IP Library Granted Patent US 10,963,167
Granted Patent B2
US 10,963,167 · App. 15/858,882 · Granted Mar 30, 2021

Method, first device, second device and system for managing access to data

Inventors: Didier Hugot (Le Plessis Robinson, FR); Asad Ali (Austin, TX); Gorav Arora (San Jose, CA)
Assignees: THALES DIS FRANCE SA; THALES DIS CPL USA, INC.
G06F3/0622G06F3/067G06F3/0637G06F21/31G06F21/44G06F21/604G06F21/62H04L63/08H04L63/10G06F21/79G06F2221/2113G06F2221/2129G06F2221/2141H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,963,167
App. No.
15/858,882
Filed
Dec 29, 2017
Granted
Mar 30, 2021
Kind
B2
Art Unit
2137
USPC
711/163
Abstract

The invention relates to a method for managing data access. The method includes receiving at least one request for accessing data; capturing data relating to at least one current context signal during each data access request; comparing, as a current authorization step, the data relating to at least one captured current context signal to predetermined reference data relating to at least one corresponding context signal according to at least one corresponding predetermined authorization policy; determining, based upon the current authorization result and at least one predetermined dynamic data access policy, whether the data access is or is not authorized, as a data access decision; and issuing the data access decision. The invention also relates to corresponding first device, second device and system.

Claims (54)

1. A method for managing access to data stored in a computer environment, comprising:

receiving, by a first device, at least one request for accessing data;

capturing, by the first device, data relating to at least one current context signal during each and every data access request, wherein each and every data access request is distinct from an original login data access request;

selecting, by the first device, at least one piece of the captured data relating to the at least one current context signal based on at least one corresponding predetermined authorization policy, wherein the selection of at least one piece of the captured data relating to the at least one current context signal is carried out in response to each and every data access request;

comparing, as a current authorization step, by the first device or a second device connected or coupled to the first device, the selected data relating to at least one captured current context signal to predetermined reference data relating to at least one corresponding context signal according to the at least one corresponding authorization policy, wherein the comparison of respective selected data relating to the at least one captured context signal and respective reference data relating to the at least one corresponding context signal is carried out in response to each and every data access request;

determining, by the first or second device, based upon (a) whether the selected data relating to the at least one captured current context signal matches the reference data relating to the at least one corresponding context signal according to the at least one corresponding authorization policy and (b) at least one predetermined dynamic data access policy, whether the data access is or is not authorized, as a dynamic data access decision; and

issuing, by the first or second device, the dynamic data access decision, the dynamic data access decision being either a data access authorization or a data access deny.

2. Method according to claim 1 , wherein, if the data access is authorized, then the data is accessed according to the at least one dynamic data access policy, the at least one dynamic data access policy including at least one element of a group comprising:

a data reading entitlement,

a data sharing entitlement,

a data creation entitlement,

a data removal entitlement,

a data update entitlement,

a data writing entitlement and a metadata update entitlement, the metadata being associated with the concerned data.

3. Method according to claim 1 , wherein, if the data access is authorized, then the at least one dynamic data access policy includes at least one element of a group comprising, as at least one additional condition to be satisfied:

requesting to further authenticate the requester prior to granting access to data;

carrying out at least one action prior to granting access to data;

carrying out at least one action after granting access to data;

sending at least one predetermined alert message to at least one predetermined addressee.

4. Method according to claim 1 , wherein, if the data access is not authorized, then the data is not accessed according to the at least one dynamic data access policy.

5. Method according to claim 4 , wherein, when the data access is not authorized, the at least one dynamic data access policy includes at least one element of a group comprising:

sending at least one predetermined alert message to at least one predetermined addressee;

sending a data access request response refusal;

sending a data access request response refusal accompanied with at least one reason;

requesting to further authenticate the requester;

carrying out at least one action; and

disconnecting the open requester session.

6. Method according to claim 1 , wherein the method further comprises at least one anomaly detection, the at least one anomaly detection comprising detecting a change of at least one of the at least one captured current context signal with respect to at least one corresponding captured previous context signal, the at least one dynamic data access policy being able to change when at least one of the at least one anomaly detection occurs.

7. Method according to claim 1 , wherein at least one of the at least one dynamic data access policy changes when at least one of the at least one captured current context signal has changed with respect to a corresponding captured previous context signal or a corresponding reference context signal.

8. Method according to claim 1 ,

wherein the original login data access request is valid for one and the same user; and

wherein each and every data access request of a plurality of data access requests is valid for the user.

