US2004128537A1PendingUtilityA1
Retrospective policy safety net
Est. expiryDec 30, 2022(expired)· nominal 20-yr term from priority
H04L 63/101G06F 2221/2101G06F 21/6218G06F 21/00
47
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
These and other objectives are attained with a method and system for evaluating an access policy change. The method comprises the step of providing an access control mechanism having a first policy, and an audit log having entries of accesses made under that first policy. The method comprises the further steps of submitting a second policy to the access control mechanism, comparing the log entries to the second policy, and based on the results of the comparing step, taking one of a predetermined number of actions.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of evaluating an access policy change, comprising the steps of:
providing an access control mechanism having a first policy, and an audit log having entries of accesses made under said first policy; submitting a second policy to said access control mechanism; comparing said entries to said second policy; and based on the results of the comparing step, taking one of a predetermined number of actions.
2 . A method according to claim 1 , wherein:
each entry in the log identifies a person and an associated action; and the comparing step includes the step of, for each of a group of the entries, determining whether the person identified in the action has access under the second policy to the associated action.
3 . A method according to claim 1 , wherein the taking step includes the step of displaying any of said entries which do not have access under said second policy.
4 . A method according to claim 1 , wherein the taking step includes the step of modifying the second policy, using one of a group of predefined procedures, based on the results of the comparing step.
5 . A method according to claim 4 , wherein a defined group of users has access to a specified action under the first policy and do not have access to the specified action under the second policy, and wherein the modifying step includes the step of altering the second policy so that said second policy provides a subset of said group of users with access to the specified action.
6 . A method according to claim 1 , wherein the comparing step includes the step of comparing said entries to the second policy before the second policy becomes active.
7 . A system for evaluating an access policy change, comprising:
means providing an access control mechanism having a first policy, and an audit log having entries of accesses made under said first policy, said access control mechanism including means for receiving a second policy; means for comparing said entries to said second policy; and comprises means for taking one of a predetermined number of actions based on the results of the comparing means.
8 . A system according to claim 7 , wherein:
each entry in the log identifies a person and an associated action; and the means for comparing includes means for determining, for each of a group of the entries, action.
9 . A system according to claim 7 , wherein the means for taking includes means for displaying any of said entries which do not have access under said second policy.
10 . A system according to claim 7 , wherein the means for taking includes means for modifying the second policy, using one of a group of predefined procedures, based on the results of the comparing means.
11 . A system according to claim 9 , wherein a defined group of users has access to a specified action under the first policy and do not have access to the specified action under the second policy, and wherein the modifying means includes means for altering the second policy so that said second policy provides a subset of said group of users with access to the specified action.
12 . A system according to claim 11 , wherein the comparing means compares said entries to the second policy before the second policy becomes active.
13 . A program storage device readable by machine, tangibly embodying a program of instructions executable by the machine to perform method steps for evaluating an access policy change, said method steps comprising:
providing an access control mechanism having a first policy, and an audit log having entries of accesses made under said first policy; submitting a second policy to said access control mechanism; comparing said entries to said second policy; and based on the results of the comparing step, taking one of a predetermined number of actions.
14 . A program storage device according to claim 13 , wherein:
each entry in the log identifies a person and an associated action; and the comparing step includes the step of, for each of a group of the entries, determining whether the person identified in the action has access under the second policy to the associated action.
15 . A program storage device according to claim 13 , wherein the taking step includes the step of displaying any of said entries which do not have access under said second policy
16 . A program storage device according to claim 15 , wherein the taking step includes the step of modifying the second policy, using one of a group of predefined procedures, based on the results of the taking step.
17 . A program storage device according to claim 16 , wherein a defined group of users has access to a specified action under the first policy and do not have access to the specified action under the second policy, and wherein the modifying step includes the step of altering the second policy so that said second policy provides a subset of said group of users with access to the specified action.
18 . A method according to claim 13 , wherein the comparing step includes the step of comparing said entries to the second policy before the second policy becomes active.Join the waitlist — get patent alerts
Track US2004128537A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.