Invention Grant
- Patent Title: Policy-driven approach to managing privileged/shared identity in an enterprise
-
Application No.: US13411112Application Date: 2012-03-02
-
Publication No.: US09529993B2Publication Date: 2016-12-27
- Inventor: Kaushal Kiran Kapadia , Gaurav Gupta , Rohit Jaiswal , Gaurang Sudhakar Tapase , Sachin Sanjay Gujar
- Applicant: Kaushal Kiran Kapadia , Gaurav Gupta , Rohit Jaiswal , Gaurang Sudhakar Tapase , Sachin Sanjay Gujar
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Gail H. Zarick; David H. Judson
- Main IPC: G06F21/30
- IPC: G06F21/30 ; G06F21/40 ; G06F21/33 ; H04L29/06

Abstract:
Access to a privileged account is managed by first requiring authentication of a user logging into the account and then performing a policy evaluation to determine whether the identified user is allowed to log in using the privileged identity. Preferably, the authentication is a two factor authentication. The policy evaluation preferably enforces a policy, such as a role-based access control, and a context-based access control, a combination of such access controls, or the like. Thus, according to this approach, the entity is provided access to the privileged account if the user's identity is verified and a policy is met. In the alternative, the entity is denied access to the privileged account if either the authentication fails, or (assuming authentication does not fail) policy criteria for the user is not met.
Public/Granted literature
- US20130232541A1 Policy-driven approach to managing privileged/shared identity in an enterprise Public/Granted day:2013-09-05
Information query