IP Library › Granted Patent US 11,170,118
Granted Patent B2
US 11,170,118 · App. 16/659,076 · Granted Nov 9, 2021

Network system and method for access management authentication and authorization

Inventors: M Weam Al-Shanqity (Dhahran, SA); Mohamed Faizal Kooliyattayil Saidali (Al Khobar, SA); Eman A Al Abdulraheem (Dhahran, SA); Mohammad H Fraihat (Dhahran, SA)
Assignee: Saudi Arabian Oil Company
G06F21/604G06F21/6218G06F2221/2129G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,170,118
App. No.
16/659,076
Filed
Oct 21, 2019
Granted
Nov 9, 2021
Kind
B2
Art Unit
2439
USPC
726/7
Abstract

A technology solution, including a method, a system, and a computer program for receiving, processing, and managing access requests in a network system, including autonomously processing and managing access requests to one or more information technology (IT) domains in the network system. The technology solution can include receiving an access request for the computing resource at the node, determining a service type and one or more validation criteria from information included in the access request, comparing the service type and the one or more validation criteria to a validation table, and automatically creating, renewing, modifying or revoking access privileges of a network user at the computing resource at the node without any user intervention.

Claims (59)

1. A method for automatically provisioning access privileges for a computing resource at a node in a computer network which includes a plurality of nodes, the method comprising:

receiving an access request for the computing resource at the node;

determining a service type and one or more validation criteria from information included in the access request, the service type being one of create, renew, modify, and revoke;

comparing the service type and the one or more validation criteria to a validation table;

determining if the access request is consistent with the validation table based on the comparison;

in response to determining the access request is consistent with the validation table:

automatically creating access privileges of a network user for the computing resource at the node without any user intervention when the service type is create;

automatically renewing the access privileges of the network user for the computing resource at the node without any user intervention when the service type is renew;

automatically modifying the access privileges of the network user for the computing resource at the node without any user intervention when the service type is modify; and

automatically revoking the access privileges of the network user for the computing resource at the node without any user intervention when the service type is revoke; and

transmitting a trigger to a network inventory system (NIS),

wherein the NIS comprises an information technology (IT) inventory server, and

wherein the access privileges for the computing resource comprise viewing, editing, and administrator privileges.

2. The method in claim 1 , further comprising:

transmitting a trigger to the computing resource to

compare the service type and the one or more validation criteria to the validation table, and

apply access privileges included in the access request for the network user to the computing resource.

3. The method in claim 2 , wherein the automatically creating, renewing, modifying, and revoking the access privileges of the network user for the computing resource at the node without any user intervention is executed by the computing resource in response to the trigger transmitted to the computing resource.

4. The method in claim 2 ,

wherein the trigger transmitted to the computing resource and the trigger transmitted to the NIS are sent by an automated approval application engine.

5. The method in claim 1 , wherein the computing resource comprises a database server located in an information technology (IT) domain.

6. The method in claim 1 , wherein the one or more validation criteria include at least one of an access type, a user type, a computing resource identification, an area of interest, and a subarea of interest.

7. A system for automatically provisioning access privileges for a node in a computer network that includes a plurality of nodes, the system comprising:

a memory and/or hardware processor; and

a network authentication and authorization (NA 3 ) controller that uses the memory and/or hardware processor in order to:

receive an access request for said node in the computer network;

determine a service type and one or more validation criteria from information included in the access request, the service type being one of create, renew, modify, and revoke;

transmit a trigger to a computing resource located at said node to compare the service type and the one or more validation criteria to validation criteria in a validation table, in order to determine if the access request is consistent with the validation table based on the comparison; and

transmit a further trigger to a network inventory system (NIS);

wherein in response to determining the access request is consistent with the validation table, the computing resource at said node automatically:

creates access privileges of a network user for the computing resource without any user intervention when the service type is create;

renews the access privileges of the network user for the computing resource without any user intervention when the service type is renew;

modifies the access privileges of the network user for the computing resource without any user intervention when the service type is modify; and

revokes the access privileges of the network user for the computing resource without any user intervention when the service type is revoke,

wherein the NIS comprises an information technology (IT) inventory server, and

wherein the access privileges for the node comprise viewing, editing, and administrator privileges.

8. The system in claim 7 , wherein the computing resource comprises a database server.

9. The system in claim 7 , wherein the one or more validation criteria include at least one of an access type, a user type, a computing resource identification, an area of interest, and a subarea of interest.

10. A non-transitory computer readable medium that stores instructions for automatically, without any user intervention, provisioning access privileges for a computing resource at a node in a computer network that includes a plurality of nodes comprising machine executable code which when executed by at least one computing device, causes the at least one computing device to perform steps comprising:

receiving an access request for the computing resource at the node;

determining a service type and one or more validation criteria from information included in the access request, the service type being one of create, renew, modify, and revoke;

comparing the service type and the one or more validation criteria to a validation table;

determining if the access request is consistent with the validation table based on the comparison;

in response to determining the access request is consistent with the validation table:

automatically creating access privileges of a network user for the computing resource at the node without any user intervention when the service type is create;

automatically renewing the access privileges of the network user for the computing resource at the node without any user intervention when the service type is renew;

automatically modifying the access privileges of the network user for the computing resource at the node without any user intervention when the service type is modify; and

automatically revoking the access privileges of the network user for the computing resource at the node without any user intervention when the service type is revoke; and

transmitting a trigger to a network inventory system (NIS),

wherein the NIS comprises an information technology (IT) inventory server, and

wherein the access privileges for the computing resource comprise viewing, editing, and administrator privileges.

11. The non-transitory computer readable medium in claim 10 , further causing the at least one computing device to perform steps comprising:

transmitting a trigger to the computing resource to

compare the service type and the one or more validation criteria to the validation table, and

apply access privileges included in the access request for the network user to the computing resource.

12. The non-transitory computer readable medium in claim 11 , wherein the automatically creating, renewing, modifying, and revoking the access privileges of the network user for the computing resource at the node without any user intervention is executed by the computing resource in response to the trigger.

13. The non-transitory computer readable medium in claim 11 ,

wherein the trigger transmitted to the computing resource and the trigger transmitted to the NIS are sent by an automated approval application engine.

14. The non-transitory computer readable medium in claim 10 , wherein the computing resource comprises a database server located in an information technology (IT) domain.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2019
From: AL-SHANQITY, M WEAM; KOOLIYATTAYIL SAIDALI, MOHAMED FAIZAL; AL ABDULRAHEEM, EMAN A; FRAIHAT, MOHAMMAD H
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 050795/0022 →
Continuity (1)
Related Publication 20210117557A1 · Apr 22, 2021
Cited By (6)
US 12,207,351 US 12,245,118 US 12,439,239 US 12,457,485 US 12,543,026 US 12,580,827