IP Library Granted Patent US 11,693,982
Granted Patent B2
US 11,693,982 · App. 17/068,674 · Granted Jul 4, 2023

Systems for secure enterprise-wide fine-grained role-based access control of organizational assets

Inventors: Yan Bregman (East Brunswick, NJ); Kizito Ofornagoro (Queens, NY)
Assignee: ASG Technologies Group, Inc.
G06F21/6218G06F3/0482G06F3/0483G06F16/211G06F16/256G06F21/31G06F21/604G06F40/106G06N5/01H04L63/101H04L63/102H04L63/105H04L63/205G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,693,982
App. No.
17/068,674
Granted
Jul 4, 2023
Kind
B2
Abstract

The disclosure is directed to systems and methods for enterprise-wide fine-grained role-based access control to a plurality of organizational assets. In various embodiments exemplary methods include receiving, via an authorization service client API, identification of an asset for fine-grained role-based access control; a definition of an asset type of the asset; a definition of an asset value; receiving, a definition of an organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value. Furthermore, receiving permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value. Furthermore, the exemplary method may comprise providing an authorization service user interface (UI) for enabling fine-grained role-based access control to the asset based on the fine-grained role-based access control database schema.

Claims (66)

1. A method for enterprise-wide fine-grained role-based access control to a plurality of organizational assets, the method comprising:

receiving, via an authorization service client Application Programming Interface (API), identification of an asset for fine-grained role-based access control from an organization;

receiving, via the authorization service client API, a definition of an asset type of the asset using the identification of the asset;

receiving, via the authorization service client API, a definition of an asset value of the asset based on the asset type;

receiving, via the authorization service client API, a definition of an organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value;

receiving, via the authorization service client API, permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value, the permissions comprising at least one access rule having a set of variables based on the asset, the asset type, and the asset value;

generating a fine-grained role-based access control database schema using the asset, the definition of an asset type, the definition of an asset value, the definition of an organizational role, and the permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value;

providing an authorization service user interface (UI) for enabling fine-grained role-based access control to the asset based on the fine-grained role-based access control database schema;

receiving, via the authorization service client API, a request for permission to access at least one of the asset, the asset type, and the asset value by an authenticated user;

receiving, via the UI, selection input of an asset for fine-grained role-based access control using the identification of an asset;

receiving, via the UI, selection input of an asset type of the asset using the definition of the asset type of the asset;

receiving, via the UI, selection input of an asset value of the asset using the definition of the asset value of the asset;

receiving, via the UI, selection input of an organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value; and

receiving, via the UI, selection input of the permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value, the receiving, via the UI, the selection input of the organizational role is a root user; and the receiving, via the UI, the selection input of the permissions for fine-grained role-based access by the root user includes permissions to access all asset types and asset values.

2. The method as recited in claim 1 , further comprising:

fine-grained role-based access evaluating the request for permission to access the asset from the authenticated user using the fine-grained role-based access control database schema;

generating a fine-grained role-based access decision regarding the request for permission to access the asset, the asset type, and the asset value by the authenticated user based on the fine-grained role-based access evaluating; and

replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user, via the authorization service client API based on the fine-grained role-based access decision regarding the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

3. The method as recited in claim 2 , wherein the replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user comprises granting permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

4. The method as recited in claim 2 , wherein the replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user comprises denial of permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

5. The method as recited in claim 1 ,

wherein the receiving, via the UI, the selection input of the organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value comprises multiple organizational roles.

6. A system for enterprise-wide fine-grained role-based access control to a plurality of organizational assets, the system comprising:

at least one processor, and

a memory storing processor-executable instructions, wherein the at least one processor is configured to implement the following operations upon executing the processor-executable instructions:

receiving, via an authorization service client Application Programming Interface (API), identification of an asset for fine-grained role-based access control from an organization;

receiving, via the authorization service client API, a definition of an asset type of the asset using the identification of the asset;

receiving, via the authorization service client API, a definition of an asset value of the asset based on the asset type;

receiving, via the authorization service client API, a definition of an organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value;

receiving, via the authorization service client API, permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value, the permissions comprising at least one access rule having a set of variables based on the asset, the asset type, and the asset value;

generating a fine-grained role-based access control database schema using the asset, the definition of an asset type, the definition of an asset value, the definition of an organizational role, and the permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value;

providing an authorization service user interface (UI) for enabling fine-grained role-based access control to the asset based on the fine-grained role-based access control database schema;

receiving, via the authorization service client API, a request for permission to access at least one of the asset, the asset type, and the asset value by an authenticated user;

receiving, via the UI, selection input of an asset for fine-grained role-based access control using the identification of an asset;

receiving, via the UI, selection input of an asset type of the asset using the definition of the asset type of the asset;

receiving, via the UI, selection input of an asset value of the asset using the definition of the asset value of the asset;

receiving, via the UI, selection input of an organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value; and

receiving, via the UI, selection input of the permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value, the receiving, via the UI, the selection input of the organizational role is a root user; the receiving, via the UI, selection input of the permissions for fine-grained role-based access by the root user includes permissions to access all asset types and asset values.

