI B.
To: CA, INC.
Reel/Frame 038164/0521 →