IP Library Granted Patent US 8,539,604
Granted Patent B2
US 8,539,604 · App. 11/196,107 · Granted Sep 17, 2013

Method, system and program product for versioning access control settings

Inventor: David E. Wilson (Lowell, MA)
Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,539,604
App. No.
11/196,107
Granted
Sep 17, 2013
Kind
B2
Abstract

The present invention allows changes to access control settings for a computer-based resource to be detected and stored in a set (e.g., one or more) of electronic documents. In a typical embodiment each stored change includes a previous access control setting and a new access control setting so that the precise differences resulting from changes can be known. In addition, in the event of an access control condition such as an undesired security risk or undesired security restriction, the history of changes maintained in the set of documents can be consulted, and a previous version of access control settings can be reverted to.

Claims (31)

1. A computer-implemented method for versioning access control settings, comprising:

detecting, using a computer device, changes to access control settings made by an administrator for a computer-based resource, wherein the changes to access control settings creates new access control settings;

storing, in response to the detecting changes to access control settings, using the computer device, the new access control settings in a set of documents, wherein at least one set of previous access control settings is maintained, wherein the set of documents contains a history of changes to the access control settings for the computer-based resource, and wherein the history of changes includes at least one set of previous access control settings and, as a result of the storing, the new access control settings;

detecting, in response to the detecting the changes to access control settings, an access control condition, wherein the access control condition is an undesired change in the access control setting for at least one user; and

reverting, in response to the detecting the access control condition, to the at least one set of previous access control settings.

2. The method of claim 1 , wherein the access control condition comprises an undesired security risk.

3. The method of claim 1 , wherein the access control condition comprises an undesired security restriction.

4. The method of claim 1 , wherein the set of documents comprises at least one Extensible Access Control Markup Language (XACML) document.

5. A system for versioning access control settings, comprising:

a computer hardware device including:

a system for detecting changes to access control settings made by an administrator for a computer-based resource, wherein the changes to access control settings creates new access control settings;

a system for storing, in response to the detecting changes to access control settings, the new access control settings in a set of documents, wherein at least one set of previous access control settings is maintained, wherein the set of documents contains a history of changes to the access control settings for the computer-based resource, and wherein the history of changes includes at least one set of previous access control settings and, as a result of the storing, the new access control settings;

a system for detecting, in response to the detecting the changes to access control settings, an access control condition, wherein the access control condition is an undesired change in the access control setting for at least one user; and

a system for reverting, in response to the detecting the access control condition, to the at least one set of previous access control settings.

6. The system of claim 5 , wherein the access control condition comprises an undesired security risk.

7. The system of claim 5 , wherein the access control condition comprises an undesired security restriction.

8. The system of claim 5 , wherein the set of documents comprises at least one Extensible Access Control Markup Language (XACML) document.

9. A program product stored on a computer readable storage non-transitory medium for versioning access control settings, the computer readable storage medium comprising program code for causing a computer system to perform the following steps:

detecting changes to access control settings made by an administrator for a computer-based resource, wherein the changes to access control settings creates new access control settings;

storing, in response to the detecting changes to access control settings, the new access control settings in a set of documents, wherein at least one set of previous access control settings is maintained, wherein the set of documents contains a history of changes to the access control settings for the computer-based resource, and wherein the history of changes includes at least one set of previous access control settings and, as a result of the storing, the new access control settings;

detecting, in response to the detecting the changes to access control settings, an access control condition, wherein the access control condition is an undesired change in the access control setting for at least one user; and

reverting, in response to the detecting the access control condition, to the at least one set of previous access control settings.

10. The program product of claim 9 , wherein the access control condition comprises an undesired security risk.

11. The program product of claim 9 , wherein the access control condition comprises an undesired security restriction.

12. The program product of claim 9 , wherein the set of documents comprises at least one Extensible Access Control Markup Language (XACML) document.

13. A method for deploying an application for versioning access control settings, comprising:

providing a computer infrastructure comprising a device being operable to:

detect changes to access control settings made by an administrator for a computer-based resource, wherein the changes to access control settings creates new access control settings;

store, in response to the detect changes to access control settings, the new access control settings in a set of documents, wherein at least one set of previous access control settings is maintained, wherein the set of documents contains a history of changes to the access control settings for the computer-based resource, and wherein the history of changes includes at least one set of previous access control settings and, as a result of the storing, the new access control settings;

detect, in response to the detect the changes to access control settings, an access control condition, wherein the access control condition is an undesired change in the access control setting for at least one user; and

revert, in response to the detect the access control condition, to the at least one set of previous access control settings.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2005
From: WILSON, DAVID E.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 016637/0522 →
Continuity (1)
Related Publication 20070033654A1 · Feb 8, 2007