Authentication of api-based endpoints
US-2016080355-A1 · Mar 17, 2016 · US
US9699218B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-9699218-B1 |
| Application number | US-201615284099-A |
| Country | US |
| Kind code | B1 |
| Filing date | Oct 3, 2016 |
| Priority date | Oct 3, 2016 |
| Publication date | Jul 4, 2017 |
| Grant date | Jul 4, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method and system for improving deployment of a security compliance framework is provided. The method includes deploying a data store that includes an authoritative source of information comprising configuration and operational management requirements associated with IT devices. A component comprising an interface for an authoritative source configured to provide authentication and authorization for access to servers of the IT devices is deployed and configured to enable authentication and privilege management for access to deployed and configured authoritative source components. An API interface and compliance framework management components are deployed and configured and message transfer agent API endpoint components of the compliance framework are identified. In response, operation of the compliance framework is enabled with respect to the data store, the authoritative source components, the API interface, the compliance framework management components, and the API endpoint components.
Opening claim text (preview).
What is claimed is: 1. A security compliance framework deployment improvement method comprising: deploying, by a processor of a compliance framework, a data store comprising an authoritative source of information comprising configuration and operational management requirements associated with Information Technology (IT) devices; deploying, by said processor, a component comprising an interface for an authoritative source configured to provide authentication and authorization for access to servers of said IT devices; configuring, by said processor, said component for enabling authentication and privilege management for access to authoritative source components comprising said IT devices; deploying, by said processor, said authoritative source components; configuring, by said processor, said authoritative source components for logging security events to a source component data store; deploying and configuring, by said processor, an Application Programming Interface (API) interface; deploying and configuring, by said processor, compliance framework management components; identifying, by said processor, message transfer agent API endpoint components of said compliance framework; and enabling, by said processor, operation of said compliance framework with respect to said data store, said authoritative source components, said API interface, said compliance framework management components, and said API endpoint components. 2. The method of claim 1 , wherein said deploying and configuring said API interface comprises: deploying API components of said API interface with respect to said IT devices, wherein said IT devices comprise managed IT devices; and configuring said API interface to write copies of API requests to said data store. 3. The method of claim 2 , wherein said API components comprise a gateway based router configuration for allowing only approved requests to communicate with tools of said compliance framework. 4. The method of claim 1 , wherein said compliance framework management components comprise user interface components, and wherein said deploying and configuring said compliance framework management components comprises: associating said user interface components with execution keys and associated tokens of said API interface; and configuring via said user interface components, said authoritative source components with respect to specified permission for interaction with said content framework. 5. The method of claim 1 , further comprising: deploying, by said processor, management dashboard components comprising an architectural configuration associated with said IT devices; and configuring, by said processor, specified permission for interaction with said content framework for a hardware/software tool for use with said API interface. 6. The method of claim 1 , further comprising: deploying, by said processor, reporting engine components comprising an architectural configuration associated with said IT devices; and authenticating, by said processor, specified permission for interaction with said content framework for a hardware/software tool for use with said API interface. 7. The method of claim 1 , wherein said API endpoint components are associated with a message transfer agent, and wherein said method further comprises: determining, by said processor, a task completion time for each request associated with said message transfer agent. 8. The method of claim 1 , further comprising: enabling, by said processor, a content framework password for a hardware/software tool for use with said content framework, said content framework password unknown by a user of said content framework. 9. The method of claim 1 , further comprising: aligning, by said processor, a logging configuration of a hardware/software tool with requirements of said content framework. 10. The method of claim 1 , further comprising: configuring, by said processor, said data store such that said data store is only configured to accept write requests from pre-identified hardware sources of said compliance framework. 11. The method of claim 1 , wherein said configuring said authoritative source components further comprises: initializing first credentials for allowing application programming interface (API) servers to interact with compliance framework components of said compliance framework; and initializing second credentials for allowing said compliance framework to interact with said compliance framework components, and accepting default profiles comprising authorization permission. 12. The method of claim 1 , further comprising: providing at least one support service for at least one of creating, integrating, hosting, maintaining, and deploying computer-readable code in the hardware device, said code being executed by the computer processor to implement: said deploying said data store, said deploying said component, said configuring said component, said deploying said authoritative source components, said configuring said authoritative source components, said deploying and configuring said API interface, said deploying and configuring said compliance framework management components, said identifying, and said enabling. 13. A computer program product, comprising a computer readable hardware storage device storing a computer readable program code, said computer readable program code comprising an algorithm that when executed by a processor of a compliance framework implements a security compliance framework deployment improvement method, said method comprising: deploying, by said processor, a data store comprising an authoritative source of information comprising configuration and operational management requirements associated with Information Technology (IT) devices; deploying, by said processor, a component comprising an interface for an authoritative source configured to provide authentication and authorization for access to servers of said IT devices; configuring, by said processor, said component for enabling authentication and privilege management for access to authoritative source components comprising said IT devices; deploying, by said processor, said authoritative source components; configuring, by said processor, said authoritative source components for logging security events to a source component data store; deploying and configuring, by said processor, an Application Programming Interface (API) interface; deploying and configuring, by said processor, compliance framework management components; identifying, by said processor, message transfer agent API endpoint components of said compliance framework; and enabling, by said processor, operation of said compliance framework with respect to said data store, said authoritative source components, said API interface, said compliance framework management components, and said API endpoint components. 14. The computer program product of claim 13 , wherein said deploying and configuring said API interface comprises: deploying API components of said API interface with respect to said IT devices, wherein said IT devices comprise managed IT devices; and configuring said API interface to write copies of API requests to said data store. 15. A compliance framework comprising a processor coupled to a computer-readable memory unit, said memory unit comprising instructions that when executed by the processor implements a security compliance framework deployment improvement method comprising: deploying, by said processor, a data store comprising an authoritative source of information comprising configuration and operational management requirements
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
for controlling access to devices or network resources · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.