IP Library › Granted Patent US 12,596,827
Granted Patent B1
US 12,596,827 · App. 18/506,205 · Granted Apr 7, 2026

Systems and methods for providing role-based access control to web services using mirrored, secluded web instances

Inventors: Christopher Edward Delaney (Front Royal, VA); Chava Louis Jurado (Leesburg, VA); Carl Bailey Jacobs (Fredericksburg, VA); Jeremiah MacDonald (Greenville, SC)
Assignee: Cyber IP Holdings, LLC
G06F21/6218G06F21/31G06F21/604H04L63/083H04L63/102H04L63/108H04L63/168H04L67/34H04L67/51H04L67/55H04L67/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,827
App. No.
18/506,205
Granted
Apr 7, 2026
Kind
B1
Abstract

Systems and methods are provided for providing access to data on a personalized basis. A service operating on a server is identified, where data at the service is associated with a first user and other users. Data associated with the first user is extracted. A network location is spawned for the first user. The extracted data is transferred to the spawned network location to make the extracted data available to the first user in a read-only fashion by accessing the spawned network location. Additional network locations are spawned for second and third users, respectively, wherein data associated with the second and third users is transferred such that they are available to the second and third users by accessing their respective additional network locations.

Claims (46)

1 . A method for providing access to data, comprising:

identifying, for each of a plurality of users, respective data that is stored on a server that is inaccessible to any of the plurality of users;

spawning a network location for each user;

transferring, for each user, the corresponding data to the respective spawned network location; and

providing, for each user, access to the corresponding transferred data using the respective spawned network location.

2 . The method of claim 1 , further comprising:

detecting an update of the data associated with a first user of the plurality of users; and

pushing updated data associated with the first user to the spawned network location for access by the first user.

3 . The method of claim 1 , further comprising:

receiving a direct access request by a first user of the plurality of users attempting to access a service of the server directly; and

providing an indication to the first user that authentication is required to directly access the service.

4 . The method of claim 3 , further comprising:

receiving an authentication attempt by the first user at the server; and

providing an indication to the first user that the first user is not authorized to directly access the service.

5 . The method of claim 1 , further comprising:

receiving an attempt by a first user of the plurality of users to access the spawned network location; and

providing an indication to the first user that authentication is required to access the spawned network location.

6 . The method of claim 5 , further comprising:

receiving an authentication attempt by the first user at the spawned network location; and

permitting the first user to access the transferred data from the spawned network location.

7 . The method of claim 1 , wherein a first user of the plurality of users is a single user or a group of users.

8 . The method of claim 1 , wherein a service of the server is a message service, wherein messages for a first user of the plurality of users are extracted and transferred to the spawned network location for access by the first user.

9 . The method of claim 1 , wherein the spawned network location for a first user of the plurality of users is maintained for a random or pseudo-random period of time and then is terminated.

10 . The method of claim 9 , wherein, following termination of the spawned network location for the first user, a second network location is spawned for the first user, wherein the data associated with the first user is transferred to the second network location for access by the first user.

11 . The method of claim 1 , wherein authentication credentials and an address for the spawned network location are provided to a first user of the plurality of users via a digital message.

12 . The method of claim 11 , wherein the digital message is an electronic mail or a text message.

13 . The method of claim 11 , wherein the address and the authentication credentials are embedded in a link contained in the digital message.

14 . The method of claim 1 , wherein all data transferred to the spawned network location for a first user of the plurality of users is associated with the first user.

15 . The method of claim 14 , wherein no data that is not associated with the first user is transferred to the spawned network location.

16 . The method of claim 1 , further comprising:

directly accessing a service of the server by a system administrator authorized to directly access the service.

17 . The method of claim 1 , wherein the server connects to the spawned network location for a first user of the plurality of users via a reverse proxy connection to transfer the data associated with the first user.

18 . The method of claim 1 further comprising:

identifying a service operating on the server as being associated with the plurality of users.

19 . A non-transitory computer-readable medium encoded with instructions for commanding one or more data processors to execute steps of a method for providing access to data, the steps comprising:

identifying, for each of a plurality of users, respective data that is stored on a server that is inaccessible to any of the plurality of users;

spawning a network location for each user;

transferring, for each user, the corresponding data to the respective spawned network location; and

providing, for each user, access to the corresponding transferred data using the respective spawned network location.

20 . A system for providing access to data, comprising:

at least one processor; and

memory storing instructions which, when executed by the at least one processor, execute operations comprising:

identifying, for each of a plurality of users, respective data that is stored on a server that is inaccessible to any of the plurality of users;

spawning a network location for each user;

transferring, for each user, the corresponding data to the respective spawned network location; and

providing, for each user, access to the corresponding transferred data using the respective spawned network location.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2023
From: BERRYVILLE HOLDINGS, LLC
To: CYBER IP HOLDINGS, LLC
Reel/Frame 065537/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2023
From: DELANEY, CHRISTOPHER EDWARD; JURADO, CHAVA LOUIS; JACOBS, CARL BAILEY; MACDONALD, JEREMIAH
To: BERRYVILLE HOLDINGS, LLC
Reel/Frame 065520/0218 →
Continuity (3)
Continuation 17190550 · Mar 3, 2021
Continuation 16155408 · Oct 9, 2018
Provisional Application 62570202 · Oct 10, 2017
References Cited (24)
US 6112228A · Earl et al. · 2000 [cited by applicant]
US 8893294B1 · Steele, III et al. · 2014 [cited by applicant]
US 11853443B1 · Delaney · 2023 [cited by examiner]
US 20020010798A1 · Ben-Shaul et al. · 2002 [cited by applicant]
US 20030120593A1 · Bansal et al. · 2003 [cited by applicant]
US 20030145094A1 · Staamann et al. · 2003 [cited by applicant]
US 20030188016A1 · Agarwalla et al. · 2003 [cited by applicant]
US 20030191812A1 · Agarwalla et al. · 2003 [cited by applicant]
US 20040049579A1 · Ims et al. · 2004 [cited by applicant]
US 20070106754A1 · Moore · 2007 [cited by applicant]
US 20080262990A1 · Kapoor et al. · 2008 [cited by applicant]
US 20090157693A1 · Palahnuk · 2009 [cited by applicant]
US 20100037298A1 · Lottin et al. · 2010 [cited by applicant]
US 20120124372A1 · Dilley · 2012 [cited by examiner]
US 20130031203A1 · Bestfleisch et al. · 2013 [cited by applicant]
US 20130291060A1 · Moore · 2013 [cited by applicant]
US 20130325671A1 · Glass · 2013 [cited by examiner]
US 20130326020A1 · Bastide · 2013 [cited by examiner]
US 20160004820A1 · Moore · 2016 [cited by applicant]
US 20160191296A1 · Scharber et al. · 2016 [cited by applicant]
US 20160197886A1 · Lapidous · 2016 [cited by examiner]
US 20170149767A1 · Hinton et al. · 2017 [cited by applicant]
US 20200137189A1 · Steele, III et al. · 2020 [cited by applicant]
Wang, et al.; Random Domain Name and Address Mutation (RDAM) for Thwarting Reconnaissance Attacks; PLoS One, 12(5): e0177111; May 2017. [cited by applicant]