Transforming policies to enforce control in an information management system

US9703978B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9703978-B2
Application numberUS-201615013337-A
CountryUS
Kind codeB2
Filing dateFeb 2, 2016
Priority dateDec 29, 2005
Publication dateJul 11, 2017
Grant dateJul 11, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In an information management system, policies are deployed to targets and targets can evaluate the policies whether they are connected or disconnected to the system. The policies may be transferred to the target, which may be a device or user. Relevant policies may be transferred while not relevant policies are not. The policies may have policy abstractions.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method of managing information of a network comprising: providing a server handling a first policy language having access to a policy database; providing a first device comprising a decision engine to manage information accessible via the device according to a first set of policies stored on the device, wherein the first set of policies is associated with the first policy language; providing a second device that handles a second policy language; managing a first application program on the second device by a third decision engine, wherein the third decision engine comprises a third policy language; translating a first policy of the policy database into the second policy language; translating the first policy of the policy database into the third policy language; and transferring the first policy in the second policy language to the second device. 2. The method of claim 1 wherein the second and third policy languages are different policy languages. 3. The method of claim 1 wherein the first device comprises a first target profile and the second device comprises a second target profile, different than the first target profile. 4. The method of claim 3 wherein the second target profile comprises a first identifier corresponding to a second application program and a second identifier corresponding to a third application program. 5. The method of claim 3 wherein the translating the first policy of the policy database into the third policy language comprises modifying the first conditional statement of the first policy. 6. The method of claim 1 wherein the translating a first policy of the policy database into the second policy language comprises modifying a first conditional statement of the first policy. 7. The method of claim 1 wherein the policy database comprises a plurality of policies wherein each policy comprises a conditional statement having a policy abstraction and allowing execution of an application operation when the conditional statement is satisfied, and each policy abstraction has a corresponding definition statement stored separately from the policy. 8. The method of claim 1 wherein the second device comprises a firewall. 9. The method of claim 8 wherein operation of the firewall is altered by the first policy. 10. The method of claim 1 wherein the first and second devices are separate devices. 11. The method of claim 1 further comprising: when at a first time the first policy evaluates to Boolean true, allowing the second device access to a first piece of information; and when at a second time the first policy evaluates to Boolean false, denying the second device access to the first piece of information. 12. The method of claim 1 wherein the translating a first policy of the policy database into the second policy language comprises modifying a first policy abstraction of the first policy. 13. The method of claim 12 wherein the translating the first policy of the policy database. 14. A method of managing information of a network comprising: providing a server handling a first policy language having access to a policy database; providing a first device comprising a first decision engine to manage information accessible via the first device according to a first set of policies stored on the device, wherein the first set of policies is associated with the first policy language; providing a second device comprising a first application program installed on the second device and managed by a second decision engine, wherein the second decision engine comprises a second policy language; translating a first policy of the policy database into the second policy language; translating the first policy of the policy database into the third policy language; and transferring the first policy in the second policy language to the second device. 15. The method of claim 14 wherein a second application program is installed on the second device and managed by a third decision engine, and the third decision engine comprises a third policy language.

Assignees

Inventors

Classifications

  • G06Q10/06Primary

    Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling · CPC title

  • Access control lists [ACL] · CPC title

  • Physics · mapped topic

  • to a system of files or objects, e.g. local or distributed file system or database · CPC title

  • Virtual private networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9703978B2 cover?
In an information management system, policies are deployed to targets and targets can evaluate the policies whether they are connected or disconnected to the system. The policies may be transferred to the target, which may be a device or user. Relevant policies may be transferred while not relevant policies are not. The policies may have policy abstractions.
Who is the assignee on this patent?
Nextlabs Inc
What technology area does this patent fall under?
Primary CPC classification G06Q10/06. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 11 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).