Query interface to policy server
Abstract
A scalable access filter that is used together with others like it in a virtual private network to control access by users at clients in the network to information resources provided by servers in the network. Each access filter uses a local copy of an access control data base to determine whether an access request is made by a user. Each user belongs to one or more user groups and each information resource belongs to one or more information sets. Access is permitted or denied according to access policies which define access in terms of the user groups and information sets. The first access filter in the path performs the access check, encrypts and authenticates the request; the other access filters in the path do not repeat the access check. The interface used by applications to determine whether a user has access to an entity is now an SQL entity. The policy server assembles the information needed for the response to the query from various information sources, including source external to the policy server.
Claims
exact text as granted — not AI-modified1 . A method for managing user access to computing resources, the method comprising:
receiving a first access policy, wherein the first access policy identifies that resources associated with a first set of information can be accessed by a first set of one or more users assigned to a first user group; receiving a second access policy, wherein the second access policy identifies that resources associated with a second set of information can be accessed by a second set of one or more uses assigned to a second user group; receiving an indication of a hierarchical relationship between the first user group and the second user group; receiving a request to access a resource associated with the first set of resources is received from a user of the second user group; identifying that the second user group is hierarchically related to the first user group according to the received hierarchical relationship between the second user group and the first user group; and allowing access to the resource based on the received hierarchical relationship.
2 . The method of claim 1 , wherein information relating to at least one of the first access policy and the second access policy were input by an administrator over a user interface.
3 . The method of claim 1 , further comprising:
receiving a request from the user of the second user group to access data that the first set of users are allowed to access according to a third access policy; identifying that the user of the second user group is not authorized to access the requested data that the first set of users are allowed to access according to the third access policy; and denying the user of the second user group access to the requested data based on the user of the second user group not being authorized to access the requested data according to the third access policy.
4 . The method of claim 1 , further comprising:
receiving an access request from a computing device associated with a third user; identifying that the computer associated with the third user includes a client user identification software program that is executable to generate a first prompt requesting that the third user provide information that identifies the third user; and identifying that additional identification information is required from the third user to associate the third user with one of a plurality of user groups.
5 . The method of claim 4 , wherein the client user identification software program is executed to:
generate a second prompt requesting that the third user provide the additional identification information; receive the additional identification information from the computer associated with the third user, identify that the received additional information indicates that the third user belongs to the first user group, and grant access to information associated with the access request received from the computing device associated with the third user according to the first access policy, the access grant based on the identification that the third user belongs to the first user group.
6 . The method of claim 4 , wherein information relating to the first prompt are displayed via a pop-up window on a display at the computer associated with the third user.
7 . A non-transitory computer readable storage medium having embodied thereon a program executable by a processor to implement a method for managing user access to computing resources, the method comprising:
receiving a first access policy, wherein the first access policy identifies that resources associated with a first set of information can be accessed by a first set of one or more users assigned to a first user group; receiving a second access policy, wherein the second access policy identifies that resources associated with a second set of information can be accessed by a second set of one or more uses assigned to a second user group; receiving an indication of a hierarchical relationship between the first user group and the second user group; receiving a request to access a resource associated with the first set of resources is received from a user of the second user group; identifying that the second user group is hierarchically related to the first user group according to the received hierarchical relationship between the second user group and the first user group; and allowing access to the resource based on the received hierarchical relationship.
8 . The non-transitory computer readable storage medium of claim 7 , wherein information relating to at least one of the first access policy and the second access policy were input by an administrator over a user interface.
9 . The non-transitory computer readable storage medium of claim 7 , wherein the program further comprises instructions executable to:
receive a request from the user of the second user group to access data that the first set of users are allowed to access according to a third access policy; identify that the user of the second user group is not authorized to access the requested data that the first set of users are allowed to access according to the third access policy; and deny the user of the second user group access to the requested data based on the user of the second user group not being authorized to access the requested data according to the third access policy.
10 . The non-transitory computer readable storage medium of claim 7 , wherein the program further comprises instructions executable to:
receive an access request from computing device associated with a third user; identify that the computer associated with the third user includes a client user identification software program that is executable to generate a first prompt requesting that the third user provide information that identifies the third user; and identify that additional identification information is required from the third user to associate the third user with one of a plurality of user groups.
