Digital asset protection policy using dynamic network attributes

US2017237747A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2017237747-A1
Application numberUS-201615387123-A
CountryUS
Kind codeA1
Filing dateDec 21, 2016
Priority dateFeb 15, 2016
Publication dateAug 17, 2017
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Various systems and methods for determining whether to allow or continue to allow access to a protected data asset are disclosed herein. For example, one method involves receiving a request to access a protected data asset, wherein the request is received from a first user device; determining whether to grant access to the protected data asset, wherein the determining comprises evaluating one or more criteria associated with the first user device, and the criteria comprises first information associated with a first policy constraint; and in response to a determination that access to the protected data asset is to be granted, granting access to the protected data asset.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: receiving a request to access a protected data asset, wherein the request is received from a first user device; determining whether to grant access to the protected data asset, wherein the determining comprises evaluating one or more criteria associated with the first user device, and the criteria comprise first information associated with a first policy constraint; and in response to a determination that access to the protected data asset is to be granted, granting access to the protected data asset. 2 . The method of claim 1 , wherein the first policy constraint comprises first location information, and the first location information indicates a geographic location of the first user device. 3 . The method of claim 2 , wherein the criteria further comprises second information associated with a second policy constraint, the second policy constraint comprises first user group information, and the first user group information indicates a user group associated with a user of the first user device. 4 . The method of claim 1 , wherein the protected data asset is encrypted, and the providing access comprises providing decryption information for the protected data asset. 5 . The method of claim 1 , wherein the access to the protected data asset is limited to the first user device. 6 . The method of claim 1 , wherein the access is limited to a predetermined time period. 7 . The method of claim 1 , further comprising: subsequent to the granting access, receiving updated location information from the first user device, wherein the updated location information indicates that the geographic location of the first user device has changed, and using the updated location information to determine whether to revoke access to the protected data asset. 8 . A system comprising: a microprocessor; and a non-transient computer-readable storage medium, comprising computer instructions executable by the microprocessor, wherein the computer instructions are configured to perform a method comprising the steps of: receiving a request to access a protected data asset, wherein the request is received from a first user device; determining whether to grant access to the protected data asset, wherein the determining comprises evaluating one or more criteria associated with the first user device, and the criteria comprise first information associated with a first policy constraint; and in response to a determination that access to the protected data asset is to be granted, granting access to the protected data asset. 9 . The system of claim 8 , wherein the first policy constraint comprises first location information, and the first location information indicates a geographic location of the first user device. 10 . The system of claim 9 , wherein the criteria further comprises second information associated with a second policy constraint, the second policy constraint comprises first user group information, and the first user group information indicates a user group associated with a user of the first user device. 11 . The system of claim 8 , wherein the protected data asset is encrypted, and the providing access comprises providing decryption information for the protected data asset. 12 . The system of claim 8 , wherein the access to the protected data asset is limited to the first user device. 13 . The system of claim 8 , wherein the access is limited to a predetermined time period. 14 . The system of claim 8 , wherein the method further comprises the steps of: subsequent to the granting access, receiving updated location information from the first user device, wherein the updated location information indicates that the geographic location of the first user device has changed, and using the updated location information to determine whether to revoke access to the protected data asset. 15 . A computer program product, comprising a plurality of instructions stored on a non-transient computer-readable storage medium, wherein the instructions are configured to execute a method comprising the steps of: receiving a request to access a protected data asset, wherein the request is received from a first user device; determining whether to grant access to the protected data asset, wherein the determining comprises evaluating one or more criteria associated with the first user device, and the criteria comprise first information associated with a first policy constraint; and in response to a determination that access to the protected data asset is to be granted, granting access to the protected data asset. 16 . The computer program product of claim 15 , wherein the first policy constraint comprises first location information, and the first location information indicates a geographic location of the first user device. 17 . The computer program product of claim 16 , wherein the criteria further comprises second information associated with a second policy constraint, the second policy constraint comprises first user group information, and the first user group information indicates a user group associated with a user of the first user device. 18 . The computer program product of claim 15 , wherein the protected data asset is encrypted, and the providing access comprises providing decryption information for the protected data asset. 19 . The computer program product of claim 15 , wherein the access to the protected data asset is limited to the first user device, and the access is limited to a predetermined time period. 20 . The computer program product of claim 15 , wherein the method further comprises the steps of: subsequent to the granting access, receiving updated location information from the first user device, wherein the updated location information indicates that the geographic location of the first user device has changed, and using the updated location information to determine whether to revoke access to the protected data asset.

Assignees

Inventors

Classifications

  • to a system of files or objects, e.g. local or distributed file system or database · CPC title

  • H04L63/107Primary

    wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • Providing cryptographic facilities or services · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Access security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2017237747A1 cover?
Various systems and methods for determining whether to allow or continue to allow access to a protected data asset are disclosed herein. For example, one method involves receiving a request to access a protected data asset, wherein the request is received from a first user device; determining whether to grant access to the protected data asset, wherein the determining comprises evaluating one o…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/107. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Aug 17 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).