Client reputation driven role-based access control
US-2018077172-A1 · Mar 15, 2018 · US
US10375077B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-10375077-B1 |
| Application number | US-201615235900-A |
| Country | US |
| Kind code | B1 |
| Filing date | Aug 12, 2016 |
| Priority date | Aug 12, 2016 |
| Publication date | Aug 6, 2019 |
| Grant date | Aug 6, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The disclosed computer-implemented method for mediating information requests may include (1) detecting, at the information-managing device, a request for the information-managing device to provide at least one element of personal information to a requesting device that is within physical proximity of the information-managing device, (2) evaluating, based at least in part on an attribute of the request, whether the request for the element of personal information is appropriate, and (3) performing a security action that responds to the request in a manner that is commensurate to the appropriateness of the request for the element of personal information. Various other methods, systems, and computer-readable media are also disclosed.
Opening claim text (preview).
What is claimed is: 1. A computer-implemented method for mediating information requests, at least a portion of the method being performed by an information-managing device comprising at least one processor, the method comprising: detecting, at the information-managing device, a request for the information-managing device to provide a plurality of elements of personal information to a requesting device that is within physical proximity of the information-managing device; identifying at least one attribute of the request that describes a context in which the information-managing device detected the request, wherein the at least one attribute comprises a device type of the requesting device; evaluating each requested element of personal information in the plurality of elements of personal information, based at least in part on determining whether the requested element of personal information matches the context in which the information-managing device detected the request, for whether the request for the requested element of personal information is an appropriate request for the requested element of personal information; and preventing the information-managing device from providing elements of personal information to requesting devices that requested the elements of personal information in an inappropriate context by performing, at the information-managing device, a security action that responds to the request in a manner that is commensurate to the appropriateness of the request for the element of personal information wherein the security action comprises: in response to determining that a first portion of the request represents an inappropriate request for a first element of personal information in the plurality of elements of personal information, preventing the information-managing device at least from providing the first element of personal information to the requesting device; and in response to determining that an additional portion of the request represents an appropriate request for an additional element of personal information in the plurality of elements of personal information, providing the additional element of personal information to the requesting device. 2. The method of claim 1 , wherein preventing the information-managing device from providing the element of personal information comprises providing a partial response to the requesting device. 3. The method of claim 1 , wherein the security action further comprises at least one of: notifying a user of the information-managing device of the request; providing a security vendor with a report that contains details about the request; and generating a log entry that describes the request. 4. The method of claim 1 , wherein evaluating whether the request for the plurality of elements of personal information is appropriate comprises determining whether the request exceeds user-privacy preferences specified by a user of the information-managing device. 5. The method of claim 1 , wherein evaluating whether the request for the plurality of elements of personal information is appropriate comprises determining whether the requesting device is listed on: a whitelist that identifies approved requesting devices; or a blacklist that identifies disapproved requesting devices. 6. The method of claim 1 , wherein the attribute of the request further comprises at least one of: a time of day when the request was received; the physical location of the requesting device; a manufacturer of the requesting device; a unique identifier associated with the requesting device; a reputation score associated with the requesting device; a third-party verification certificate, included within the request, that digitally verifies the identity of the requesting device by a third party; and at least one characteristic of the element of personal information specified in the request. 7. The method of claim 6 , wherein the reputation score is calculated based on at least one of: prior requests issued by the requesting device; and prior requests issued by other requesting devices. 8. The method of claim 6 , wherein the reputation score is calculated by at least one of: a third-party security vendor; and the information-managing device. 9. The method of claim 1 , further comprising, prior to responding to the request, providing a user of the information-managing device with a security challenge that verifies the identity of the user. 10. The method of claim 1 , wherein the information-managing device comprises at least one of: a mobile device; a smart phone; and a smart badge. 11. A system for mediating information requests, the system comprising: a detecting module, stored in memory, that detects, at an information-managing device, a request for the information-managing device to provide a plurality of elements of personal information to a requesting device that is within physical proximity of the information-managing device; an evaluating module, stored in memory, that: identifies at least one attribute of the request that describes a context in which the information-managing device detected the request, wherein the at least one attribute comprises a device type of the requesting device; and evaluates each requested element of personal information in the plurality of elements of personal information, based at least in part on determining whether the requested element of personal information matches the context in which the information-managing device detected the request, for whether the request for the requested element of personal information is an appropriate request for the requested element of personal information; a performing module, stored in memory, that prevents the information-managing device from providing elements of personal information to requesting devices that requested the elements of personal information in an inappropriate context by performing, at the information-managing device, a security action that responds to the request in a manner that is commensurate to the appropriateness of the request for the element of personal information, wherein the security action comprises: in response to determining that a first portion of the request represents an inappropriate request for a first element of personal information in the plurality of elements of personal information, preventing the information-managing device at least from providing the first element of personal information to the requesting device; and in response to determining that an additional portion of the request represents an appropriate request for an additional element of personal information in the plurality of elements of personal information, providing the additional element of personal information to the requesting device; and at least one physical processor configured to execute the detecting module, the evaluating module, and the performing module. 12. The system of claim 11 , wherein the performing module prevents the information-managing device from providing the element of personal information by providing a partial response to the requesting device. 13. The system of claim 11 , wherein the security action further comprises at least one of: notifying a user of the information-managing device of the request; providing a security vendor with a report that contains details about the request; and generating a log entry that describes the request. 14. The system of claim 11 , wherein the evaluating module evaluates whether the request for the plurality of elements of personal information is appropriate by determining whether the request exceeds user-privacy preferences specifi
Protecting personal data, e.g. for financial or medical purposes · CPC title
Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems · CPC title
wherein the identity of one or more communicating identities is hidden (cryptographic mechanisms or cryptographic arrangements for anonymous credentials or for identity based cryptographic systems H04L9/00) · CPC title
Access control lists [ACL] · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.