Implicit population of access control lists
Abstract
Communication applications may include lists of users with which a user of the application communicates. If two users of a communications application each include the other user on their user lists, an implicit trust may be established between the users. For example, if user A includes user B in her list and user B includes user A in his list, then it may be determined that each user knows and/or trusts the other user. As a result, a connection or communications pathway may be automatically created between the client devices of the users to facilitate communications between the users based on the implicit trust.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A method comprising:
logging a first client device into a server; logging a second client device into the server; accessing, using the server, a first user list associated with a first user of the first client device; accessing, using the server, a second user list associated with a second user of the second client device, wherein the first user list and the second user list are maintained separately from one another; analyzing, using the server, the accessed first user list to determine whether an identifier of the second user is included in the first user list; analyzing, using the server, the accessed second user list to determine whether an identifier of the first user is included in the second user list; regulating, using the server, a communications pathway between the first client device and the second client device based on both the determination of whether the identifier of the first user is included on the second user list and the determination of whether the identifier of the second user is included on the first user list.
2. The method of claim 1 wherein regulating the communications pathway includes establishing a virtual private network.
3. The method of claim 1 wherein regulating the communications pathway includes establishing a peer-to-peer connection between the first client device and the second client device.
4. The method of claim 1 wherein the first user list and the second user list comprise lists of identities for whom online presence is monitored.
5. The method of claim 1 further comprising receiving, at the server, a request from a first communications program executing on the first client device to establish a communications pathway with a second communications program executing on the second client device, wherein:
analyzing, using the server, the accessed first user list to determine whether the identifier of the second user is included in the first user list comprises analyzing, using the server, the accessed first user list to determine whether the identifier of the second user is included in the first user list in response to receiving the request;
analyzing, using the server, the accessed second user list to determine whether the identifier of the first user is included in the second user list comprises analyzing, using the server, the accessed second user list to determine whether the identifier of the first user is included in the second user list in response to receiving the request; and
regulating the communications pathway comprises establishing the communications pathway between the first communications program and the second communications program.
6. The method of claim 1 further comprising receiving a message from a first communications application executing on the first client device directed to a second communications application executing on the second client device, wherein:
analyzing, using the server, the accessed first user list to determine whether the identifier of the second user is included in the first user list comprises analyzing, using the server, the accessed first user list to determine whether the identifier of the second user is included in the first user list in response to receiving the message;
analyzing, using the server, the accessed second user list to determine whether the identifier of the first user is included in the second user list comprises analyzing, using the server, the accessed second user list to determine whether the identifier of the first user is included in the second user list in response to receiving the message; and
regulating the communications pathway comprises establishing the communications pathway between the first communications program and the second communications program.
7. The method of claim 1 , wherein regulating, using the server, a communications pathway between the first client device and the second client device, comprises automatically establishing a communications pathway between the first client device and the second client device.
8. The method of claim 1 , wherein regulating, using the server, a communications pathway between the first client device and the second client device, comprises sending a shared secret to the first client device and the second device, which enables the first client device and the second client device to authenticate themselves.
9. A system comprising:
a first client device; a second client device; and a server configured to: access a first user list associated with a first user of the first client device; access a second user list associated with a second user of the second client device, wherein the first user list and the second user list are maintained separately from one another; analyze the accessed first user list to determine whether an identifier of the second user is included in the first user list; analyze the accessed second user list to determine whether an identifier of the first user is included in the second user list; and regulate a communications pathway between the first client device and the second client device based on both the determination of whether the identifier of the first user is included on the second user list and the determination of whether the identifier of the second user is included on the first user list.
10. The system of claim 9 wherein, to regulate the communications pathway, the server is configured to establish a virtual private network.
11. The system of claim 9 wherein, to regulate the communications pathway, the server is configured to establish a peer-to-peer connection between the first client device and the second client device.
12. The system of claim 9 wherein the first user list and the second user list comprise lists of identities for whom online presence is monitored.
13. The system of claim 9 wherein:
the server is configured to receive a request from a first communications program executing on the first client device to establish a communications pathway with a second communications program executing on the second client device;
to analyze the accessed first user list to determine whether the identifier of the second user is included in the first user list, the server is configured to analyze the accessed first user list to determine whether the identifier of the second user is included in the first user list in response to receiving the request;
to analyze the accessed second user list to determine whether the identifier of the first user is included in the second user list the server is configured to analyze the accessed second user list to determine whether the identifier of the first user is included in the second user list in response to receiving the request; and
to regulate the communications pathway, the server is configured to establish the communications pathway between the first communications program and the second communications program.
