IP Library › Granted Patent US 12,335,268
Granted Patent B2
US 12,335,268 · App. 18/032,126 · Granted Jun 17, 2025

Scenario-based access control

Inventors: James Paul Gyarmathy, Jr. (Shoreline, WA); Ali Alam (Sammamish, WA); Amanda Holcomb (Gig Harbor, WA); Alka Garg (Redmond, WA); Ayyappan Balasubramanian (Redmond, WA); Mansi Singhal (Redmond, WA); Gerardo Bodegas Martinez (Kirkland, WA); Michael Todd (Mill Creek, WA); Carrie Ann Culley (Seattle, WA); Hardeep Kohli (Bothell, WA); Can Zheng (Sammamish, WA); Rohan Kamath (Issaquah, WA); Sandhya Vankamamidi (Redmond, WA); Jing Jing (Beijing, CN); Zhuang Gao (Kirkland, WA); John Kingsly Masilamani (North Bend, WA); Jack Pullikottil (Redmond, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/101H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,268
App. No.
18/032,126
Granted
Jun 17, 2025
Kind
B2
Abstract

Methods, systems, and computer programs are presented for managing access to resources using scenarios. One method includes an operation for storing first scenario data received for a first control scenario. The first scenario data comprises a control scenario identifier, a first resource, an authorization control, and a scenario trigger that defines an event that causes an activation of the first control scenario for providing access to the first resource. Further, the method includes operations for monitoring for an occurrence of the scenario trigger and detecting an occurrence of the event associated with the scenario trigger. Further, the method determines, in response to the occurrence of the event, a set of users authorized to access the first resource, including accessing the first scenario data to determine the set of users associated with the authorization control. Furthermore, access is provided to the set of users based on the determining.

Claims (40)

1. A computer-implemented method comprising:

storing, in a computer memory, first scenario data received for a first control scenario, the first scenario data comprising a control scenario identifier, a first resource, an authorization control, and a scenario trigger that defines an event that causes an activation of the first control scenario for providing access to the first resource;

monitoring for an occurrence of the scenario trigger;

detecting an occurrence of the event associated with the scenario trigger of the first control scenario;

determining, in response to the occurrence of the event, a set of users authorized to access the first resource, wherein determining the set of users includes accessing the stored first scenario data to determine the set of users associated with the authorization control; and

providing access to the set of users based on the determining;

and wherein the method further comprises providing a user interface for finding available control scenarios for a user, the user interface including an entry field for entering search query text to search by at least control scenario name, and wherein the user interface comprises a window presenting results.

2. The method as recited in claim 1 , wherein monitoring for an occurrence of the scenario trigger comprises detecting one or more of: a catastrophic event, a social disturbance, a request for access to the resource from a user, a system outage, a new member added to a group associated with the first control scenario, a member leaving the group associated with the first control scenario, or a security breach.

3. The method as recited in claim 1 , further comprising:

providing a requester user interface to a first user from the set of users authorized to access the first resource, the requester user interface including control scenarios visible to the first user, the control scenarios including the first control scenario, the requester user interface including an option for requesting access to the first resource of the first control scenario.

4. The method as recited in claim 1 , further comprising:

providing a scenario user interface (UI) for creating the control scenario that controls access to the resource, wherein the scenario UI for creating the control scenario includes options for inputting one or more of the control scenario identifier, the first resource, the authorization control, the scenario trigger, and criteria for visibility of the control scenario to users.

5. The method as recited in claim 4 , further comprising:

displaying the first control scenario at the scenario UI to the set of users authorized to access the first resource.

6. The method as recited in claim 4 , wherein the first scenario data further comprises a definition of a scenario set of users eligible for requesting access to the first resource in the first control scenario, wherein the first control scenario is made visible to the scenario set of users via the scenario UI.

7. The method as recited in claim 1 , wherein the authorization control is a mechanism which automatically provides access to the set of users authorized to access the first resource when the occurrence of the event associated with the scenario trigger is detected.

8. The method as recited in claim 1 , wherein the authorization control comprises a mechanism which creates an authorization request for review by an administrator of the first control scenario when the occurrence of the event associated with the scenario trigger is detected.

