Proximity and behavior-based enterprise security using a mobile device

US9408073B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9408073-B2
Application numberUS-201314024536-A
CountryUS
Kind codeB2
Filing dateSep 11, 2013
Priority dateSep 11, 2013
Publication dateAug 2, 2016
Grant dateAug 2, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method for facilitating configuring software security functionality. An example method includes employing a first computing device to collect information associated with a user of enterprise software, resulting in collected information; and dynamically adjusting one or more security features of enterprise software running on or accessible via a second device based on the collected information. The software running on the second device may include or represent the enterprise software that includes software security functionality. The collected information may include contextual information. An administrator user option facilitates adjusting the one or more rules.

First claim

Opening claim text (preview).

We claim: 1. A method for facilitating configuring software security functionality, the method comprising: employing a first computing device to collect information associated with a user of enterprise software, resulting in collected information, and wherein the collected information includes location information pertaining to a location of the first computing device relative to a second computing device; providing one or more rules that specify adjustments to one or more security features based on the collected information; and adjusting the one or more security features of the enterprise software to be accessed by the user via the second computing device based on the collected information, and wherein the adjusting of the one or more security features is based on the location of the first computing device relative to the second computing device. 2. The method of claim 1 , further including: employing a mobile device to collect the information, wherein the collected information includes collected contextual information; using the contextual information with reference to the one or more rules, wherein the one or more rules further map contextual information to security software behaviors and determine one or more adjustments to be made to the security software behaviors in response thereto; and adjusting one or more user access permissions to one or more security features of the enterprise software based on the one or more adjustments. 3. The method of claim 1 , wherein the one or more rules specify how the collected information is used to adjust user permissions to access one or more of software, functionality, and data provided via the enterprise software. 4. The method of claim 1 , further including providing an administrator user option to adjust the one or more rules. 5. The method of claim 1 , wherein the one or more rules enable accessing calendar information to determine when a user is in a meeting, and restricting software access in response thereto. 6. The method of claim 1 , wherein the one or more rules enable determining that a user is commuting, and restricting software access in response thereto. 7. The method of claim 1 , wherein the one or more rules enable determining that a user is in an office that includes the second computing device, and enable software access in response thereto. 8. The method of claim 1 , wherein the one or more rules enable determining that a user is within an office building but not accessing the second computing device, and partially limiting software access in response thereto. 9. The method of claim 1 , wherein the first computing device includes a mobile device, and wherein the second computing device includes a desktop computer in communication with the mobile device. 10. The method of claim 1 , wherein the first computing device includes a mobile device, and wherein the second computing device includes a desktop computer in communication with the mobile device, and wherein the collected information includes location information pertaining to a location of the mobile device relative to the desktop computer. 11. The method of claim 1 , wherein the first computing device includes a mobile device, and wherein the second computing device includes a desktop computer in communication with the mobile device, and wherein the method further comprises: employing the mobile device to collect the information, wherein the collected information includes collected contextual information; using the contextual information with reference to the one or more rules, wherein the one or more rules further map contextual information to security software behaviors and determine one or more adjustments to be made to the security software behaviors in response thereto; adjusting one or more user access permissions to the one or more security features of the enterprise software based on the one or more determined adjustments; providing an administrator user option to adjust the one or more rules; wherein the one or more rules further specify how the collected information is used to adjust user permissions to access one or more of software, functionality, and data provided via the enterprise software, wherein the one or more rules enable accessing calendar information to determine when a user is in a meeting, and restricting software access in response thereto, wherein the one or more rules further enable determining that a user is commuting, and restricting software access in response thereto; wherein the one or more rules further enable determining that a user is in an office that includes the second computing device, and enable software access in response thereto, wherein the one or more rules enable determining that a user is within an office building but not accessing the second computing device, and partially limiting software access in response thereto, wherein the collected information includes location information pertaining to a location of the mobile device relative to the desktop computer; wherein the collected information includes velocity information pertaining to a velocity of the mobile device, and wherein the method further comprises employing the velocity information to determine when the user is commuting, and restricting the user's access to one or more features of the enterprise software on the second computing device in response thereto, wherein the collected information further includes calendar information pertaining to the user of the first computing device, and wherein the calendar information includes information pertaining to an itinerary or schedule associated with the user, wherein the collected information further includes usage history information pertaining to how the user has previously used software included in an enterprise computing environment, wherein the collected information further includes information pertaining to a task that a user is actively working on, and wherein the collected information further includes timing information pertaining to how much time has passed since a user has interacted with the enterprise software whose access is subject to the one or more security features; and employing the calendar information to facilitate determining when a user is in a meeting and restricting access to the one or more features of the enterprise software in response thereto, wherein the collected information includes user location information as determined by location information provided to a server via a mobile device employed by the user, and wherein the method further comprises selectively adjusting the one or more security features to enable a user to access all software features for which the user has permission to access when the user location is within a predetermined range of the desktop computer. 12. The method of claim 1 , wherein the collected information includes velocity information pertaining to a velocity of a mobile device, and wherein the method further comprises employing the velocity information to determine when a user is commuting, and restricting user's access to one or more features of the enterprise software on the second computing device in response thereto. 13. The method of claim 1 , wherein the collected information includes calendar information pertaining to the user of the first computing device, and wherein the calendar information includes information pertaining to an itinerary or schedule associated with the user. 14. The method of claim 13 , further including employing the calendar information to facilitate determining when a user is in a meeting and restricting access to one or more features of the enterprise software in response thereto.

Assignees

Inventors

Classifications

  • H04W12/06Primary

    Authentication · CPC title

  • H04L63/105Primary

    Multiple levels of security · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • Location-based management or tracking services · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9408073B2 cover?
A system and method for facilitating configuring software security functionality. An example method includes employing a first computing device to collect information associated with a user of enterprise software, resulting in collected information; and dynamically adjusting one or more security features of enterprise software running on or accessible via a second device based on the collected …
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 02 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).