US2015135258A1PendingUtilityA1

Mechanism for facilitating dynamic context-based access control of resources

Individually held — no corporate assignee on recordPriority: Sep 27, 2013Filed: Sep 27, 2013Published: May 14, 2015
Est. expirySep 27, 2033(~7.2 yrs left)· nominal 20-yr term from priority
H04L 63/10H04L 63/0876H04L 63/20G06F 2221/2111G06F 21/6218G06F 21/45
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A mechanism is described for facilitating context-based access control of resources for according to one embodiment. A method of embodiments, as described herein, includes receiving a first request to access a resource of a plurality of resources. The first request may be associated with one or more contexts corresponding to a user placing the first request at a computing device. The method may further include evaluating the one or more contexts. The evaluation of the one or more contexts may include matching the one or more contexts with one or more access policies associated with the requested resource. The method may further include accepting the first request if the one or more contexts satisfy at least one of the access policies.

Claims

exact text as granted — not AI-modified
1 .- 25 . (canceled) 
     
     
         26 . An apparatus comprising:
 reception logic to receive a first request to access a resource of a plurality of resources, wherein the reception logic is further to receive one or more contexts associated with a user placing the first request at a computing device;   evaluation logic of policy decision point to evaluate the one or more contexts, wherein evaluation of the one or more contexts includes matching the one or more contexts with an access policy associated with the requested resource; and   decision/return logic of the policy decision point to accept the first request if the one or more contexts satisfy the access policy.   
     
     
         27 . The apparatus of  claim 26 , wherein accepting the first request comprises providing access to the requested resource, wherein the acceptance is enforced via policy enforcement point of resource manager, and wherein the access to the requested resource is facilitated via resource/policy return logic of the resource manager, wherein accessing the requested resource comprises accessing one or more of data, computing devices, and physical properties. 
     
     
         28 . The apparatus of  claim 26 , wherein the decision/return logic is further to reject the first request if the one or more contexts fail to satisfy the access policy, wherein rejecting the first request comprises denying access to the requested resource, wherein the rejection is enforced via the policy enforcement point. 
     
     
         29 . The apparatus of  claim 28 , wherein the decision/return logic is further to generate, if the first request is rejected, a minimum access policy having a minimum access criteria to access the requested resource. 
     
     
         30 . The apparatus of  claim 27 , wherein the resource/policy return logic to communicate, via communication/compatibility logic, the minimum access policy to the user via the computing device to facilitate a second request to access the resource of the plurality of resources. 
     
     
         31 . The apparatus of  claim 26 , further comprising authentication logic to authenticate one or more of the request, the user, and the computing device, wherein the request is received over a network including a cloud network. 
     
     
         32 . The apparatus of  claim 26 , further comprising policy maintenance and publication logic to maintain a plurality of policies associated with the plurality of resources, wherein the plurality of access policies include the access policy associated with the requested resource. 
     
     
         33 . An apparatus comprising:
 one or more context-aware sensors to collect contexts relating to a user, wherein the contexts are further collected via one or more audio/visual devices;   trusted execution environment logic to authenticate the contexts; and   resource requestor to receive a first request for accessing a resource of a plurality of resources, wherein the request is placed by the user, wherein the resource requestor is further to submit, via communication logic, the first request for retrieval of the requested resource,   wherein the resource requestor is further to associate the authenticated contexts to the first request to facilitate satisfaction of an access policy associated with the requested resource.   
     
     
         34 . The apparatus of  claim 33 , wherein the resource requestor is further to receive a decision package indicating acceptance or rejection of the first request, wherein access to the requested resource is granted if the first request is accepted, and wherein the first request is accepted if the authenticated contexts satisfy the access policy of a plurality of access policies associated with the plurality of resources. 
     
     
         35 . The apparatus of  claim 34  wherein the decision package further includes a minimum access policy if the first request is rejected, wherein the first request is rejected if the authenticated contexts fail to satisfy the access policy, and wherein, if the first request is rejected, the resource requestor to automatically trigger a second request to access the resource based on the minimum access policy. 
     
