US2004128537A1PendingUtilityA1

Retrospective policy safety net

Assignee: IBMPriority: Dec 30, 2002Filed: Dec 30, 2002Published: Jul 1, 2004
Est. expiryDec 30, 2022(expired)· nominal 20-yr term from priority
H04L 63/101G06F 2221/2101G06F 21/6218G06F 21/00
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

These and other objectives are attained with a method and system for evaluating an access policy change. The method comprises the step of providing an access control mechanism having a first policy, and an audit log having entries of accesses made under that first policy. The method comprises the further steps of submitting a second policy to the access control mechanism, comparing the log entries to the second policy, and based on the results of the comparing step, taking one of a predetermined number of actions.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A method of evaluating an access policy change, comprising the steps of: 
 providing an access control mechanism having a first policy, and an audit log having entries of accesses made under said first policy;    submitting a second policy to said access control mechanism;    comparing said entries to said second policy; and    based on the results of the comparing step, taking one of a predetermined number of actions.    
     
     
         2 . A method according to  claim 1 , wherein: 
 each entry in the log identifies a person and an associated action; and    the comparing step includes the step of, for each of a group of the entries, determining whether the person identified in the action has access under the second policy to the associated action.    
     
     
         3 . A method according to  claim 1 , wherein the taking step includes the step of displaying any of said entries which do not have access under said second policy.  
     
     
         4 . A method according to  claim 1 , wherein the taking step includes the step of modifying the second policy, using one of a group of predefined procedures, based on the results of the comparing step.  
     
     
         5 . A method according to  claim 4 , wherein a defined group of users has access to a specified action under the first policy and do not have access to the specified action under the second policy, and wherein the modifying step includes the step of altering the second policy so that said second policy provides a subset of said group of users with access to the specified action.  
     
     
         6 . A method according to  claim 1 , wherein the comparing step includes the step of comparing said entries to the second policy before the second policy becomes active.  
     
     
         7 . A system for evaluating an access policy change, comprising: 
 means providing an access control mechanism having a first policy, and an audit log having entries of accesses made under said first policy, said access control mechanism including    means for receiving a second policy;    means for comparing said entries to said second policy; and    comprises means for taking one of a predetermined number of actions based on the results of the comparing means.    
     
     
         8 . A system according to  claim 7 , wherein: 
 each entry in the log identifies a person and an associated action; and    the means for comparing includes means for determining, for each of a group of the entries,    action.    
     
     
         9 . A system according to  claim 7 , wherein the means for taking includes means for displaying any of said entries which do not have access under said second policy.  
     
     
         10 . A system according to  claim 7 , wherein the means for taking includes means for modifying the second policy, using one of a group of predefined procedures, based on the results of the comparing means.  
     
     
         11 . A system according to  claim 9 , wherein a defined group of users has access to a specified action under the first policy and do not have access to the specified action under the second policy, and wherein the modifying means includes means for altering the second policy so that said second policy provides a subset of said group of users with access to the specified action.  
     
     
         12 . A system according to  claim 11 , wherein the comparing means compares said entries to the second policy before the second policy becomes active.  
     
     
         13 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform method steps for evaluating an access policy change, said method steps comprising: 
 providing an access control mechanism having a first policy, and an audit log having entries of accesses made under said first policy;    submitting a second policy to said access control mechanism;    comparing said entries to said second policy; and    based on the results of the comparing step, taking one of a predetermined number of actions.    
     
     
         14 . A program storage device according to  claim 13 , wherein: 
 each entry in the log identifies a person and an associated action; and    the comparing step includes the step of, for each of a group of the entries, determining whether    the person identified in the action has access under the second policy to the associated action.    
     
     
         15 . A program storage device according to  claim 13 , wherein the taking step includes the step of displaying any of said entries which do not have access under said second policy  
     
     
         16 . A program storage device according to  claim 15 , wherein the taking step includes the step of modifying the second policy, using one of a group of predefined procedures, based on the results of the taking step.  
     
     
         17 . A program storage device according to  claim 16 , wherein a defined group of users has access to a specified action under the first policy and do not have access to the specified action under the second policy, and wherein the modifying step includes the step of altering the second policy so that said second policy provides a subset of said group of users with access to the specified action.  
     
     
         18 . A method according to  claim 13 , wherein the comparing step includes the step of comparing said entries to the second policy before the second policy becomes active.

Join the waitlist — get patent alerts

Track US2004128537A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.