IP Library Granted Patent US 10,454,939
Granted Patent B1
US 10,454,939 · App. 15/198,692 · Granted Oct 22, 2019

Method, apparatus and computer program product for identifying excessive access rights granted to users

Inventors: Shay Amram (Holon, IL); Alex Zaslavsky (Petah Tikva, IL); Carmit Sahar (Tel Aviv, IL)
Assignee: EMC IP Holding Company LLC
H04L63/102H04L63/104H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,454,939
App. No.
15/198,692
Filed
Jun 30, 2016
Granted
Oct 22, 2019
Kind
B1
Art Unit
2437
USPC
726/4
Abstract

There is disclosed in one embodiment a method comprising the step of determining, access rights granted to a first user that enables access to a computerized resource. The method also comprises the step of comparing the access rights granted to the first user against access rights granted to a second user associated with the first user. The method further comprises the step of providing a warning when the comparison indicates that the first user has excessive access rights over the second user.

Claims (17)

1. A method, comprising:

evaluating, by processing circuitry, access rights granted to one or more computerized resources, wherein the said evaluation comprises (i) determining access rights granted to one or more users in a group, (ii) determining access rights granted to the group, (iii) determining a hierarchal level of the one or more users in the group in which each user is organized at one of a plurality of hierarchal levels such that the respective hierarchal levels describe a corresponding level of access rights and a user at a higher hierarchal level is entitled to extra access rights over a sub-ordinate user at a lower hierarchal level, and (iv) determining a role of the one or more users in the group such that at least one role enables a sub-ordinate user to have similar access rights to a user at a higher hierarchal level;

determining, by processing circuitry, appropriate access rights for each of the one or more users in the group based on the access rights granted to the group and the hierarchal level of the respective users and the role of the one or more users in the group;

comparing, by processing circuitry, the access rights granted to each of the one or more users in the group against the appropriate access rights for that user in order to determine if excessive access rights have been granted to that user; and

based on the comparison, controlling, by processing circuitry, access to the one or more computerized resources by modifying the access rights of one or more users having excessive access rights such that the one or more users are prevented from exercising the excessive access rights in connection with the one or more computerized resources.

2. An apparatus, comprising:

memory; and

processing circuitry coupled to the memory, the memory storing program code which, when executed by the processing circuitry, cause the processing circuitry to:

evaluate access rights granted to one or more computerized resources, wherein the said evaluation comprises (i) determining access rights granted to one or more users in a group, (ii) determining access rights granted to the group, (iii) determining a hierarchal level of the one or more users in the group in which each user is organized at one of a plurality of hierarchal levels such that the respective hierarchal levels describe a corresponding level of access rights and a user at a higher hierarchal level is entitled to extra access rights over a sub-ordinate user at a lower hierarchal level, and (iv) determining a role of the one or more users in the group such that at least one role enables a sub-ordinate user to have similar access rights to a user at a higher hierarchal level;

determine appropriate access rights for each of the one or more users in the group based on the access rights granted to the group and the hierarchal level of the respective users and the role of the one or more users in the group;

compare the access rights granted to each of the one or more users in the group against the appropriate access rights for that user in order to determine if excessive access rights have been granted to that user; and

based on the comparison, control access to the one or more computerized resources by modifying the access rights of one or more users having excessive access rights such that the one or more users are prevented from exercising the excessive access rights in connection with the one or more computerized resources.

3. A computer program product having a non-transitory computer readable medium which stores a set of instructions, the set of instructions, when carried out by processing circuitry, causing the processing circuitry to perform a method, the method comprising:

evaluating access rights granted to one or more computerized resources, wherein the said evaluation comprises (i) determining access rights granted to one or more users in a group, (ii) determining access rights granted to the group, (iii) determining a hierarchal level of the one or more users in the group in which each user is organized at one of a plurality of hierarchal levels such that the respective hierarchal levels describe a corresponding level of access rights and a user at a higher hierarchal level is entitled to extra access rights over a sub-ordinate user at a lower hierarchal level, and (iv) determining a role of the one or more users in the group such that at least one role enables a sub-ordinate user to have similar access rights to a user at a higher hierarchal level;

determining appropriate access rights for each of the one or more users in the group based on the access rights granted to the group and the hierarchal level of the respective users and the role of the one or more users in the group;

comparing the access rights granted to each of the one or more users in the group against the appropriate access rights for that user in order to determine if excessive access rights have been granted to that user; and

based on the comparison, controlling access to the one or more computerized resources by modifying the access rights of one or more users having excessive access rights such that the one or more users are prevented from exercising the excessive access rights in connection with the one or more computerized resources.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (051302/0528) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.); SECUREWORKS CORP.
Reel/Frame 060438/0593 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 051449 FRAME 0728 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
Reel/Frame 058002/0010 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Dec 31, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 051449/0728 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Dec 16, 2019
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.; SECUREWORKS CORP.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 051302/0528 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2016
From: AMRAM, SHAY; ZASLAVSKY, ALEX; SAHAR, CARMIT
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040197/0643 →
Cited By (1)
US 12,255,885