IP Library Granted Patent US 9,807,097
Granted Patent B1
US 9,807,097 · App. 15/247,041 · Granted Oct 31, 2017

System for managing access to protected resources

Inventor: Michael W. Roegner (McKinney, TX)
Assignee: Jericho Systems Corporation
H04L63/10G06F17/30312H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,807,097
App. No.
15/247,041
Granted
Oct 31, 2017
Kind
B1
Abstract

A rules evaluation engine that controls user's security access to enterprise resources that have policies created for them. This engine allows real time authorization process to be performed with dynamic enrichment of the rules if necessary. Logging, alarm and administrative processes for granting or denying access to the user are also realized. The access encompasses computer and physical access to information and enterprise spaces.

Claims (21)

1. A computer program product comprising non-transitory computer readable storage medium, said computer program product for controlling authorization of access to a resource, said computer program product comprising:

computer readable program code embodied at the non-transitory computer readable storage medium for retrieving an indication of a request for access to the resource from a policy enforcement point;

computer readable program code embodied at the non-transitory computer readable storage medium for obtaining from a policy repository a dynamically-loadable security policy associated with the resource, the dynamically-loadable security policy comprising at least one rule;

computer readable program code embodied at the non-transitory computer readable storage medium for examining the at least one rule of the dynamically-loadable security policy to determine at least one attribute required by the rule to evaluate the policy associated with the resource and comprising the at least one rule;

computer readable program code embodied at the non-transitory computer readable storage medium for invoking a connector to a data source that contains the at least one attribute required by the rule needed to evaluate the policy;

computer readable program code embodied at the non-transitory computer readable storage medium for retrieving the at least one attribute required by the rule to evaluate the policy;

computer readable program code embodied at the non-transitory computer readable storage medium for evaluating the policy using a value of the at least one attribute; and

return an authorization decision to the policy enforcement point.

2. The computer program product apparatus of claim 1 wherein the request for access to the resource comprises a client-generated request.

3. The computer program product apparatus of claim 2 wherein the client generated request is generated by a client module and wherein the client module is prohibited from accessing the data source that contains the additional information.

4. A method for controlling authorization of access to a resource, said method comprising:

retrieving an indication of a request for access to the resource from a policy enforcement point;

obtaining a dynamically-loadable security policy associated with the resource, the dynamically-loadable security policy comprising at least one rule from a policy repository;

examining the at least one rule of the dynamically-loadable security policy to determine at least one attribute required by the rule to evaluate the dynamically-loadable policy associated with the resource and comprising the at least one rule;

invoking a connector to a data source that contains the at least one attribute required by the rule to evaluate the policy;

retrieving the at least one attribute required by the rule to evaluate the policy;

evaluating the policy using a value of the at least one attribute; and

returning an authorization decision to the policy enforcement point.

5. The method of claim 4 wherein the request for access to the resource comprises a client-generated request.

6. The method of claim 5 wherein the client generated request is generated by a client module and wherein the client module is prohibited from accessing the data source that contains the additional information.

7. The method of claim 4 wherein the at least one attribute retrieved during said retrieving is of a value current when retrieved, subsequent to retrieval of the indication of the request for access to the resource.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: BIN 2020, SERIES 550 ALLIED SECURITY TRUST I
To: CROWDSTRIKE, INC.
Reel/Frame 058310/0455 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2020
From: JERICHO SYSTEMS CORPORATION
To: BIN 2020, SERIES 550 OF ALLIED SECURITY TRUST I
Reel/Frame 052831/0119 →
Continuity (4)
Continuation 14014359 · Aug 30, 2013
Continuation 12658421 · Feb 11, 2010
Continuation 10755173 · Jan 9, 2004
Provisional Application 60438972 · Jan 9, 2003