US2019372981A1PendingUtilityA1
Methods and resources for creating permissions
Est. expiryJan 21, 2035(~8.5 yrs left)· nominal 20-yr term from priority
Inventors:Remy PottierHugo John Martin VincentAmyas Edward Wykes PhillipsChristopher Mark PaolaMilosch Meriac
H04L 63/0823H04L 63/10H04L 63/104G06F 21/51H04L 63/101
54
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method of creating, at a permissions management resource, access permissions relating to a subject device for at least one data processing device, the method comprising: obtaining, at the permissions management resource, input data; generating, at the permissions management resource, at least one permission relating to accessing the subject device in response to the input data; transmitting, from the permissions management resource to the subject device and/or the at least one processing device, a communication comprising the at least one permission.
Claims
exact text as granted — not AI-modified1 . A method of creating, at a permissions management resource, access permissions for a plurality of subject devices, the method comprising:
obtaining, at the permissions management resource, input data to cause the permissions management resource to generate at least one access permission; generating, at the permissions management resource, the at least one access permission in response to the input data; transmitting, from the permissions management resource to one or more of the plurality of subject devices or the data processing device, a communication comprising the at least one access permission to enable each of the one or more subject devices or the data processing device to perform an operation specified in the at least one access permission.
2 . The method according to claim 1 , wherein the input data comprises; a rule/policy defined by an authorized party; a device attribute of the at least one data processing device; a device attribute of the subject device, and/or contextual information.
3 . The method according to claim 1 , wherein the input data comprises classification data relating to the subject device.
4 . The method according to claim 3 , the method further comprising:
generating, at the permissions management resource, a communication comprising a request for at least one device attribute associated with the group; transmitting the communication comprising the request to a remote directory service; receiving, at the permissions management resource from the remote directory service, the device attribute relating associated with the group.
5 . The method according to claim 1 , wherein generating at least one permission in response to the input data comprises:
automatically generating the at least one permission at the permissions management resource.
6 . The method according to claim 5 , the method further comprising:
transmitting, from the permissions management resource, a permission proposal communication to an authorized party, wherein the permission proposal communication comprises data relating to the automatically created at least one permission.
7 . The method according to claim 1 , wherein:
transmitting the communication comprising the at least one permission comprises transmitting the communication indirectly to the subject device via at least one data processing device.
8 . The method according to claim 7 , wherein the access permission further comprises a credential associated with the at least one data processing device.
9 . The method according to claim 8 , wherein the credential associated with the data processing device comprises a first cryptographic key, wherein the first cryptographic key is associated with the at least one data processing device.
10 . The method according to claim 9 , wherein the first cryptographic key comprises a public key of the at least one data processing device.
11 . The method according to claim 10 , wherein the certificate further comprises a credential associated with an authorized party.
12 . The method according to claim 11 , wherein the credential associated with the authorized party comprises a second cryptographic key, wherein the second cryptographic key is associated with the authorized party.
13 . The method according to claim 12 , wherein the second cryptographic key comprises a private key of the authorized party.
14 . The method according to claim 1 , the method further comprising:
generating, at the permissions management resource, a blacklist of permissions; transmitting, from the permissions management resource, a communication comprising the blacklist of permissions to the subject device.
15 - 20 . (canceled)
21 . The method according to claim 1 , wherein transmitting the blacklist of permissions to the subject device comprises:
transmitting the blacklist of permissions to the subject device directly or indirectly.
22 . The method according to claim 1 , further comprising:
receiving, at the permissions management resource, further input data; generating, at the permissions management resource, at least one further access permission in response to the further input data; and transmitting, from the permissions management resource to one or more of the plurality of subject devices or the further data processing device, a communication comprising the at least one further access permission to enable each of the one or more subject devices or the further data processing device perform an operation specified in the at least one further access permission.
23 . A permissions management resource for creating access permissions for a plurality of subject devices, the permissions management resource comprising:
a permission creation engine to generate access permissions based on input data to cause the permissions management resource to generate at least one access permission; and an identity management engine configured to manage the access permissions generated at the permission creation engine and to communicate the access permissions to one or more of the plurality of subject devices to enable each of the one or more subject devices to perform an operation specified in the at least one access permission.
24 . The permissions management resource according to claim 23 , wherein the permission creation engine is configured to automatically generate the permissions based on the input data.
25 . A first data processing device for setting permissions at a permissions management resource, the data processing device comprising:
communications circuitry to communicate with the permissions management resource; the data processing device to:
receive, from a second data processing device, a request to access a subject device;
transmit, to the permissions management resource, input data to cause the permissions management resource to generate at least one access permission for the subject device in response to the input data;
receive, from the permissions management resource, the at least one access permission;
transmit, to the data processing device or the subject device, the at least one access permission to enable the data processing device or subject device to perform an operation specified in the at least one access permission.Join the waitlist — get patent alerts
Track US2019372981A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.