14. The system of claim 9 wherein:
the server is configured to receive a message from a first communications application executing on the first client device directed to a second communications application executing on the second client device;
to analyze the accessed first user list to determine whether the identifier of the second user is included in the first user list, the server is configured to analyze the accessed first user list to determine whether the identifier of the second user is included in the first user list in response to receiving the message;
to analyze the accessed second user list to determine whether the identifier of the first user is included in the second user list, the server is configured to analyze the accessed second user list to determine whether the identifier of the first user is included in the second user list in response to receiving the message; and
to regulate the communications pathway, the server is configured to establish the communications pathway between the first communications program and the second communications program.
15. The system of claim 9 , wherein the server is further configured to automatically establish a communications pathway between the first client device and the second client device.
16. The system of claim 9 , wherein the server is further configured to send a shared secret to the first client device and the second device, which enables the first client device and the second client device to authenticate themselves.
17. A host system comprising:
an interface to receive a communication from a first client device associated with a first user and to transmit a communication to a second client device associated with a second user; storage to store a first user list associated with the first user and to store a second user list associated with the second user; and a host configured to: determine an identifier of the first user and an identifier of the second user; access the first user list associated with the first user of the first client device; access the second user list associated with the second user of the second client device, wherein the first user list and the second user list are maintained separately from one another; analyze the accessed first user list to determine whether an identifier of the second user is included in the first user list; analyze the accessed second user list to determine whether an identifier of the first user is included in the second user list; and regulate a communications pathway between the first client device and the second client device based on both the determination of whether the identifier of the first user is included on the second user list and the determination of whether the identifier of the second user is included on the first user list.
18. The system of claim 17 wherein, to regulate the communications pathway, the host is configured to establish a virtual private network.
19. The system of claim 17 wherein, to regulate the communications pathway, the host is configured to establish a peer-to-peer connection between the first client device and the second client device.
20. The system of claim 17 wherein the first user list and the second user list comprise lists of identities for whom online presence is monitored.
21. The system of claim 17 wherein:
the communication from the first client device is a request received from a first communications program executing on the first client device to establish a communications pathway with a second communications program executing on the second client device;
to analyze the accessed first user list to determine whether the identifier of the second user is included in the first user list, the host is configured to analyze the accessed first user list to determine whether the identifier of the second user is included in the first user list in response to receiving the request;
to analyze the accessed second user list to determine whether the identifier of the first user is included in the second user list, the host is configured to analyze the accessed second user list to determine whether the identifier of the first user is included in the second user list in response to receiving the request; and
to regulate the communications pathway, the host is configured to establish the communications pathway between the first communications program and the second communications program.
22. The system of claim 17 wherein:
the communication from the first client device is a message from a first communications application executing on the first client device directed to a second communications application executing on the second client device;
to analyze the accessed first user list to determine whether the identifier of the second user is included in the first user list, the host is configured to analyze the accessed first user list to determine whether the identifier of the second user is included in the first user list in response to receiving the message;
to analyze the accessed second user list to determine whether the identifier of the first user is included in the second user list the host is configured to analyze the accessed second user list to determine whether the identifier of the first user is included in the second user list in response to receiving the message; and
to regulate the communications pathway, the host is configured to establish the communications pathway between the first communications program and the second communications program.
23. The system of claim 17 , wherein the host is further configured to automatically establish a communications pathway between the first client device and the second client device.
24. The system of claim 17 , wherein the host is further configured to send a shared secret to the first client device and the second device, which enables the first client device and the second client device to authenticate themselves.
25. A method comprising:
establishing a first type of communication between a first user computer and a second user computer by providing a first message display to the first user computer and a second message display to the second user computer, the first type of communication provided in a first protocol comprising a messaging protocol; accessing, by at least one processor, a first user list associated with a first user corresponding to the first user computer; accessing, by the at least one processor, a second user list associated with a second user corresponding to the second user computer, wherein the first user list associated with the first user and the second user list associated with the second user are maintained independently of one another; determining that an identifier of the first user is included within the second user list and that an identifier of the second user is included within the first user list; and establishing a second type of communication between the first user computer and the second user computer based on the determination that the identifier of the first user is included within the second user list and that the identifier of the second user is included within the first user list, the second type of communication provided in a second protocol different from the first protocol.
26. The method of claim 25, wherein establishing the first type of communication between the first user computer and the second user computer comprises establishing an instant messaging session between the first user computer and the second user computer.
