IP Library Granted Patent US 11,849,330
Granted Patent B2
US 11,849,330 · App. 17/498,436 · Granted Dec 19, 2023

Geolocation-based policy rules

Inventors: Sudhi Balan (Fairfield, CT); Randy Baiad (Brookfield, CT); Robert Russell (New Canaan, CT)
Assignee: ASG Technologies Group, Inc.
H04W12/63H04W4/029H04W12/06H04W12/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,849,330
App. No.
17/498,436
Granted
Dec 19, 2023
Kind
B2
Abstract

A system for providing geolocation-based policy rules is provided. The system includes a policy engine and a memory communicatively coupled to the policy engine. The policy engine is configured to receive geolocation data for a plurality of objects. The policy engine is configured to create, based on the geolocation data, location policy attributes for the plurality of objects. The policy engine is configured to incorporate the location policy attributes into policy rules. The policy rules include rules for accessing the plurality of objects. The policy engine is further configured to execute the policy rules with regard to the plurality of objects.

Claims (62)

1. A system for providing geolocation-based policy rules, the system comprising:

a policy engine;

a memory communicatively coupled to the policy engine having instructions stored thereon; and

one or more processors to execute the instructions and cause the policy engine to:

receive geolocation data, at least one regional attribute, and content metadata for a plurality of objects;

based on the geolocation data, the at least one regional attribute, and a portion of the content metadata, create location policy attributes for the plurality of objects, the location policy attributes being geographically bounded by the at least one regional attribute;

incorporate the location policy attributes into policy rules, the policy rules including rules for accessing the plurality of objects; and

execute the policy rules with regard to the plurality of objects, the policy rules comprising allowing a user to view redacted content based on access privileges and the geolocation data of the user; and

a memory communicatively coupled to the policy engine and configured to store the policy rules.

2. The system of claim 1 , wherein the execution of the policy rules includes:

receiving, from a user, a request to access one of the plurality of objects;

determining a location policy attribute associated with the user;

determining, based on the policy rules and the location policy attribute, whether the access to the one of the plurality of objects is allowed for the user; and

based on the determination, selectively providing the user with the access to the one of the plurality of objects.

3. The system of claim 2 , further comprising:

determining further attributes associated with the plurality of objects, the further attributes including one or more of the following: security of access, content metadata, an identity of a user, an access privilege of the user, a role of the user, an applicable law, a geographic region, and a time zone, wherein the selectively providing the user with the access is further based on the further attributes.

4. The system of claim 1 , wherein the execution of the policy rules includes:

receiving an Application Programming Interface (API) call to access one of the plurality of objects;

determining a location policy attribute associated with at least one of the following: a user device initiating the API call, a user associated with the user device, and an application running on the user device and initiating the API call;

determining, based on the policy rules and the location policy attribute, whether the access to the one of the plurality of objects is allowed; and

based on the determining, selectively providing the user with the access to the one of the plurality of objects.

5. The system of claim 1 , wherein the plurality of objects includes one or more of the following: a data object, content, a file, a person, a user, a hardware, a software, a domain, a domain object, a network resource, and a network device.

6. The system of claim 1 , wherein the geolocation data is determined based on one or more of the following: information received from web browsers, mobile location services, cell tower triangulation, user data, third party data, global positioning system (GPS) data, Wi-Fi location data, and cell identification data (ID).

7. The system of claim 1 , wherein the execution of the policy rules includes allowing or denying one or more of the following: annotations, updates, access modifications, view modifications, content modifications, and contact information filtering.

8. The system of claim 1 , wherein the geolocation data are determined based on network data associated with the plurality of objects or received from a third party.

9. The system of claim 1 , wherein the execution of the policy rules includes:

receiving, from a user, a request to perform an action with respect to a first object of the plurality of objects;

determining a location policy attribute associated with the user;

based on the location policy attribute, determining one or more second objects configured to perform the action with respect to the first object; and

providing a list of the one or more second objects to the user to allow the user to select one of the one or more second objects to perform the action.