9. The method as recited in claim 1 , wherein the first scenario data further comprises an expiration date for the first control scenario.

10. The method as recited in claim 1 , wherein the first resource is one or more of a door lock, data stored on a memory, a program, a web page, and an application programming interface.

11. The method as recited in claim 1 , wherein the first resource is a resource managed by an active directory, wherein providing access to the set of users based on the determining comprises:

submitting a request to the active directory to enable access to the first resource by the set of users authorized to access the first resource.

12. The method as recited in claim 1 , further including:

providing an attesting user interface (UI) for attesting that requirements, for accessing assets controlled by the control scenario, are met by a requesting user.

13. The method as recited in claim 1 , further including detecting a scenario access request associated with a user, checking if the associated user is one of the users currently approved for access to the first resource under the control scenario, if the associated user is currently approved, checking to determine the scenario access requires renewal and if the scenario access requires renewal, checking to determine if a scenario owner approves the access request.

14. A system for performing scenario based access control comprising:

a processor; and

a memory device coupled to the processor and having a program stored thereon, which when executed by the processor cause the processor to perform operations comprising:

storing, in a computer memory, first scenario data received for a first control scenario, the first scenario data comprising a control scenario identifier, a first resource, an authorization control, and a scenario trigger that defines an event that causes an activation of the first control scenario for providing access to the first resource;

monitoring for an occurrence of the scenario trigger;

detecting an occurrence of the event associated with the scenario trigger of the first control scenario;

determining, in response to the occurrence of the event, a set of users authorized to access the first resource, wherein determining the set of users includes accessing the stored first scenario data to determine the set of users associated with the authorization control; and

providing access to the set of users based on the determining;

and wherein the method further comprises providing a user interface for finding available control scenarios for a user, the user interface including an entry field for entering search query text to search by at least control scenario name, and wherein the user interface comprises a window presenting results.

15. At least one machine-readable media including instructions that, when executed by a machine, cause the machine to perform:

storing, in a computer memory, first scenario data received for a first control scenario, the first scenario data comprising a control scenario identifier, a first resource, an authorization control, and a scenario trigger that defines an event that causes an activation of the first control scenario for providing access to the first resource;

monitoring for an occurrence of the scenario trigger;

detecting an occurrence of the event associated with the scenario trigger of the first control scenario;

determining, in response to the occurrence of the event, a set of users authorized to access the first resource, wherein determining the set of users includes accessing the stored first scenario data to determine the set of users associated with the authorization control; and

providing access to the set of users based on the determining;

