US2017011226A1PendingUtilityA1

System and method for access control and identity management

Assignee: SKAI INCPriority: Nov 24, 2010Filed: Mar 21, 2016Published: Jan 12, 2017
Est. expiryNov 24, 2030(~4.3 yrs left)· nominal 20-yr term from priority
H04L 63/10G06F 21/6218H04L 63/102
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In a computer environment, a mechanism for the flow of access by means of derivation is provided. Typically, access rights granted with respect to an access point flow (or derive from) an access provider to an access recipient. Typically, the access provider is a function and the access recipient is a function. The access point may be any object, such as files or functions, to which the access recipient is granted access rights by the access provider. Access is typically represented by a relationship object referencing the access provider function, the access recipient function, and the access point object, and a set of access rights. There are typically different types of access, including read access, right access, and membership access. Therefore, the membership access relationship is typically represented as a subtype of the general/abstract access relationship. Membership is the idea that a first function can gain access to a second function, so that the first function becomes the member of the second function. The membership access relationship (MAR1) maps the access provider role to a function A, maps the access recipient to function B, and maps the access point to function C, wherein, function A is a function doing the membership inviting and therefore providing access (as the access provider), function B is the function being invited and therefore receiving access (as the access recipient), and function C (the access point) is the function into which function B is obtaining membership. When a membership access relationship (MAR1) is created, typically a new associated persona function is generated, representing the new identity created for the access recipient function (function B) while serving as a member of the access point function (function C). Because the persona (persona1) is typically a function, additional rights may be granted to or granted by persona1, such as rights granted by persona1 (as the access provider in a new access relationship) or rights granted to persona1 (as the access recipient in a new access relationship). After a persona (persona1) is created, it may itself be invited by a function 3 to become a member in another function (function 4), thereby creating another membership access relationship (MAR2) in which MAR2's access recipient is persona 1, MAR2's access provider is function 3, and MAR's access point is function 4. A second persona (persona2) is then typically automatically created representing the new membership access (MAR2). Persona2 is then said to derive from persona1, since persona 2 is based on persona1. In this way, identity derivation is provided so that persona1 has a derived persona2 (and persona 2 derives from persona 1). Persona1 may have a plurality of derived personas, including persona2, persona3, and persona4. Since these derived personas are based on the persona1, if persona1 is deleted, persona2, persona3, and persona4 (the derived personas) may also be deleted. So, a new technique is provided by which a function may be invited to participate in a plurality of other functions, wherein each membership “invite” is expressed by a new membership access relationship and each such membership access relationship results in the creation of a new and associated persona. When a persona function is invited to be a member in another function, that in turn generates a membership and a second persona that is derived from the first persona, resulting in identity derivation.

Claims

exact text as granted — not AI-modified
1 - 37 . (canceled) 
     
     
         38 . A computer program product for decomposing functions having computer code stored in a tangible storage medium that when read and executed by a computer causes the following steps to be performed in a computer system:
 creating a first function, a second function, and a third function;   creating a first identity object with a first associated identifier for the first function, a second identity object with an a second associated identifier for the second function, and a third identity object with a third associated identifier for the third function, wherein each identity object has a separately evolving information set in the computer system;   joining in a membership object the first identity object, the second identity object, and the third function, wherein the first identity object is a membership provider, the second identity object is a membership recipient, and the third function is a membership target, so that the second identity object is a member of the third function,   creating a fourth identity object with an associated fourth identifier that derives from the second identity object, so that the third function is decomposable into a collection of multiple member functions through the creation of additional membership object, accomplishing decomposition of the membership target function through the creation of new membership objects, wherein the newly derived identity object resulting from the new membership is a member function of the membership target function, so that new member functions generate new membership objects, creating an expanding program structure and a collaborative means for interpreting the functional structure of a computer program wherein all of the member functions participate in the interpretation, performing interpretation dynamically at system runtime;   creating separately evolving information sets for the identity objects associated with any of the member functions;   providing immediate access to the member functions the information set of the membership target so that the a member function immediately access and operates on the information set of the membership target;   wherein the member functions are distributable within a single system, throughout a multi-node system, or throughout a distributed graph database system on one or a plurality of machines so that the work of the function may also be distributed; and   applying specific access rights controlling how each of the multiple member functions accesses or operates on the information set of the membership target so that the membership target makes accessible its complete information set or a subset of its information set to its member functions, and so that different subsets of information made be made accessible to each member function.   
     
     
         39 . The computer program product of  claim 38 , wherein a function is any agent internal or external to a system that is capable of any one of the following: providing one or more inputs, consuming one or more inputs, generating one or more outputs, submitting one or more requests, or operating in a system. 
     
     
         40 . The computer program product of  claim 39 , wherein a function is a user, project, task, group, computation, or network. 
     
     
         41 . The computer program product of  claim 38 , wherein an identity object is a persona that specifies at least one of an access provider, access recipient, and access point, and access rights. 
     
     
         42 . The computer program product of  claim 38 , wherein in the providing immediate access step wherein the member function immediately accesses and operates on the information set of the membership target includes accessing, reading, writing, modifying, evolving, extending, and deleting. 
     
     
         43 . The computer program product of  claim 38 , wherein the member functions are ordered so that the member functions are executable in a particular order. 
     
     
         44 . The computer program product of  claim 38 , wherein any one of the multiple member functions may itself be decomposed into a collection of member functions so that the work of the function can be further subdivided. 
     
     
         45 . The computer program product of  claim 38 , wherein information added to the information set for the membership target information immediately flows its member functions. 
     
     
         46 . The computer program product of  claim 38 , wherein the membership of any of the multiple member functions is modified or deleted independently of all other member functions so that the collection of member functions can be expanded or contracted as needed. 
     
     
         47 . The computer program product of  claim 38 , wherein the structure of a program as expressed by member functions dynamically changes at runtime and adapts to changing requirements through membership. 
     
     
         48 . The computer program product of  claim 38 , wherein membership recipients and derived identity objects that license the membership recipients are functions that interpret the membership target, the interpreters configured to further decompose the work of the membership target into at least one additional member function so that membership propagates a self-generating and dynamically expanding functional system through the creation of additional functions by the interpreters of the membership target function. 
     
     
         49 . The computer program product of  claim 38 , wherein the membership target is an outer function and the function that licenses the membership recipient is a first inner function so that the first inner function interprets the outer function and invites at least one new interpreter as second inner functions that through a membership object further interprets the first inner function or the outer function, wherein the inner function is a child function and the outer function is a parent function of the child function. 
     
     
         50 . (canceled)

Join the waitlist — get patent alerts

Track US2017011226A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.