Facilitating separation-of-duties when provisioning access rights in a computing system

US10341385B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10341385-B2
Application numberUS-201615095588-A
CountryUS
Kind codeB2
Filing dateApr 11, 2016
Priority dateDec 20, 2012
Publication dateJul 2, 2019
Grant dateJul 2, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods for managing risk management rules are provided. A risk management rule may be configured at a rule configuration interface are described. The rule configuration interface may include a list of access rights available for selection. Based on input received, one of the access rights may be identified as a base access right and one of the access rights may be identified as a conflicting access right for the risk management rule. The access rights provisioned at the computing system may be monitored to determine whether a user is provisioned with both the base access right and the conflicting access right. If so, a violation review may be created and presented at a violation review interface at which a decision for the violation review is receivable. An exception to the risk management rule may also be configured at an exception configuration interface.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for managing risk management rules comprising: at least one processor; a rule configuration interface used to configure a risk management rule based on user input received, from a first user, at the rule configuration interface, wherein the rule configuration interface comprises a first list of access rights available for selection by the first user, and wherein a first plurality of access rights listed in the first list of access rights comprise at least one of (i) one or more roles, (ii) one or more tasks, or (iii) one or more permissions; a role configuration interface used to configure a role based on user input received, from the first user, at the role configuration interface, wherein the role configuration interface comprises a second list of access rights available for selection by the first user, and wherein a second plurality of access rights listed in the second list of access rights comprise at least one of (i) one or more tasks, or (ii) one or more permissions; and memory storing instructions that, when executed by the at least one processor, cause the system to: facilitate configuration of the risk management rule by at least: displaying the rule configuration interface wherein displaying the rule configuration interface comprises presenting, at a first portion of the rule configuration interface, the first list of access rights; receiving, at the rule configuration interface, input selecting a first access right from the first list of access rights, the first access right selected corresponding to a base access right for the risk management rule, receiving, at the rule configuration interface, input selecting a second access right from the first list of access rights, the second access right selected corresponding to a conflicting access right for the risk management rule, displaying, in the rule configuration interface and in a list of conflicting access rights for the risk management rule, the conflicting access right; facilitate configuration of the role by at least: displaying the role configuration interface wherein displaying the role configuration interface comprises presenting, at a first portion of the role configuration interface, the second list of access rights, receiving, at the role configuration interface, input selecting an access right from the second list of access rights for association with the role, evaluating whether the access right selected for association with the role violates one or more risk management rules, and based on determining that the access right selected for association with the role violates at least one risk management rule, displaying, in the role configuration interface, an indication that the access right selected violates at least one risk management rule; and monitor access rights provisioned at a computing system to determine whether both the base access right and the conflicting access right are provisioned to a second user of the computing system. 2. The system of claim 1 wherein: the instructions, when executed by the at least one processor, further cause the system to: create a violation review associated with the risk management rule responsive to determining that the second user has been provisioned with both the base access right and the conflicting access right. 3. The system of claim 2 further comprising: an exception configuration interface used to configure an exception to the risk management rule based on user input received, from the first user, at the exception configuration interface. 4. The system of claim 3 wherein: the exception configuration interface comprises a list of attribute values available for selection by the first user; and wherein the instructions, when executed by the at least one processor, further cause the system to associate one of the attribute values with the exception based on the user input received. 5. The system of claim 4 wherein: the instructions, when executed by the at least one processor, further cause the system to set an expiration date for the exception based on user input received, from the first user, at the exception configuration interface. 6. The system of claim 3 further comprising: a violation review interface used to receive a review decision for the violation review; wherein the violation review interface comprises a pending violation review list that indicates the violation review and the risk management rule associated with the violation review; and wherein the instructions, when executed at the at least one processor, further cause the system to store, at a data store, the review decision received at the violation review interface. 7. The system of claim 6 wherein: the pending violation review list further indicates an exception associated with the risk management rule and whether the exception applies to the risk management rule. 8. The system of claim 6 wherein: the instructions, when executed by the at least one processor, further cause the system to, responsive to determining that the review decision indicates an approval of violation of the risk management rule: prompt for a justification of the approval of the violation of the risk management rule, and store the justification at the data store with the review decision. 9. The system of claim 3 wherein: the instructions, when executed, further cause the system to: determine whether the exception applies to the risk management rule based on a comparison of an attribute value associated with the exception to a corresponding attribute value of a user associated with the violation review. 10. The system of claim 9 wherein: the instructions, when executed, cause the system to determine whether the exception applies to the risk management rule further based on a comparison of a current date to an expiration date set, based on user input received from the first user at the exception configuration interface, for the exception. 11. A computer-implemented method for managing risk management rules comprising: providing a rule configuration interface used to configure a risk management rule based on user input received, from a first user, at the rule configuration interface, wherein the rule configuration interface comprises a first list of access rights available for selection by the first user, and wherein a first plurality of access rights listed in the first list of access rights comprise at least one of (i) one or more roles, (ii) one or more tasks, or (iii) one or more permissions; providing a role configuration interface used to configure a role based on user input received, from the first user, at the role configuration interface, wherein the role configuration interface comprises a second list of access rights available for selection by the first user, and wherein a second plurality of access rights listed in the second list of access rights comprise at least one of (i) one or more tasks, or (ii) one or more permissions; facilitating configuration of the risk management rule by at least: displaying the rule configuration interface wherein displaying the rule configuration interface comprises presenting, at a first portion of the rule configuration interface, the first list of access rights; receiving, at the rule configuration interface, input selecting a first access right from the first list of access rights, the first access right selected corresponding to a base access right for the risk management rule; receiving, at the configuration interface, input selecting a second access right from the first list of access rights, the second access right selected corresponding to a conflicting access right for the risk management rule;

Assignees

Inventors

Classifications

  • G06F16/283Primary

    Multi-dimensional databases or data warehouses, e.g. MOLAP or ROLAP · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • for controlling access to devices or network resources · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10341385B2 cover?
Systems and methods for managing risk management rules are provided. A risk management rule may be configured at a rule configuration interface are described. The rule configuration interface may include a list of access rights available for selection. Based on input received, one of the access rights may be identified as a base access right and one of the access rights may be identified as a c…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification G06F16/283. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 02 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).