11 . The non-transitory computer readable storage medium of claim 10 , wherein the client user identification software program is executed to:
generate a second prompt requesting that the third user provide the additional identification information; receive the additional identification information from the computer associated with the third user, identify that the received additional information indicates that the third user belongs to the first user group, and grant access to information associated with the access request received from the computing device associated with the third user according to the first access policy, the access grant based on the identification that the third user belongs to the first user group.
12 . The non-transitory computer readable storage medium of claim 10 , wherein information relating to the first prompt are displayed via a pop-up window on a display at the computer associated with the third user.
13 . An apparatus for managing user access to computing resources, the apparatus comprising:
one or more network interfaces that:
receive a first access policy, wherein the first access policy identifies that resources associated with a first set of information can be accessed by a first set of one or more users assigned to a first user group, receive a second access policy, wherein the second access policy identifies that resources associated with a second set of information can be accessed by a second set of one or more uses assigned to a second user group,
receive an indication of a hierarchical relationship between the first user group and the second user group, and
receive a request to access a resource associated with the first set of resources is received from a user of the second user group via a network interface of the one or more network interfaces;
a memory; and a processor that executes instructions stored in the memory, wherein execution of the instructions by the processor:
identifies that the second user group is hierarchically related to the first user group according to the received hierarchical relationship between the second user group and the first user group, and
allows access to the resource based on the received hierarchical relationship.
14 . The apparatus of claim 1 , wherein information relating to at least one of the first access policy and the second access policy were input by an administrator over a user interface.
15 . The apparatus of claim 13 , wherein the network interfaces receives a request from the user of the second user group to access data that the first set of one or more users are allowed to access according to a third access policy, and wherein the processor executes further instructions to:
identify that the user of the second user group is not authorized to access the requested data that the first set of one or more users are allowed to access according to the third access policy is made, and deny the access request based on the user of the second user group not being authorized to access the requested data according to the third access policy.
16 . The apparatus of claim 13 , wherein the network interfaces receive an access request from a computing device associated with a third user, and wherein the processor executes further instructions to:
identify that the computer associated with the third user includes a client user identification software program that is executable to generate a first prompt requesting that the third user provide information that identifies the third user, and identify that additional identification information is required from the third user to associate the third user with one of a plurality of user groups.
17 . The apparatus of claim 16 , wherein the processor executes further instructions to:
generate a second prompt requesting that the third user provide the additional identification information; receive the additional identification information from the computer associated with the third user, identify that the received additional information indicates that the third user belongs to the first user group, and grant access to information associated with the access request received from the computing device associated with the third user according to the first access policy, the access grant based on the identification that the third user belongs to the first user group.
18 . The apparatus of claim 16 , wherein information relating to the first prompt are displayed via a pop-up window on a display at the computer associated with the third user.
19 . A method for providing access to data, the method comprising:
receiving a request to access data that is associated with a first data sensitivity level of a plurality of data sensitivity levels, wherein the request is from a computing device operated by a user; assigning a first trust level, wherein the first trust level is associated with the computing device that is operated by the user; identifying a second trust level, wherein the second trust level is associated with a first path over which the data associated with the first data sensitivity level can be transmitted; identifying that the first trust level allows the computing device operated by the user to access the data with the first sensitivity level; and identifying that the second trust level requires the data with the first data sensitivity level must be encrypted according to a policy that identifies a minimum encryption level that is associated with the second trust level, wherein the data with the first data sensitivity level is encrypted according to the policy that identifies the minimum encryption level and is transmitted to the computing device operated by the user via the first path.
20 . The method of claim 19 , wherein the path includes a plurality of different computing devices, each of the different computing devices is identified by a name and is assigned with at least one trust level of a plurality of trust levels, and the second trust level corresponds to a minimum trust level of the plurality of trust levels that is associated with at least one of the plurality of different computing devices along the path.Join the waitlist — get patent alerts
Track US2017118221A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.