9. A first device for managing access to data stored in a computer environment, wherein the first device includes at least one processor and is configured to:

receive at least one request for accessing data;

capture data relating to at least one current context signal during each and every data access request, wherein each and every data access request is distinct from an original login data access request;

select at least one piece of the captured data relating to the at least one current context signal based on at least one corresponding predetermined authorization policy, wherein the selection of at least one piece of the captured data relating to the at least one current context signal is carried out in response to each and every data access request;

compare, as a current authorization, the selected data relating to at least one captured current context signal to reference data relating to at least one corresponding context signal according to the at least one corresponding predetermined authorization policy, wherein the comparison of respective selected data relating to the at least one captured context signal and respective reference data relating to the at least one corresponding context signal is carried out in response to each and every data access request;

determine, based upon (a) whether the selected data relating to the at least one captured current context signal matches the reference data relating to the at least one corresponding context signal according to the at least one corresponding authorization policy and (b) at least one predetermined dynamic data access policy, whether the data access is or is not authorized, as a dynamic data access decision; and

issue the dynamic data access decision, the dynamic data access decision being either a data access authorization or a data access deny.

10. A second device for managing access to data stored in a computer environment, wherein the second device includes at least one processor and is configured to:

receive data relating to at least one captured current context signal during each and every data access request, wherein each and every data access request is distinct from an original login data access request;

select at least one piece of the captured data relating to the at least one current context signal based on at least one corresponding predetermined authorization policy, wherein the selection of at least one piece of the captured data relating to the at least one current context signal is carried out in response to each and every data access request;

compare, as a current authorization, the selected data relating to at least one captured current context signal to predetermined reference data relating to at least one corresponding context signal according to the at least one corresponding authorization policy, wherein the comparison of respective selected data relating to the at least one captured context signal and respective reference data relating to the at least one corresponding context signal is carried out in response to each and every data access request;

determine, based upon (a) whether the selected data relating to the at least one captured current context signal matches the reference data relating to the at least one corresponding context signal according to the at least one corresponding authorization policy and (b) at least one predetermined dynamic data access policy, whether the data access is or is not authorized, as a dynamic data access decision; and

issue the dynamic data access decision, the dynamic data access decision being either a data access authorization or a data access deny.

11. A system for managing access to data stored in a computer environment, wherein the system comprising a first device and at least one second device, the second device being connected or coupled to the first device, the first device is configured to:

receive at least one request for accessing data;

capture data relating to at least one current context signal during each and every data access request, wherein each and every data access request is distinct from an original login data access request;

send to the second device the data relating to at least one captured current context signal; and

wherein the second device is configured to:

select at least one piece of the captured data relating to the at least one current context signal based on at least one corresponding predetermined authorization policy, wherein the selection of at least one piece of the captured data relating to the at least one current context signal is carried out in response to each and every data access request;

compare, as a current authorization, the selected data relating to at least one captured current context signal to predetermined reference data relating to at least one corresponding context signal according to the at least one corresponding authorization policy, wherein the comparison of respective selected data relating to the at least one captured context signal and respective reference data relating to the at least one corresponding context signal is carried out in response to each and every data access request;

determine, based upon (a) whether the selected data relating to the at least one captured current context signal matches the reference data relating to the at least one corresponding context signal according to the at least one corresponding authorization policy and (b) at least one predetermined dynamic data access policy, whether the data access is or is not authorized, as a dynamic data access decision; and

issue the dynamic data access decision, the dynamic data access decision being either a data access authorization or a data access deny.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2025
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 072457/0635 →
CHANGE OF NAME Recorded Feb 16, 2021
From: SAFENET, INC.
To: THALES DIS CPL USA, INC.
Reel/Frame 055264/0258 →
CHANGE OF NAME Recorded Feb 16, 2021
From: GEMALTO SA
To: THALES DIS FRANCE SA
Reel/Frame 055304/0591 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2019
From: GEMALTO, INC.
To: SAFENET, INC.
Reel/Frame 048645/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2019
From: HUGOT, DIDIER
To: GEMALTO SA
Reel/Frame 048168/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2019
From: ALI, ASAD
To: GEMALTO INC
Reel/Frame 048168/0196 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2019
From: ARORA, GORAV
To: SAFENET INC.
Reel/Frame 048168/0259 →
Continuity (1)
Related Publication 20190205045A1 · Jul 4, 2019
Cited By (1)
US 12,468,825