     
         36 . A method comprising:
 receiving a first request to access a resource of a plurality of resources, wherein the first request is associated with one or more contexts corresponding to a user placing the first request at a computing device;   evaluating the one or more contexts, wherein evaluation of the one or more contexts includes matching the one or more contexts with an access policy associated with the requested resource; and   accepting the first request if the one or more contexts satisfy the access policy.   
     
     
         37 . The method of  claim 36 , wherein accepting the first request comprises providing access to the requested resource, wherein accessing the requested resource comprises accessing one or more of data, computing devices, and physical properties. 
     
     
         38 . The method of  claim 37 , wherein the acceptance is indicated via a decision package, wherein access to the requested resource is granted if the first request is accepted. 
     
     
         39 . The method of  claim 36 , further comprising rejecting the first request if the one or more contexts fail to satisfy the access policy, wherein rejecting the first request comprises denying access to the requested resource and generating a minimum access policy, the minimum access policy having a minimum access criteria to access the requested resource. 
     
     
         40 . The method of  claim 39 , wherein the rejection is indicated via the decision package, wherein access to the requested resource is denied if the first request is rejected, and wherein the decision package further includes the minimum access policy having the minimum access criteria to automatically trigger a second request to access the resource based on the minimum access policy. 
     
     
         41 . The method of  claim 36 , further comprising communicating the minimum access policy to the user via the computing device for facilitating the second request to access the resource of the plurality of resources. 
     
     
         42 . The method of  claim 36 , further comprising authenticating one or more of the request, the user, and the computing device, wherein the request is received over a network including a cloud network. 
     
     
         43 . The method of  claim 36 , further comprising maintaining a plurality of policies associated with the plurality of resources, wherein the plurality of access policies include the access policy associated with the requested resource. 
     
     
         44 . At least one machine-readable medium comprising a plurality of instructions that in response to being executed on a computing device, causes the computing device to carry out one or more operations comprising:
 receiving a first request to access a resource of a plurality of resources, wherein the first request is associated with one or more contexts corresponding to a user placing the first request at a computing device;   evaluating the one or more contexts, wherein evaluation of the one or more contexts includes matching the one or more contexts with an access policy associated with the requested resource; and   accepting the first request if the one or more contexts satisfy the access policy.   
     
     
         45 . The machine-readable medium of  claim 44 , wherein accepting the first request comprises providing access to the requested resource, wherein accessing the requested resource comprises accessing one or more of data, computing devices, and physical properties. 
     
     
         46 . The machine-readable medium of  claim 45 , wherein the acceptance is indicated via a decision package, wherein access to the requested resource is granted if the first request is accepted. 
     
     
         47 . The machine-readable medium of  claim 44 , wherein the one or more operations further comprise rejecting the first request if the one or more contexts fail to satisfy the access policy, wherein rejecting the first request comprises denying access to the requested resource and generating a minimum access policy, the minimum access policy having a minimum access criteria to access the requested resource. 
     
     
         48 . The machine-readable medium of  claim 47 , wherein the rejection is indicated via the decision package, wherein access to the requested resource is denied if the first request is rejected, and wherein the decision package further includes the minimum access policy having the minimum access criteria to automatically trigger a second request to access the resource based on the minimum access policy. 
     
     
         49 . The machine-readable medium of  claim 44 , wherein the one or more operations further comprise communicating the minimum access policy to the user via the computing device for facilitating a second request to access the resource of the plurality of resources. 
     
     
         50 . The machine-readable medium of  claim 44 , wherein the one or more operations further comprise:
 authenticating one or more of the request, the user, and the computing device, wherein the request is received over a network including a cloud network; and   maintaining a plurality of policies associated with the plurality of resources, wherein the plurality of access policies include the access policy associated with the requested resource.

Join the waitlist — get patent alerts

Track US2015135258A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.