and wherein the method further comprises providing a user interface for finding available control scenarios for a user, the user interface including an entry field for entering search query text to search by at least control scenario name, and wherein the user interface comprises a window presenting results.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2023
From: GYRAMATHY, JAMES PAUL, JR.; ALAM, ALI; HOLCOMB, AMANDA; GARG, ALKA; BALASUBRAMANIAN, AYYAPPAN; SINGHAL, MANSI; BODEGAS MARTINEZ, GERARDO; TODD, MICHAEL; CULLEY, CARRIE ANN; KOHLI, HARDEEP; ZHENG, CAN; KAMATH, ROHAN; VANKAMAMIDI, SANDHYA; JING, JING; GUO, ZHUANG; MASILAMANI, JOHN KINGSLY; PULLIKOTTIL, JACK
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 063413/0720 →
Priority Claims (1)
LU 102215 · Nov 24, 2020 · national
Continuity (1)
Related Publication 20230412602A1 · Dec 21, 2023
References Cited (45)
US 7827196B2 · Victor · 2010 [cited by examiner]
US 8959580B2 · Lim · 2015 [cited by examiner]
US 9071626B2 · Morris · 2015 [cited by examiner]
US 10178101B2 · Dintenfass · 2019 [cited by examiner]
US 11063940B2 · Hemaraju · 2021 [cited by examiner]
US 11467553B2 · Short · 2022 [cited by examiner]
US 11526603B2 · Makhlevich · 2022 [cited by examiner]
US 11593165B2 · Pavlin · 2023 [cited by examiner]
US 20050125688A1 · Ogawa · 2005 [cited by examiner]
US 20080015889A1 · Fenster · 2008 [cited by examiner]
US 20120216243A1 · Gill · 2012 [cited by examiner]
US 20130057384A1 · Morris · 2013 [cited by examiner]
US 20140157351A1 · Canning · 2014 [cited by examiner]
US 20140173755A1 · Wahl · 2014 [cited by examiner]
US 20140359127A1 · Linares · 2014 [cited by examiner]
US 20160226858A1 · Pritchard, Jr. · 2016 [cited by examiner]
US 20170272121A1 · Dao · 2017 [cited by examiner]
US 20180048517A1 · Stern · 2018 [cited by examiner]
US 20190182121A1 · Karnes · 2019 [cited by examiner]
US 20200065811A1 · Sloane · 2020 [cited by examiner]
US 20200125050A1 · Short · 2020 [cited by examiner]
US 20200204556A1 · Smith · 2020 [cited by examiner]
US 20200279041A1 · Endler · 2020 [cited by examiner]
US 20210397478A1 · Pavlin · 2021 [cited by examiner]
US 20220078797A1 · Helms · 2022 [cited by examiner]
US 20220092197A1 · Sakowicz · 2022 [cited by examiner]
US 20220180247A1 · Chow · 2022 [cited by examiner]
US 20230179617A1 · Yavo · 2023 [cited by examiner]
US 20230344822A1 · Sloane · 2023 [cited by examiner]
US 20230370322A1 · Arzani · 2023 [cited by examiner]
US 20240241927A1 · Richman · 2024 [cited by examiner]
“Notice of Allowance Issued in European Patent Application No. 21810487.5”, Mailed Date: Oct. 2, 2023, 9 Pages. [cited by applicant]
“Git—everything-is-local”, Retreived from: https://git-scm.com/, Retrieved Date: Jun. 24, 2020, 2 Pages. [cited by applicant]
“HL7 Role-Based Access Control (RBAC) Role Engineering Process”, Retrieved from: https://csrc.nist.gov/csrc/media/projects/role-based-access-control/documents/hl7_role-based_access_control_(rbac).pdf, Sep. 19, 2007, 24 … [cited by applicant]
Weststrate, et al., “MobX”, Retrieved from: https://github.com/mobxjs/mobx, Jun. 27, 2020, 14 Pages. [cited by applicant]
“Semantic UI React”, Retreived from: https://react.semantic-ui.com, Retrieved Date: Jun. 24, 2020, 5 Pages. [cited by applicant]
Hagnelius, et al., “Typewriter”, Retreived from: https://github.com/frhagn/Typewriter, Apr. 21, 2019, 3 Pages. [cited by applicant]
“Search Report Issued in Luxembourg Patent Application No. LU102215”, Mailed Date: Aug. 16, 2021, 11 Pages. [cited by applicant]
Ma, et al., “An Access Control Method based on Scenario Trust”, In International Journal of Computational Intelligence Systems, vol. 5, No. 5, Sep. 2012, pp. 942-952. [cited by applicant]
“International Search Report & Written Opinion issued in PCT Application No. PCT/US21/056285”, Mailed Date : Feb. 3, 2022, 12 Pages. [cited by applicant]
Peleg, et al., “Situation-Based Access Control: Privacy Management via Modeling of Patient Data Access Scenarios”, In Journal of Biomedical Informatics, vol. 41, Issue 6, Dec. 2008, pp. 1028-1040. [cited by applicant]
Schuster, et al., “Situational Access Control in the Internet of Things”, In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, Oct. 15, 2018, pp. 1056-1073. [cited by applicant]
“TypeScript is JavaScript with Syntax for Types”, Retrieved From: https://www.typescriptlang.org/, Retrieved Date: Jun. 24, 2020, 9 Pages. [cited by applicant]
Communication under Rule 71(3) EPC Received for European Application No. 21810487.5, mailed on Jan. 5, 2024, 09 pages. [cited by applicant]
“Decision to Grant Issued in European Patent Application No. 21810487.5”, Mailed Date: Jan. 25, 2024, 2 Pages. [cited by applicant]