IP Library › Granted Patent US 10,673,831
Granted Patent B2
US 10,673,831 · App. 15/675,524 · Granted Jun 2, 2020

Systems and methods for automating security controls between computer networks

Inventors: Sasan Sahraei (Dublin, IE); Navjot S. Sidhu (Ardsley, NY); Eric G. Alger (Edwardsville, IL); Jenny Qian Zhang (Wildwood, MO)
Assignee: Mastercard International Incorporated
H04L63/0807H04L63/0823H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,673,831
App. No.
15/675,524
Filed
Aug 11, 2017
Granted
Jun 2, 2020
Kind
B2
Examiner
LI, MENG
Art Unit
2437
USPC
726/10
Abstract

A security control (SC) system including one or more security control (SC) computing devices for automating security controls between computer networks is provided. The SC system is configured to receive a request to access a service including a system identifier that identifies a computer system requesting access to a service controlled by the one or more SC computing devices, build a token request based on the request, and correlate the token request to at least one security policy associated with the system identifier. The SC system is also configured to generate an access token in response to the token request, wherein the access token is included in an authorization request, and invoke the service using the authorization request. The SC system is further configured to validate the access token using the at least one security policy and authorize access to the service based on the at least one security policy.

Claims (54)

1. A security control (SC) system comprising one or more security control (SC) computing devices for automating security controls between computer networks, the one or more SC computing devices comprising at least one processor and a memory, the SC system configured to:

generate, using a declared dependency graph, a network topology based on service metadata identifying zones of the computer networks;

identify one or more computer systems included in the computer networks based on the network topology, wherein the identified one or more computer systems are one or more non-privileged access computer systems that do not require privileged access to a service controlled by the one or more SC computing devices;

receive a request to access the service including a system identifier, the system identifier identifies a candidate computer system requesting access to the service;

perform a lookup in the network topology for the candidate computer system;

determine that the candidate computer system is not one of the one or more non-privileged access computer systems based on results from the lookup;

in response to the determination, build a token request based on the received request;

download, from a policy administration point (PAP), at least one security policy and at least one public key, the at least one security policy and the at least one public key associated with the system identifier;

correlate the token request to the at least one security policy and the at least one public key;

generate an access token in response to the token request, wherein the access token is included in an authorization request;

invoke the service using the authorization request;

validate the access token using the at least one security policy and the at least one public key; and

authorize access to the service in response to the validation.

2. The SC system of claim 1 further configured to monitor a time stamp included in the access token.

3. The SC system of claim 2 further configured to deny access to the service when the time stamp meets a predefined threshold.

4. The SC system of claim 3 further configured to renew access to the service when the time stamp meets the predefined threshold and the at least one security policy enables to renew access to the service.

5. The SC system of claim 1 further configured to generate the access token and encrypt the access token based on the at least one security policy.

6. The SC system of claim 1 further configured to store data included in the access token in a database, wherein the database is in communication with the SC system.

7. A computer-implemented method for automating security controls between computer networks, the method implemented using one or more security control (SC) computing devices coupled to a memory device, the method comprising:

generating, using a declared dependency graph, a network topology based on service metadata identifying zones of the computer networks;

identifying one or more computer systems included in the computer networks based on the network topology, wherein the identified one or more computer systems are one or more non-privileged access computer systems that do not require privileged access to a service controlled by the one or more SC computing devices;

receiving a request to access the service including a system identifier, the system identifier identifies a candidate computer system requesting access to the service;

performing a lookup in the network topology for the candidate computer system;

determining that the candidate computer system is not one of the one or more non-privileged access computer systems based on results from the lookup;

in response to the determination, building a token request based on the received request;

downloading, from a policy administration point (PAP), at least one security policy and at least one public key, the at least one security policy and the at least one public key associated with the system identifier;

correlating the token request to the at least one security policy and the at least one public key;

generating an access token in response to the token request, wherein the access token is included in an authorization request;

invoking the service using the authorization request;

validating the access token using the at least one security policy and the at least one public key; and

authorizing access to the service in response to the validation.

8. The method of claim 7 further comprising monitoring a time stamp included in the access token.

9. The method of claim 8 further comprising denying access to the service when the time stamp meets a predefined threshold.

10. The method of claim 9 further comprising renewing access to the service when the time stamp meets the predefined threshold and the at least one security policy enables to renew access to the service.

11. The method of claim 7 further comprising generating the access token and encrypt the access token based on the at least one security policy.

12. The method of claim 7 further comprising storing data included in the access token in a database, wherein the database is in communication with the one or more SC computing devices.

13. A non-transitory computer-readable medium that includes computer-executable instructions for automating security controls between computer networks, wherein when executed by one or more security control (SC) computing devices comprising at least one processor in communication with at least one memory device, the computer-executable instructions cause the one or more SC computing devices to:

generate, using a declared dependency graph, a network topology based on service metadata identifying zones of the computer networks;

identify one or more computer systems included in the computer networks based on the network topology, wherein the identified one or more computer systems are one or more non-privileged access computer systems that do not require privileged access to a service controlled by the one or more SC computing devices;

receive a request to access the service including a system identifier, the system identifier identifies a candidate computer system requesting access to service;

perform a lookup in the network topology for the candidate computer system;

determine that the candidate computer system is not one of the one or more non-privileged access computer systems based on results from the lookup;

in response to the determination, build a token request based on the received request;

download, from a policy administration point (PAP), at least one security policy and at least one public key, the at least one security policy and the at least one public key associated with the system identifier;

correlate the token request to the at least one security policy and the at least one public key;

generate an access token in response to the token request, wherein the access token is included in an authorization request;

invoke the service using the authorization request;

validate the access token using the at least one security policy and the at least one public key; and

authorize access to the service in response to the validation.

14. The computer-readable medium of claim 13 wherein the computer-executable instructions further cause the one or more SC computing devices monitor a time stamp included in the access token.

15. The computer-readable medium of claim 14 wherein the computer-executable instructions further cause the one or more SC computing devices to deny access to the service when the time stamp meets a predefined threshold.

16. The computer-readable medium of claim 15 wherein the computer-executable instructions further cause the one or more SC computing devices to renew access to the service when the time stamp meets the predefined threshold and the at least one security policy enables to renew access to the service.

17. The computer-readable medium of claim 13 wherein the computer-executable instructions further cause the one or more SC computing devices to generate the access token and encrypt the access token based on the at least one security policy.

18. The computer-readable medium of claim 13 wherein the computer-executable instructions further cause the one or more SC computing devices to store data included in the access token in a database, wherein the database is in communication with the one or more SC computing devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2017
From: SAHRAEI, SASAN; SIDHU, NAVJOT S.; ALGER, ERIC G.; ZHANG, JENNY QIAN
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 043273/0218 →
Continuity (1)
Related Publication 20190052621A1 · Feb 14, 2019