US2015358359A1PendingUtilityA1

Policy-based physical security system for restricting access to computer resources and data flow through network equipment

Assignee: HID GlobalPriority: Aug 14, 2006Filed: Aug 15, 2015Published: Dec 10, 2015
Est. expiryAug 14, 2026(~0 yrs left)· nominal 20-yr term from priority
G07C 9/37G06Q 10/06H04L 63/1416H04L 41/28G06F 21/55G06F 2221/034G06F 21/604H04L 63/20
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Embodiments are directed to systems and methods for integration and normalization of physical security data, states and events to and from disparate physical security systems to maintain in real-time rules based policy state information to enforce physical security policies uniformly across network and information technology (IT) systems. Moreover it pertains specifically to such apparatus for providing an integration platform, methods and processes for normalizing data from physical security systems, to maintain physical security states, mapping to network access and either directly affecting the network equipment through standard programming commands or providing interfaces for network equipment and IT applications to query and determine physical security access states thus enforcing rules in real-time based on security systems data and events.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A system comprising:
 a plurality of network resources distributed throughout a site, the network resources comprising proprietary and Internet Protocol (IP) enabled security system components including sensors, actuators, alarms and monitoring devices, utilizing physical and Information Technology (IT) security data, wherein each sensor of the sensors is configured to generate a signal in response to a defined event, and in accordance with a proprietary data format defined specifically for a device by a respective manufacturer of the device;   a single integration layer component that is configured to receive signals from each of the plurality of network resources in the proprietary data format of a respective security component and integrate disparate proprietary data formats for aggregation and processing in other components, the network resources comprising at least one of: HVAC, lighting, building, video, alarms, identity management, and event security system components;   a central network device security management processor coupled to the plurality of network resources, configured to receive signals from the integration layer by extracting security data and events from network traffic and the security system components to build a continually updated security state of the system through a physical security state engine;   a normalization component in the central network device security management processor normalizing the signal data from the integration layer component in accordance with a defined data mapping scheme to transform the received signals from the proprietary data format to a corresponding Extensible Markup Language (XML) document configured to describe system policies through the use of virtual objects that comprise components of executable rules, and conforming to a schema that represents relationships between the virtual objects and corresponding devices, objects and processes, wherein the schema defines one or more attributes of the executable rules including inputs from the system components, actions to be taken based on the input, addresses of system components performing the actions, and states to be maintained by the coupled network resources;   a rules definition component defining actionable events definitions and responses to actionable events, the physical security policies comprising definitional rules consisting of the virtual objects representing network devices and physical security states used by the plurality of network resources;   a policy manager component defining policies that control a data flow in accordance with the executable rules that are organized into types of policies comprising system, user, and sensor state related policies, and wherein the policies reference the attributes of data objects for each security system component;   a communication integration interface integrating the security data with information technology (IT) data of an entity deploying the system; and   a signal processing component applying the executable rules to the normalized signal data and physical security states to generate control signals that invoke the defined responses to the actionable events and to control the security system components in accordance with policies established for entity personnel defined by the integrated security data and access control rules, and transmitting the control signals to the security system components in the respective proprietary format in order to effect network access, data flow and application security and update the security state of the system.

Join the waitlist — get patent alerts

Track US2015358359A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.