IP Library Granted Patent US 10,671,747
Granted Patent B2
US 10,671,747 · App. 15/932,439 · Granted Jun 2, 2020

Multi-user permission strategy to access sensitive information

Inventors: Dipankar Dasgupta (Germantown, TN); Arunava Roy (Memphis, TN); Debasis Ghosh (Memphis, TN)
G06F21/6218G06F21/40H04L63/0876H04L63/105G06F2221/2113H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,671,747
App. No.
15/932,439
Granted
Jun 2, 2020
Kind
B2
Abstract

A system and related methods for providing greater security and control over access to classified files and documents and other forms of sensitive information based upon a multi-user, multi-modality permission strategy centering on organizational structure, thereby making authentication strategy unpredictable so to significantly reduce the risk of exploitation. Based on the sensitivity or classification of the information being requested by a user, approvers are selected dynamically based on the work environment, e.g., mobility, use of the computing device seeking access, authentication factors under applicable environmental settings, access policy, and the like.

Claims (18)

1. A machine for improved secure access to computing devices, systems, resources, or services, comprising:

one or more computer servers with access control data for a subject organization; and

a processor or microprocessor, wherein the processor or microprocessor is programmed to determine a response to an access authentication request by:

generating an access control graph for the subject organization, said access control graph based on the interrelationships among a plurality of employees and their roles in the subject organization;

receiving an access request from a user to access one or more secured computing devices, computing systems, computer resources, or computer services;

generating a set of possible approvers for the access request from the user, wherein the set of possible approvers is based on each possible approvers' current availability and rank in the subject organization with respect to the user;

generating a set of permission approvers from the set of possible approvers; and

obtaining approval from each of the set of permission grantees prior to providing access to the user in response to the access request.

2. The machine of claim 1 , wherein the set of permission approvers differs for each access request from the user.

3. The machine of claim 1 , wherein the user does not know the set of permission approvers associated with a particular user access request.

4. The machine of claim 1 , wherein the set of possible approvers is based on the key result area (KRA) of the user.

5. The machine of claim 1 , wherein the access request is communicated from a mobile device of the user.

6. The machine of claim 1 , further comprising the step of determining the number of separate approvals required for access to said one or more secured computing devices, computing systems, computer resources, or computer services.

7. The machine of claim 6 , wherein the size of the set of permission approvers is based on the number of separate approvals required.

8. The machine of claim 6 , wherein the number of separate approvals required is based on a sensitivity or classification level of the one or more secured computing devices, computing systems, computer resources, or computer services.

9. The machine of claim 1 , further comprising the step of storing the access request and approvals in a user access log and an approver log corresponding to each approver in the set of permission approvers.

10. The machine of claim 9 , wherein the user access log and the approver logs are stored in a geographically separate location from the one or more computer servers.

11. The machine of claim 1 , wherein the set of permission approvers is determined in real time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2021
From: UNIVERSITY OF MEMPHIS
To: UNIVERSITY OF MEMPHIS RESEARCH FOUNDATION
Reel/Frame 058067/0523 →
Continuity (4)
Continuation In Part 14968676 · Dec 14, 2015
Provisional Application 62169991 · Jun 2, 2015
Provisional Application 62262626 · Dec 3, 2015
Related Publication 20190130124A1 · May 2, 2019