IP Library Granted Patent US 11,297,066
Granted Patent B2
US 11,297,066 · App. 16/747,135 · Granted Apr 5, 2022

Constrained roles for access management

Inventors: Yi-hsiu Wei (Austin, TX); David Yu Chang (Austin, TX); Ching-Yun Chao (Austin, TX); Hui-Ming Lin (Austin, TX)
Assignee: International Business Machines Corporation
H04L63/102G06F21/604H04L41/22H04L63/108H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,297,066
App. No.
16/747,135
Granted
Apr 5, 2022
Kind
B2
Abstract

Described are techniques for an access management protocol including a method comprising associating a granted permission set and a constrained permission set to a user profile in an access management system. Respective granted permissions in the granted permission set authorize the user profile to perform the respective granted permissions, and respective constrained permissions in the constrained permission set preclude the user profile from performing the respective constrained permissions. The method further comprises receiving a permission-based request at the access management system and from the user profile and determining that the permission-based request is associated with a permission that is included in both the granted permission set and the constrained permission set. The method further comprises rejecting the permission-based request.

Claims (48)

1. A method for an access management protocol, the method comprising:

associating a granted permission set and a constrained permission set to a user profile in an access management system comprising a processor and a non-transitory memory, wherein respective granted permissions in the granted permission set authorize the user profile to perform the respective granted permissions, wherein respective constrained permissions in the constrained permission set preclude the user profile from performing the respective constrained permissions, wherein the constrained permission set supersedes the granted permission set, wherein the granted permission set is a first node in a policy graph including permissions for sub-nodes of the first node in the policy graph, and wherein the constrained permission set is a first sub-node of the first node;

receiving a permission-based request at the access management system and from the user profile;

determining, by the access management system, that the permission-based request is associated with a permission that is included in both the granted permission set and the constrained permission set; and

rejecting, by the access management system, the permission-based request based on the policy graph and the constrained permission set superseding the granted permission set for the permission.

2. The method of claim 1 , wherein the permission is associated with multiple permissions in the granted permission set and a single permission in the constrained permission set.

3. The method of claim 2 , wherein the single permission in the constrained permission set and one of the multiple permissions in the granted permission set are associated with the user profile at an initial time, and wherein another one of the multiple permissions in the granted permission set is associated with the user profile at a later time.

4. The method of claim 1 , further comprising:

receiving a second permission-based request at the access management system and from the user profile;

determining, by the access management system, that the second permission-based request is allowed by at least one permission from the granted permission set and not denied by any permission from the constrained permission set; and

approving, by the access management system, the second permission-based request.

5. The method of claim 1 , wherein associating the granted permission set and the constrained permission set to the user profile in the access management system further comprises:

associating the granted permission set to the user profile;

determining that the granted permission set is associated with the constrained permission set based on the policy graph; and

associating the constrained permission set to the user profile.

6. The method of claim 5 , wherein the policy graph includes a second constrained permission set and a negated second constrained permission set, and wherein the method further comprises:

receiving a second permission-based request at the access management system and from the user profile;

determining, by the access management system, that the second permission-based request is associated with a permission that is included in the granted permission set, the constrained permission set, and the negated second constrained permission set; and

approving, by the access management system, the second permission-based request.

7. The method of claim 1 , wherein the constrained permission set is related to the granted permission set in a directed graph.

8. The method of claim 1 , wherein the access management protocol is a role-based access control (RBAC) protocol.

9. The method of claim 1 , wherein the access management protocol comprises software that is downloaded to the access management system from a remote data processing system.

10. The method of claim 9 , wherein the method further comprises:

metering a usage of the access management protocol; and

generating an invoice based on metering the usage.

11. An access management system comprising:

a processor; and

a computer-readable storage medium storing access management protocol instructions which, when executed by the processor, are configured to cause the processor to perform a method comprising:

associating a granted permission set and a constrained permission set to a user profile in an access management system, wherein respective granted permissions in the granted permission set authorize the user profile to perform the respective granted permissions, and wherein respective constrained permissions in the constrained permission set preclude the user profile from performing the respective constrained permissions, wherein the constrained permission set supersedes the granted permission set, wherein the granted permission set is a first node in a policy graph including permissions for sub-nodes of the first node in the policy graph, and wherein the constrained permission set is a first sub-node of the first node;

receiving a permission-based request at the access management system and from the user profile;

determining, by the access management system, that the permission-based request is associated with a permission that is included in both the granted permission set and the constrained permission set; and

rejecting, by the access management system, the permission-based request based on the policy graph and the constrained permission set superseding the granted permission set for the permission.

12. The access management system of claim 11 , wherein the permission is associated with multiple permissions in the granted permission set and a single permission in the constrained permission set.

13. The access management system of claim 12 , wherein the single permission in the constrained permission set and one of the multiple permissions in the granted permission set are associated with the user profile at an initial time, and wherein another one of the multiple permissions in the granted permission set is associated with the user profile at a later time.

14. The access management system of claim 11 , wherein the access management protocol is a role-based access control (RBAC) protocol.

15. The access management system of claim 11 , wherein associating the granted permission set and the constrained permission set to the user profile in the access management system further comprises:

associating the granted permission set to the user profile;

determining that the granted permission set is associated with the constrained permission set based on the policy graph; and

associating the constrained permission set to the user profile.

16. The access management system of claim 11 , wherein the constrained permission set is related to the granted permission set in a directed graph.

17. A computer program product comprising a computer readable storage medium having access management protocol instructions embodied therewith, the access management protocol instructions when executed by an access management system to cause the access management system to perform a method comprising:

associating a granted permission set and a constrained permission set to a user profile in the access management system, wherein respective granted permissions in the granted permission set authorize the user profile to perform the respective granted permissions, and wherein respective constrained permissions in the constrained permission set preclude the user profile from performing the respective constrained permissions, wherein the constrained permission set supersedes the granted permission set, wherein the granted permission set is a first node in a policy graph including permissions for sub-nodes of the first node in the policy graph, and wherein the constrained permission set is a first sub-node of the first node;

receiving a permission-based request at the access management system and from the user profile;

determining, by the access management system, that the permission-based request is associated with a permission that is included in both the granted permission set and the constrained permission set; and

rejecting, by the access management system, the permission-based request based on the policy graph and the constrained permission set superseding the granted permission set for the permission.

18. The computer program product of claim 17 , wherein the access management protocol comprises software that is downloaded to the access management system from a remote data processing system, and wherein the method further comprises:

metering a usage of the access management protocol; and

generating an invoice based on metering the usage.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2020
From: WEI, YI-HSIU; CHANG, DAVID YU; CHAO, CHING-YUN; LIN, HUI-MING
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 051555/0433 →
Continuity (1)
Related Publication 20210226956A1 · Jul 22, 2021
Cited By (2)
US 12,238,114 US 12,474,902