27. The method of claim 25, wherein the first user list comprises a portion of users associated with the first user that have been assigned to a first group of users, and wherein the second user list comprises a portion of users associated with the first user that have been assigned to a second group of users.
28. The method of claim 27, wherein the first group of users comprises one or more contacts of the first user, and wherein the second group of users comprises one or more contacts of the second user.
29. The method of claim 25, wherein determining that the identifier of the first user is included within the second user list and that the identifier of the second user is included within the first user list comprises providing an indication of implicit trust between the first user computer associated with the first user and the second user computer associated with the second user.
30. The method of claim 25, further comprising determining whether the first user computer and the second user computer are currently able to communicate using the second type of communication.
31. The method of claim 25, wherein the first type of communication comprises a communication between the first user computer and the second user computer using a first communication application and the second type of communication comprises a communication between the first user computer and the second user computer using a second communication application.
32. The method of claim 31, wherein the first communication application comprises an instant messaging application.
33. The method of claim 25, wherein the second protocol comprises a virtual private network protocol.
34. The method of claim 31, wherein the second communication application comprises a browser application.
35. The method of claim 25, wherein establishing the second type of communication comprises, in response to the determination that the identifier of the first user is included within the second user list and that the identifier of the second user is included within the first user list, establishing, without any user intervention, the second type of communication between the first user computer and the second user computer.
36. The method of claim 25, wherein establishing the second type of communication comprises establishing a virtual private network.
37. The method of claim 25, wherein establishing the second type of communication comprises establishing a peer-to-peer connection between the first user computer associated with the first user and the second user computer associated with the second user.
38. The method of claim 25, further comprising monitoring the first user list and the second user list for online presence corresponding with identifiers associated with other users.
39. The method of claim 25, further comprising:
receiving a message, from the first user computer and directed to the second user computer, via the second type of communication; determining that the second user computer is currently able to communicate with the first user computer via the second type of communication; and wherein establishing the second type of communication between the first user computer and the second user computer is further based on determining that the second user computer is currently able to communicate with the first user computer using the second type of communication.
40. The method of claim 25, further comprising:
receiving a request from the first user computer to establish the second type of communication between the first user computer and the second user computer; determining that the second user computer is currently able to communicate with the first user computer using the second type of communication; and wherein establishing the second type of communication between the first user computer and the second user computer is further based on determining that the second user computer is currently able to communicate with the first user computer using the second type of communication.
41. A method comprising:
establishing a first type of communication between a first user computer and a second user computer by providing a first message display to the first user computer and a second message display to the second user computer, the first type of communication provided in a first protocol comprising a messaging protocol; receiving a request from the first user computer to establish a second type of communication between the first user computer and the second user computer; in response to receiving the request from the first user computer to establish the second type of communication, determining whether an identifier of a first user corresponding to the first user computer is included within a second user list associated with a second user corresponding to the second user computer and an identifier of the second user is included within a first user list associated with the first user, wherein the first user list associated with the first user and the second user list associated with the second user are maintained independently of one another; and establishing the second type of communication between the first user computer and the second user computer based on the determination that the identifier of the first user is included within the second user list and the identifier of the second user is included within the first user list, the second type of communication provided in a second protocol different from the first protocol.
42. The method of claim 41, further comprising
establishing the first type of communication between the first user computer and a third user computer associated with a third user; and preventing the second type of communication between the first user computer and the third user computer based on a determination that the identifier of the first user is not included within a third user list associated with the third user or an identifier of the third user is not included within the first user list.
43. The method of claim 42, further comprising:
determining whether an automatic connection path is enabled for the second type of communication between the first user and the third user; and establishing the second type of communication between the first user computer and the third user computer using the automatic connection path.
44. A system comprising:
at least one processor; and at least one non-transitory computer readable storage medium storing instructions thereon that, when executed by the at least one processor, cause the system to: maintain a first user list associated with a first user and a second user list associated with a second user, wherein the first user list associated with the first user and the second user list associated with the second user are maintained independently of one another; establish a first type of communication between a first user computer of the first user and a second user computer of the second user, the first type of communication provided in a first protocol comprising a messaging protocol; determine that an identifier of the first user is included within the second user list and that an identifier of the second user is included within the first user list; and establish a second type of communication between the first user computer and the second user computer based on the determination that the identifier of the first user is included within the second user list and that the identifier of the second user is included within the first user list, the second type of communication provided in a second protocol different from the first protocol.Join the waitlist — get patent alerts
Track USRE48102E — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.