7. The system as recited in claim 6 , wherein the at least one processor is further configured to implement the following operations upon executing the processor-executable instructions:

fine-grained role-based access evaluating the request for permission to access the asset from the authenticated user using the fine-grained role-based access control database schema;

generating a fine-grained role-based access decision regarding the request for permission to access the asset, the asset type, and the asset value by the authenticated user based on the fine-grained role-based access evaluating; and

replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user, via the authorization service client API based on the fine-grained role-based access decision regarding the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

8. The system as recited in claim 7 , wherein the replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user comprises granting permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

9. The system as recited in claim 7 , wherein the replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user comprises denial of permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

10. The system as recited in claim 6 ,

wherein the receiving, via the UI, selection input of an organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value comprises multiple organizational roles.

11. A non-transitory computer readable medium having embodied thereon instructions being executable by at least one processor to perform operations for enterprise-wide fine-grained role-based access control to a plurality of organizational assets, the operations comprising:

receiving, via an authorization service client Application Programming Interface (API), identification of an asset for fine-grained role-based access control from an organization;

receiving, via the authorization service client API, a definition of an asset type of the asset using the identification of the asset;

receiving, via the authorization service client API, a definition of an asset value of the asset based on the asset type;

receiving, via the authorization service client API, a definition of an organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value;

receiving, via the authorization service client API, permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value, the permissions comprising at least one access rule having a set of variables based on the asset, the asset type, and the asset value;

generating a fine-grained role-based access control database schema using the asset, the definition of an asset type, the definition of an asset value, the definition of an organizational role, and the permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value;

providing an authorization service user interface (UI) for enabling fine-grained role-based access control to the asset based on the fine-grained role-based access control database schema;

receiving, via the authorization service client API, a request for permission to access at least one of the asset, the asset type, and the asset value by an authenticated user;

receiving, via the UI, selection input of an asset for fine-grained role-based access control using the identification of an asset;

receiving, via the UI, selection input of an asset type of the asset using the definition of the asset type of the asset;

receiving, via the UI, selection input of an asset value of the asset using the definition of the asset value of the asset;

receiving, via the UI, selection input of an organizational role with fine-grained role-based access control to at least one of the asset, the asset type, and the asset value; and

receiving, via the UI, selection input of the permissions for fine-grained role-based access by the organizational role to at least one of the asset, the asset type, and the asset value, the receiving, via the UI, the selection input of the organizational role is a root user; and the receiving, via the UI, the selection input of the permissions for fine-grained role-based access by the root user includes permissions to access all asset types and asset values.

12. The non-transitory computer readable medium of claim 11 , wherein the operations further comprise:

fine-grained role-based access evaluating the request for permission to access the asset from the authenticated user using the fine-grained role-based access control database schema;

generating a fine-grained role-based access decision regarding the request for permission to access the asset, the asset type, and the asset value by the authenticated user based on the fine-grained role-based access evaluating; and

replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user, via the authorization service client API based on the fine-grained role-based access decision regarding the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

13. The non-transitory computer readable medium of claim 12 , wherein the replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user comprises granting permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

14. The non-transitory computer readable medium of claim 12 , wherein the replying to the request for permission to access at least one of the asset, the asset type, and the asset value by the authenticated user comprises denial of permission to access at least one of the asset, the asset type, and the asset value by the authenticated user.

Assignments (8)
CHANGE OF NAME Recorded May 17, 2024
From: ASG TECHNOLOGIES GROUP, INC.
To: ROCKET SOFTWARE TECHNOLOGIES, INC.
Reel/Frame 067456/0863 →
CHANGE OF ADDRESS Recorded Dec 27, 2022
From: ASG TECHNOLOGIES GROUP, INC. DBA ASG TECHNOLOGIES
To: ASG TECHNOLOGIES GROUP, INC. DBA ASG TECHNOLOGIES
Reel/Frame 062714/0198 →
SECURITY AGREEMENT (SUPPLEMENT - FIRST LIEN) Recorded Sep 13, 2022
From: ASG TECHNOLOGIES GROUP, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 061419/0384 →
RELEASE OF SECURITY INTEREST Recorded May 21, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: ASG TECHNOLOGIES GROUP, INC.
Reel/Frame 056312/0291 →
SECURITY INTEREST Recorded Nov 16, 2020
From: ASG TECHNOLOGIES GROUP, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 054379/0327 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2020
From: BREGMAN, YAN
To: ASG TECHNOLOGIES GROUP, INC. DBA ASG TECHNOLOGIES
Reel/Frame 054210/0838 →
CHANGE OF NAME Recorded Oct 29, 2020
From: ALLEN SYSTEMS GROUP, INC.
To: ASG TECHNOLOGIES GROUP, INC. DBA ASG TECHNOLOGIES
Reel/Frame 054252/0948 →
EMPLOYEE CONFIDENTIALITY AGREEMENT Recorded Oct 29, 2020
From: OFORNAGORO, KIZITO
To: ALLEN SYSTEMS GROUP, INC.
Reel/Frame 054252/0622 →
Continuity (2)
Provisional Application 62923381 · Oct 18, 2019
Related Publication 20210117517A1 · Apr 22, 2021
Cited By (1)
US 12,561,482