Method and system for managing identity changes to shared accounts

US9268917B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9268917-B1
Application numberUS-201314014669-A
CountryUS
Kind codeB1
Filing dateAug 30, 2013
Priority dateAug 30, 2013
Publication dateFeb 23, 2016
Grant dateFeb 23, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method includes detecting an identity change instruction. The method also includes identifying a target account associated with the identity change instruction. The method also includes determining whether the target account is checked out. The method also includes passing the identity change instruction to a kernel in response to determining that the target account is checked out. The method also includes blocking the identity change instruction in response to determining that the target account is not checked out.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: detecting, using a processor, an identity change instruction, the identity change instruction instructing a system to change a user's identity from a first identity to a second identity; identifying a target account associated with the identity change instruction; determining, using the processor, whether the target account is checked out; in response to determining that the target account is checked out: passing the identity change instruction from the system to a kernel of an operating system to be executed; and changing the user's identity from the first identity to the second identity; and in response to determining that the target account is not checked out, blocking the identity change instruction. 2. The method of claim 1 , wherein changing the user's identity from the first identity to the second identity comprises passing the identity change instruction to a user interface, the user interface configured to pass the identity change instruction to a kernel. 3. The method of claim 1 , wherein instructing the system to change the user's identity from the first identity to the second identity comprises at least one of: an instruction to switch to the target account, and an instruction to perform an action using one or more privileges of the target account, wherein the target account comprises a shared account. 4. The method of claim 1 , further comprising, in response to determining that the target account is checked out: identifying a user providing the identity change instruction; and determining whether the user checked out the target account, wherein changing the user's identity from the first identity to the second identity comprises passing the identity change instruction to a kernel in response to determining that the user checked out the target account. 5. The method of claim 1 , further comprising, in response to determining that the target account is not checked out: retrieving authentication information; determining whether the user is authorized to access the target account using the authentication information; wherein changing the user's identity from the first identity to the second identity comprises passing the identity change instruction to a kernel in response to determining that the user is authorized to access the target account. 6. The method of claim 1 , further comprising, in response to determining that the target account is not checked out: requesting permission to access the account from an owner of the target account; and receiving the permission to access the target account, wherein changing the user's identity from the first identity to the second identity comprises passing the identity change instruction to a kernel in response to receiving the permission to access the target account. 7. The method of claim 1 , further comprising, in response to determining that the target account is not checked out, sending an alert to an owner of the target account, the alert comprising at least one of: a name corresponding to a user providing the identity change instruction; and a time that the user is providing the identity change instruction. 8. A system comprising: a detecting device configured to detect an identity change instruction, the identity change instruction instructing the system to change a user's identity from a first identity to a second identity; an account identifying device configured to identify a target account associated with the identity change instruction; a first determining device configured to determine whether the target account is checked out; a passing device configured to, in response to determining that the target account is checked out, pass the identity change instruction from the system to a kernel of an operating system to be executed; a changing device configured to, in response to determining that the target account is checked out, change the user's identity from the first identity to the second identity; and a blocking device configured to block the identity change instruction in response to determining that the target account is not checked out. 9. The system according to claim 8 , wherein the passing device is configured to pass the identity change instruction to a user interface, the user interface configured to pass the identity change instruction to the kernel. 10. The system of claim 8 , wherein the identity change instruction comprises at least one of: an instruction to switch to the target account, and an instruction to perform an action using one or more privileges of the target account, wherein the target account comprises a shared account. 11. The system of claim 8 , further comprising: an user identifying device configured to identify a user providing the identity change instruction in response to determining that the target account is checked out; a second determining device configured to determine whether the user checked out the target account; wherein the passing device is configured to pass the identity change instruction to the kernel in response to determining that the user checked out the target account. 12. The system of claim 8 , further comprising: a retrieving device configured to retrieve authentication information in response to determining that the target account is not checked out; a third determining device configured to determine whether the user is authorized to access the target account using the authentication information; wherein the passing device is configured to pass the identity change instruction to the kernel in response to determining that the user is authorized to access the target account. 13. The system of claim 8 , further comprising: a requesting device configured to request permission to access the target account from an owner of the target account in response to determining that the target account is not checked out; and a permission receiving device configured to receive the permission to access the target account, wherein the passing device is configured to pass the identity change instruction to the kernel in response to receiving the permission to access the target account. 14. The system of claim 8 , further comprising: a sending device configured to send an alert to an owner of the target account, the alert comprising at least one of: a name corresponding to a user providing the identity change request; and a time that the user is providing the identity change request. 15. A computer program product comprising: a non-transitory computer readable storage medium having computer readable program code embodied therewith, the computer readable program code comprising: computer readable program code configured to detect an identity change instruction, the identity change instruction instructing a system to change a user's identity from a first identity to a second identity; computer readable program code configured to identify a target account associated with the identity change instruction; computer readable program code configured to determine whether the target account is checked out; computer readable program code configured to, in response to determining that the target account is checked out: pass the identity change instruction from the system to a kernel of an operating system to be executed; and change the user's identity from the first identity to the second identity; and computer readable program code configured to block the identity change instruction in response to determining that the target account is not checked out. 16. The computer program product

Assignees

Inventors

Classifications

  • G06F21/00Primary

    Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity · CPC title

  • Structures or tools for the administration of authentication · CPC title

  • G06F21/31Primary

    User authentication · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9268917B1 cover?
A method includes detecting an identity change instruction. The method also includes identifying a target account associated with the identity change instruction. The method also includes determining whether the target account is checked out. The method also includes passing the identity change instruction to a kernel in response to determining that the target account is checked out. The method…
Who is the assignee on this patent?
Barak Nir, Gross Miron, Jerbi Amir, and 2 more
What technology area does this patent fall under?
Primary CPC classification G06F21/00. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 23 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).