US2011252483A1PendingUtilityA1

Reputation-Based Authorization Decisions

Assignee: MICROSOFT CORPPriority: Dec 8, 2006Filed: Jun 21, 2011Published: Oct 13, 2011
Est. expiryDec 8, 2026(~0.4 yrs left)· nominal 20-yr term from priority
G06F 15/00G06Q 10/06G06F 21/6218G06F 21/00H04L 63/102
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

This document describes tools capable of receiving reputation metadata effective to enable better decision making about whether or not to authorize operations. The tools may build a reputation value from this reputation metadata and, based on this value and an authorization rule, better decide whether or not to authorize an operation requested by some program, application, or other actor.

Claims

exact text as granted — not AI-modified
1 . One or more computer-readable media having computer-readable instructions therein that, when executed by a computing device, cause the computing device to perform acts comprising:
 receiving a first reputation value from a first reputation service provider, the first reputation value indicative of an actor's reputation; and   receiving a second reputation value from a second reputation service provider, the first or the second reputation value comprising reputation metadata received from a plurality of human users and indicative of each human user's previous experience with a performance of the actor;   aggregating the received first and second reputation values into a single aggregate reputation value; and   at least in part due to the single aggregate reputation value, creating an authorization input for use in deciding whether the actor should have permission to perform an operation on an object.   
     
     
         2 . The media of  claim 1 , further comprising receiving at least one of: a user identity; an actor type; or a system type. 
     
     
         3 . The media of  claim 1 , wherein the authorization input is also created at least in part by the received user identity, actor type, or system type. 
     
     
         4 . The media of  claim 1 , further comprising outputting the authorization input to an authorization engine to compare the authorization input to an authorization policy. 
     
     
         5 . The media of  claim 4 , wherein the authorization engine is configured to automatically make an authorization decision pertaining to whether the actor should have permission to perform the operation on the object in response to the comparison. 
     
     
         6 . One or more computer-readable media having computer-readable instructions therein that, when executed by a computing device, cause the computing device to perform acts comprising:
 gathering reputation metadata from one or more reputation metadata providers, the reputation metadata comprising each reputation metadata provider's estimation of an actor's reputation; and   building an aggregate reputation value from the reputation metadata, the aggregate reputation value based at least in part on each estimation and for use in an authorization decision;   herein the gathering of the reputation metadata comprises conducting a community vote and at least one of the reputation metadata providers comprises a user in the community.   
     
     
         7 . The media of  claim 6 , wherein the authorization decision determines whether or not to allow the actor to run or perform an operation on the computing device. 
     
     
         8 . The media of  claim 6 , wherein the gathering of the reputation metadata comprises gathering product review information pertaining to the actor's reputation from one or more computing entities. 
     
     
         9 . The media of  claim 6 , wherein at least a portion of the reputation metadata comprises a history of performance of the actor. 
     
     
         10 . The media of  claim 6 , wherein the authorization decision is based at least in part on the reputation value, a type of operation requested by the actor, and attributes of an object upon which the actor requests to perform the operation. 
     
     
         11 . A method comprising:
 gathering reputation metadata from one or more reputation metadata providers, the reputation metadata comprising each reputation metadata provider's estimation of an actor's reputation; and   building an aggregate reputation value from the reputation metadata, the aggregate reputation value based at least in part on each estimation and for use in an authorization decision;   herein the gathering of the reputation metadata comprises conducting a community vote and at least one of the reputation metadata providers comprises a user in the community.   
     
     
         12 . The method of  claim 11 , wherein the authorization decision determines whether or not to allow the actor to run or perform an operation on the computing device. 
     
     
         13 . The method of  claim 11 , wherein the gathering of the reputation metadata comprises gathering product review information pertaining to the actor's reputation from one or more computing entities. 
     
     
         14 . The method of  claim 11 , wherein at least a portion of the reputation metadata comprises a history of performance of the actor. 
     
     
         15 . The method of  claim 11 , wherein the authorization decision is based at least in part on the reputation value, a type of operation requested by the actor, and attributes of an object upon which the actor requests to perform the operation. 
     
     
         16 . The method of  claim 11 , the gathering reputation metadata further comprising:
 receiving a first reputation value from a first reputation service provider, the first reputation value indicative of an actor's reputation; and   receiving a second reputation value from a second reputation service provider, the first or the second reputation value comprising reputation metadata received from a plurality of human users and indicative of each human user's previous experience with a performance of the actor.   
     
     
         17 . The method of  claim 11 , further comprising aggregating the received first and second reputation values into a single aggregate reputation value; and
 at least in part due to the single aggregate reputation value, creating an authorization input for use in deciding whether the actor should have permission to perform an operation on an object.   
     
     
         18 . The method of  claim 11 , further comprising receiving at least one of: a user identity; an actor type; or a system type, wherein an authorization input is created at least in part by the received user identity, actor type, or system type. 
     
     
         19 . The method of  claim 11 , further comprising outputting an authorization input to an authorization engine to compare the authorization input to an authorization policy. 
     
     
         20 . The media of  claim 19 , wherein the authorization engine is configured to automatically make an authorization decision pertaining to whether the actor should have permission to perform the operation on the object in response to the comparison.

Join the waitlist — get patent alerts

Track US2011252483A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.