Context-dependent transactional management for separation of duties

US9799003B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9799003-B2
Application numberUS-201213556711-A
CountryUS
Kind codeB2
Filing dateJul 24, 2012
Priority dateJul 2, 2012
Publication dateOct 24, 2017
Grant dateOct 24, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Context-dependent transactional management of services within a cloud environment for an organization using business rules includes generating a partitioned graph representing the organization and the business rule, where the business rules include one or more separation of duties requirements. Upon receiving an access request from an end user of the cloud service, a determination is made if the access request to the cloud service violates any of the one or more separation of duties requirements. Based on determining that the access request to the cloud service does not violate any of the one or more separation of duties requirements, transaction with the cloud service is granted to the end user. Based on determining that the access request to the cloud service violates one of the one or more separation of duties requirements, access to the cloud service is denied to the end user.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer implemented method for providing context-dependent transactional management within a cloud environment, the method comprising: receiving a request to create a business rule for controlling a transaction within a cloud computing environment for an organization; providing an instance of the cloud computing environment for provisioning the business rule by generating a partitioned graph representing the organization and the business rule, wherein the business rule includes one or more separation of duties requirements, and wherein the partitioned graph representing the organization comprises: a plurality of nodes that each represent a resource of the organization; and a plurality of linkages that each connect two of the plurality of nodes, wherein each of the plurality of linkages includes a threshold confidence level, which is a minimum confidence level required such that request access between the plurality of nodes does not violate the one or more separation of duties requirements; determining, by a processor, a use context associated with the partitioned graph based on the one or more separation of duties requirements; responsive to a blocking action, determining one or more confidence levels associated with the blocking action related to the use context, wherein the blocking action is indicative that the use context violates one of the one or more separation of duties requirements, wherein determining includes comparing the one or more confidence levels associated with the blocking action to the threshold confidence level associated with one or more of the plurality of linkages that correspond to the use context; creating a context-dependent firewall based on the one or more confidence levels associated with the blocking action; monitoring one or more new blocking actions; determining one or more confidence levels associated with the one or more new blocking actions related to the use context, wherein the one or more new blocking actions are indicative that the use context violates one of the one or more separation of duties requirements, wherein determining includes comparing the one or more confidence levels associated with the one or more new blocking actions to the threshold confidence level associated with the one or more of the plurality of linkages that correspond to the use context; and responsive to the determination of one or more confidence levels associated with the one or more new blocking actions related to the use context, updating the context-dependent firewall. 2. The method of claim 1 , wherein the resources of the organization comprise: people; applications; and data. 3. The method of claim 1 , wherein the access request includes an identification of one or more of the plurality of nodes associated with the end user of the cloud service. 4. The method of claim 1 , wherein based on determining that the access request to the cloud service violates one of the one or more separation of duties requirements, performing a confidence-increasing action. 5. The method of claim 4 , wherein the confidence-increasing action includes at least one of: requesting additional information regarding the access request; and increasing a monitoring level during transaction with the cloud service. 6. A computer implemented method for providing a context-dependent firewall for an organization, the method comprising: creating a partitioned graph representing the organization and one or more business rules, wherein each of the business rules includes one or more separation of duties requirements and wherein the partitioned graph representing the organization comprises: a plurality of nodes that each represent a resource of the organization; and a plurality of linkages that each connect two of the plurality of nodes, wherein each of the plurality of linkages includes a threshold confidence level, which is a minimum confidence level required such that request access between the plurality of nodes does not violate the one or more separation of duties requirements; determining, by a processor, a use context associated with the partitioned graph based on the one or more separation of duties requirements; responsive to a blocking action, determining one or more confidence levels associated with the blocking action related to the use context, wherein the blocking action is indicative that the use context violates one of the one or more separation of duties requirements, wherein determining includes comparing the one or more confidence levels associated with the blocking action to the threshold confidence level associated with one or more of the plurality of linkages that correspond to the use context; creating a context-dependent firewall based on the one or more confidence levels associated with the blocking action; monitoring one or more new blocking actions; determining one or more confidence levels associated with the one or more new blocking actions related to the use context, wherein the one or more new blocking actions are indicative that the use context violates one of the one or more separation of duties requirements, wherein determining includes comparing the one or more confidence levels associated with the one or more new blocking actions to the threshold confidence level associated with the one or more of the plurality linkages that correspond to the use context; and responsive to the determination of one or more confidence levels associated with the one or more new blocking actions related to the use context, updating the context-dependent firewall. 7. The method of claim 6 , wherein the use context includes an identification of one or more of the plurality of nodes and the one or more plurality of linkages associated with the business rule. 8. The method of claim 6 , wherein the method further comprises: monitoring an activity of a user of the context-dependent firewall for a period of time; based on the activity of the user during the period of time, modifying the one or more confidence levels associated with the blocking action; determining if the modification to the one or more confidence levels will require the context-dependent firewall to be changed; and based on determining that the context-dependent firewall is required to be changed, modifying the context-dependent firewall. 9. The method of claim 8 , wherein determining if the modification to the one or more confidence levels will require the context-dependent firewall to be changed includes: comparing one or more modified confidence levels to the threshold confidence level; based on determining that the one or more modified confidence levels has been increased to exceed the threshold confidence level, indicating that the context-dependent firewall is required to be changed; and based on determining that that the one or more modified confidence levels has been decreased below the threshold confidence level, indicating that the context-dependent firewall is required to be changed. 10. The method of claim 6 , wherein the method further comprises: receiving an access request from an end user; determining that the access request violates the one or more separation of duties requirements; requesting an additional information regarding the requested access from the end user; computing a new linkage of the partitioned graph based on the access request; and based on the additional information regarding the requested access received from the end user, provisioning the new linkage in the partitioned graph and modifying the context-dependent firewall. 11. The method of claim 10 , wherein computing the new linkage comprises: determining a context associated with the

Assignees

Inventors

Classifications

  • Entity profiles · CPC title

  • G06Q10/10Primary

    Office automation; Time management · CPC title

  • for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9799003B2 cover?
Context-dependent transactional management of services within a cloud environment for an organization using business rules includes generating a partitioned graph representing the organization and the business rule, where the business rules include one or more separation of duties requirements. Upon receiving an access request from an end user of the cloud service, a determination is made if th…
Who is the assignee on this patent?
Doran James R, Kozloski James R, Pickover Clifford A, and 2 more
What technology area does this patent fall under?
Primary CPC classification G06Q10/10. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 24 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).