10. A method for providing geolocation-based policy rules, the method comprising:

processing, by a policy engine on at least one computing system, received geolocation data, at least one regional attribute, and content metadata for a plurality of objects;

based on the geolocation data, the at least one regional attribute, and a portion of the content metadata, creating, by the policy engine, location policy attributes for the plurality of objects, the location policy attributes being geographically bounded by the at least one regional attribute;

incorporating, by the policy engine, the location policy attributes into policy rules, the policy rules including rules for accessing the plurality of objects; and

executing, by the policy engine, the policy rules with regard to the plurality of objects, the policy rules comprising allowing a user to view redacted content based on access privileges and the geolocation data of the user.

11. The method of claim 10 , wherein the execution of the policy rules includes:

receiving, from a user, a request to access one of the plurality of objects;

determining a location policy attribute associated with the user;

determining, based on the policy rules and the location policy attribute, whether the access to the one of the plurality of objects is allowed for the user; and

based on the determination, selectively providing the user with the access to the one of the plurality of objects.

12. The method of claim 11 , further comprising:

determining further attributes associated with the plurality of objects, the further attributes including one or more of the following: security of access, content metadata, an identity of a user, an access privilege of the user, a role of the user, an applicable law, a geographic region, and a time zone, wherein the selectively providing the user with the access is further based on the further attributes.

13. The method of claim 12 , further comprising incorporating the further attributes into the policy rules.

14. The method of claim 10 , wherein the execution of the policy rules includes:

receiving an Application Programming Interface (API) call to access one of the plurality of objects;

determining a location policy attribute associated with at least one of the following: a user device initiating the API call, a user associated with the user device, and an application running on the user device and initiating the API call;

determining, based on the policy rules and the location policy attribute, whether the access to the one of the plurality of objects is allowed; and

based on the determining, selectively providing the user with the access to the one of the plurality of objects.

15. The method of claim 10 , wherein the plurality of objects includes one or more of the following: a data object, content, a file, a person, a user, a hardware, a software, a domain, a domain object, a network resource, and a network device.

16. The method of claim 10 , wherein the geolocation data is determined based on one or more of the following: information received from web browsers, mobile location services, cell tower triangulation, user data, third party data, global positioning system (GPS) data, Wi-Fi location data, and cell identification data (ID).

17. The method of claim 10 , wherein the execution of the policy rules includes allowing or denying one or more of the following: annotations, updates, access modifications, view modifications, content modifications, and contact information filtering.

18. The method of claim 10 , wherein the geolocation data are received from a third party or determined based on network data associated with the plurality of objects.

19. The method of claim 10 , wherein the execution of the policy rules includes:

receiving, from a user, a request to perform an action with respect to a first object of the plurality of objects;

determining a location policy attribute associated with the user;

based on the location policy attribute, determining one or more second objects configured to perform the action with respect to the first object; and

providing a list of the one or more second objects to the user to allow the user to select one of the one or more second objects to perform the action.

20. A non-transitory computer-readable storage medium having embodied thereon instructions, which when executed by at least one processor, perform steps of a method comprising:

processing, by a policy engine on at least one computing system, received geolocation data, at least one regional attribute, and content metadata for a plurality of objects;

based on the geolocation data, the at least one regional attribute, and a portion of the content metadata, creating, by the policy engine, location policy attributes for the plurality of objects, the location policy attributes being geographically bounded by the at least one regional attribute;

incorporating, by the policy engine, the location policy attributes into policy rules, the policy rules including rules for accessing the plurality of objects; and

executing, by the policy engine, the policy rules with regard to the plurality of objects, the policy rules comprising allowing a user to view redacted content based on access privileges and the geolocation data of the user.

Assignments (3)
CHANGE OF NAME Recorded May 17, 2024
From: ASG TECHNOLOGIES GROUP, INC.
To: ROCKET SOFTWARE TECHNOLOGIES, INC.
Reel/Frame 067456/0863 →
CHANGE OF ADDRESS Recorded Dec 27, 2022
From: ASG TECHNOLOGIES GROUP, INC. DBA ASG TECHNOLOGIES
To: ASG TECHNOLOGIES GROUP, INC. DBA ASG TECHNOLOGIES
Reel/Frame 062714/0198 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2021
From: BALAN, SUDHI; BAIAD, RANDY; RUSSELL, ROBERT
To: ASG TECHNOLOGIES GROUP, INC. DBA ASG TECHNOLOGIES
Reel/Frame 057769/0510 →
Continuity (2)
Provisional Application 63091134 · Oct 13, 2020
Related Publication 20220116787A1 · Apr 14, 2022