US2011252483A1PendingUtilityA1
Reputation-Based Authorization Decisions
Est. expiryDec 8, 2026(~0.4 yrs left)· nominal 20-yr term from priority
G06F 15/00G06Q 10/06G06F 21/6218G06F 21/00H04L 63/102
47
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
This document describes tools capable of receiving reputation metadata effective to enable better decision making about whether or not to authorize operations. The tools may build a reputation value from this reputation metadata and, based on this value and an authorization rule, better decide whether or not to authorize an operation requested by some program, application, or other actor.
Claims
exact text as granted — not AI-modified1 . One or more computer-readable media having computer-readable instructions therein that, when executed by a computing device, cause the computing device to perform acts comprising:
receiving a first reputation value from a first reputation service provider, the first reputation value indicative of an actor's reputation; and receiving a second reputation value from a second reputation service provider, the first or the second reputation value comprising reputation metadata received from a plurality of human users and indicative of each human user's previous experience with a performance of the actor; aggregating the received first and second reputation values into a single aggregate reputation value; and at least in part due to the single aggregate reputation value, creating an authorization input for use in deciding whether the actor should have permission to perform an operation on an object.
2 . The media of claim 1 , further comprising receiving at least one of: a user identity; an actor type; or a system type.
3 . The media of claim 1 , wherein the authorization input is also created at least in part by the received user identity, actor type, or system type.
4 . The media of claim 1 , further comprising outputting the authorization input to an authorization engine to compare the authorization input to an authorization policy.
5 . The media of claim 4 , wherein the authorization engine is configured to automatically make an authorization decision pertaining to whether the actor should have permission to perform the operation on the object in response to the comparison.
6 . One or more computer-readable media having computer-readable instructions therein that, when executed by a computing device, cause the computing device to perform acts comprising:
gathering reputation metadata from one or more reputation metadata providers, the reputation metadata comprising each reputation metadata provider's estimation of an actor's reputation; and building an aggregate reputation value from the reputation metadata, the aggregate reputation value based at least in part on each estimation and for use in an authorization decision; herein the gathering of the reputation metadata comprises conducting a community vote and at least one of the reputation metadata providers comprises a user in the community.
7 . The media of claim 6 , wherein the authorization decision determines whether or not to allow the actor to run or perform an operation on the computing device.
8 . The media of claim 6 , wherein the gathering of the reputation metadata comprises gathering product review information pertaining to the actor's reputation from one or more computing entities.
9 . The media of claim 6 , wherein at least a portion of the reputation metadata comprises a history of performance of the actor.
10 . The media of claim 6 , wherein the authorization decision is based at least in part on the reputation value, a type of operation requested by the actor, and attributes of an object upon which the actor requests to perform the operation.
11 . A method comprising:
gathering reputation metadata from one or more reputation metadata providers, the reputation metadata comprising each reputation metadata provider's estimation of an actor's reputation; and building an aggregate reputation value from the reputation metadata, the aggregate reputation value based at least in part on each estimation and for use in an authorization decision; herein the gathering of the reputation metadata comprises conducting a community vote and at least one of the reputation metadata providers comprises a user in the community.
12 . The method of claim 11 , wherein the authorization decision determines whether or not to allow the actor to run or perform an operation on the computing device.
13 . The method of claim 11 , wherein the gathering of the reputation metadata comprises gathering product review information pertaining to the actor's reputation from one or more computing entities.
14 . The method of claim 11 , wherein at least a portion of the reputation metadata comprises a history of performance of the actor.
15 . The method of claim 11 , wherein the authorization decision is based at least in part on the reputation value, a type of operation requested by the actor, and attributes of an object upon which the actor requests to perform the operation.
16 . The method of claim 11 , the gathering reputation metadata further comprising:
receiving a first reputation value from a first reputation service provider, the first reputation value indicative of an actor's reputation; and receiving a second reputation value from a second reputation service provider, the first or the second reputation value comprising reputation metadata received from a plurality of human users and indicative of each human user's previous experience with a performance of the actor.
17 . The method of claim 11 , further comprising aggregating the received first and second reputation values into a single aggregate reputation value; and
at least in part due to the single aggregate reputation value, creating an authorization input for use in deciding whether the actor should have permission to perform an operation on an object.
18 . The method of claim 11 , further comprising receiving at least one of: a user identity; an actor type; or a system type, wherein an authorization input is created at least in part by the received user identity, actor type, or system type.
19 . The method of claim 11 , further comprising outputting an authorization input to an authorization engine to compare the authorization input to an authorization policy.
20 . The media of claim 19 , wherein the authorization engine is configured to automatically make an authorization decision pertaining to whether the actor should have permission to perform the operation on the object in response to the comparison.Join the waitlist — get patent alerts
Track US2011252483A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.