IP Library Granted Patent US 12,615,261
Granted Patent B2
US 12,615,261 · App. 18/513,282 · Granted Apr 28, 2026

Enterprise user access discovery and management using policy and entitlement framework

Inventors: John Hassler (Batavia, IL); Sindhu Kakarla (Leander, TX); Onn Lin Lee (Renton, WA); Kevin Kwok Leung (Shoreline, WA)
Assignee: T-Mobile Innovations LLC
H04L63/104H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,261
App. No.
18/513,282
Granted
Apr 28, 2026
Kind
B2
Abstract

A system and method for enabling fine-grained access to enterprise applications in an enterprise network. The method includes receiving, via a discovery application running on a computing device, user input from a user, where the user input identifies at least one of an application name, a server name, or an Internet Protocol (IP) address associated with a computing resource for accessing an enterprise application; comparing, via the discovery application, the user input to application information stored in a database accessible by the discovery application; sending, via the discovery application, a message to the user in response to determining a match between the user input and the application information, where the message identifies a membership group containing the computing resource for accessing the enterprise application; and enabling the user to access the membership group using the computing resource when the user is a member of the membership group.

Claims (22)

1 . A method for discovering membership groups to access enterprise applications, the method comprising:

creating, via a discovery application running on a computing device, one or more entitlement rules specifying computing resources for accessing enterprise applications within a membership group;

creating, via the discovery application, one or more blocking rules corresponding to each of the one or more entitlement rules in response to creating each entitlement rule, wherein the one or more blocking rules are configured to restrict access to one or more of the enterprise applications within the membership group for a subset of one or more users in the membership group;

receiving, via the discovery application, user input from a user, wherein the user is included in the subset of one or more users in the membership group, wherein the user input identifies at least one of an application name, a server name, or an Internet Protocol (IP) address associated with a computing resource for accessing an enterprise application, and wherein the computing resource is one of the computing resources within the membership group and the enterprise application is one of the enterprise applications within the membership group;

comparing, via the discovery application, the user input to application information stored in a database accessible by the discovery application;

sending, via the discovery application, a message to the user in response to determining a match between the user input and the application information, wherein the message identifies the membership group containing the computing resource for accessing the enterprise application; and

enabling the user to access the enterprise application using the computing resource based on the one or more entitlement rules while restricting the user from accessing at least another one of the enterprise applications in the membership group based on the one or more blocking rules.

2 . The method of claim 1 , wherein the application information comprises rules for accessing computing resources in a plurality of membership groups including a first membership group.

3 . The method of claim 2 , wherein the plurality of membership groups comprises a plurality of active directory (AD) groups.

4 . The method of claim 1 , wherein before enabling the user to access the enterprise application, the method further comprises forwarding, via the discovery application, an access request from the user to an owner of the membership group.

5 . The method of claim 1 , wherein the message comprises descriptive information about the membership group.

6 . The method of claim 1 , wherein the computing resource comprises at least one of a server or a port associated with the membership group.

7 . A method for enabling fine-grained access to enterprise applications, the method comprising:

defining, via a discovery application running on a computing device, an access policy for a membership group;

creating, via the discovery application, one or more entitlement rules specifying computing resources for accessing enterprise applications within the membership group;

creating, via the discovery application, one or more blocking rules corresponding to each of the one or more entitlement rules in response to creating each entitlement rule, wherein the one or more blocking rules are configured to restrict access to one or more of the enterprise applications within the membership group for a subset of one or more users in the membership group;

receiving, via the discovery application, a request from a user to access at least one of the enterprise applications in the membership group, wherein the user is included in the subset of one or more users in the membership group; and

granting the user access to at least one of the enterprise applications in the membership group based on the one or more entitlement rules while restricting the user from accessing at least another one of the enterprise applications in the membership group based on the one or more blocking rules.

8 . The method of claim 7 , wherein the membership group comprises an active directory (AD) group.

9 . The method of claim 7 , wherein the one or more entitlement rules are defined by an owner of the enterprise applications.

10 . The method of claim 7 , further comprising storing each of the one or more blocking rules in a master block policy accessible to the discovery application.

11 . The method of claim 10 , further comprising storing the one or more entitlement rules in the master block policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2023
From: HASSLER, JOHN; KAKARLA, SINDHU; LEE, ONN LIN; LEUNG, KEVIN KWOK
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 065628/0739 →
Continuity (1)
Related Publication 20250168170A1 · May 22, 2025
References Cited (17)
US 8503981B1 · Xue · 2013 [cited by examiner]
US 8935311B2 · Hannel · 2015 [cited by examiner]
US 9577891B1 · Avery · 2017 [cited by examiner]
US 11582609B2 · Zhu · 2023 [cited by examiner]
US 12170581B2 · Gautama · 2024 [cited by examiner]
US 20030177389A1 · Albert · 2003 [cited by examiner]
US 20040098446A1 · Styles · 2004 [cited by examiner]
US 20080256458A1 · Aldred · 2008 [cited by examiner]
US 20110107327A1 · Barkie · 2011 [cited by examiner]
US 20140059645A1 · Hannel · 2014 [cited by examiner]
US 20170163666A1 · Venkatramani · 2017 [cited by examiner]
US 20210029174A1 · Kunduru · 2021 [cited by examiner]
US 20220030001A1 · Poetter · 2022 [cited by examiner]
US 20220078190A1 · Hydell · 2022 [cited by examiner]
Zhou, Qian, et al. “Towards fine-grained access control in enterprise-scale Internet-of-Things.” IEEE Transactions on Mobile Computing 20.8 (2020): 2701-2714. (Year: 2020). [cited by examiner]
Rech, Alexander, Christian Steger, and Markus Pistauer. “A decentralized service-platform towards cross-domain entitlement handling.” 2019 IEEE International Conference on Blockchain (Blockchain). IEEE, 2019. (Year: 201… [cited by examiner]
Foreign Communication From a Related Counterpart Application, Partial EP Search Report and EP Search Opinion dated Mar. 21, 2025 EP Application No. 24209993.5. [cited by applicant]