IP Library Granted Patent US 9,253,179
Granted Patent B2
US 9,253,179 · App. 14/091,730 · Granted Feb 2, 2016

Managing security restrictions on a resource in a defined environment

Inventor: Mark J. Hoesl (Friendswood, TX)
Assignee: International Business Machines Corporation
H04L63/08G06F21/62
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,253,179
App. No.
14/091,730
Granted
Feb 2, 2016
Kind
B2
Abstract

Approaches described herein manage security restrictions on a resource in a defined environment to provide authorization and access. Specifically, a security system maintains a security restriction on the resource (e.g., an information technology (IT) account of a user, or an apparatus) in a defined environment. The presence of a plurality of users is continuously monitored throughout the defined environment and, based on a detection of a pre-specified set of users from the plurality of users in the defined environment, the security restriction is managed (e.g., removed or maintained). In one embodiment, the system removes the security restriction from the resource to allow at least one of: access to the IT account of the user, and operation of the apparatus. The security restriction on the resource may then be reinstated in the case that the pre-specified set of users from the plurality of users is no longer present in the defined environment.

Claims (27)

1. A method for managing security restrictions on a resource in a defined environment, the method comprising the computer-implemented steps of:

maintaining a security restriction on a resource in a defined environment, the resource comprising at least one of: an information technology (IT) account of a user, and an apparatus;

continuously monitoring a presence of a plurality of users in the defined environment;

managing the security restriction on the resource based on a detection of a pre-specified set of users from the plurality of users in the defined environment, the managing the security restriction comprising removing the security restriction on the resource to allow at least one of: access to the IT account of the user, and operation of the apparatus; and

reinstating the security restriction on the resource in the case that the pre-specified set of users from the plurality of users is no longer present in the defined environment, wherein the security restriction is reinstated when either of: a maximum number of users in the defined environment is attained, and a minimum number of users in the defined environment is not attained.

2. The method according to claim 1 , the monitoring the presence of the plurality of users comprising receiving user credentials from each of the plurality of users.

3. The method according to claim 2 , wherein the user credentials from each of the plurality of users is received via an authentication device at an access control system of an access control point.

4. The method according to claim 1 , further comprising generating an alert to indicate that the pre-specified set of users from the plurality of users is no longer present in the defined environment.

5. A system for managing security restrictions on a resource in a defined environment, the system comprising:

a memory medium comprising instructions;

a bus coupled to the memory medium; and

a processor coupled to a security system via the bus that when executing the instructions causes the system to:

maintain a security restriction on a resource in a defined environment, the resource comprising at least one of: an information technology (IT) account of a user, and an apparatus;

continuously monitor a presence of a plurality of users in the defined environment;

manage the security restriction on the resource based on a detection of a pre-specified set of users from the plurality of users in the defined environment, the managing the security restriction comprising removing the security restriction on the resource to allow at least one of: access to the IT account of the user, and operation of the apparatus; and

reinstate the security restriction on the resource in the case that the pre-specified set of users from the plurality of users is no longer present in the defined environment, wherein the security restriction is reinstated when either of: a maximum number of users in the defined environment is attained, and a minimum number of users in the defined environment is not attained.

6. The system according to claim 5 , the instructions causing the system to monitor the presence of the plurality of users comprising instructions causing the system to receive user credentials from each of the plurality of users.

7. The system according to claim 6 , wherein the user credentials from each of the plurality of users is received via an authentication device at an access control system of an access control point.

8. The system according to claim 5 , further comprising instructions causing the system to generate an alert to indicate that the pre-specified set of users from the plurality of users is no longer present in the defined environment.

9. A computer-readable storage device storing computer instructions, which when executed, enables a computer system to manage security restrictions on a resource in a defined environment, the computer instructions comprising:

maintaining a security restriction on a resource in a defined environment, the resource comprising at least one of: an information technology (IT) account of a user, and an apparatus;

continuously monitoring a presence of a plurality of users in the defined environment;

managing the security restriction on the resource based on a detection of a pre-specified set of users from the plurality of users in the defined environment, the managing the security restriction comprising removing the security restriction on the resource to allow at least one of: access to the IT account of the user, and operation of the apparatus; and

reinstating the security restriction on the resource in the case that the pre-specified set of users from the plurality of users is no longer present in the defined environment, wherein the security restriction is reinstated in the case that either of: a maximum number of users in the defined environment is attained, and a minimum number of users in the defined environment is not attained.

10. The computer-readable storage device according to claim 9 , the computer instructions causing the system to monitor the presence of the plurality of users comprising receiving user credentials from each of the plurality of users.

11. The computer-readable storage device according to claim 10 , wherein the user credentials from each of the plurality of users is received via an authentication device at an access control system of an access control point.

12. The computer-readable storage device according to claim 9 , further comprising computer instructions causing the system to generate an alert to indicate that the pre-specified set of users from the plurality of users is no longer present in the defined environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2013
From: HOESL, MARK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 031703/0066 →
Continuity (2)
Continuation In Part 13548789 · Jul 13, 2012
Related Publication 20140096204A1 · Apr 3, 2014