Hybrid role mining
    2.
    发明授权
    Hybrid role mining 失效
    混合角色挖掘

    公开(公告)号:US08635689B2

    公开(公告)日:2014-01-21

    申请号:US13283371

    申请日:2011-10-27

    IPC分类号: H04L29/06 G06F21/00

    CPC分类号: G06F21/6218

    摘要: An embodiment of the invention is directed to a data processing system having a plurality of users, a portion of which were previously assigned permissions respectively corresponding to system resources. The embodiment includes acquiring data from a first data source, containing information pertaining to the portion of users and their permissions, and further includes acquiring data from a second data source, containing information pertaining to attributes of each user of the plurality. A set of permissions is determined for a given role, from both first and second data sources. First and second criteria are determined for assigning users to the given role, from information in the first and second data sources, respectively. A particular user is selected for admission to the given role only if the particular user is in compliance with both the first criterion and second criterion.

    摘要翻译: 本发明的实施例涉及一种数据处理系统,其具有多个用户,其一部分先前被分配对应于系统资源的许可。 该实施例包括从第一数据源获取包含与用户部分及其许可有关的信息的数据,并且还包括从第二数据源获取包含与多个用户的属性有关的信息的数据。 对于给定的角色,从第一和第二数据源确定一组权限。 确定从第一和第二数据源中的信息将用户分配给给定角色的第一和第二标准。 仅当特定用户符合第一准则和第二标准时才选择特定用户才能进入给定角色。

    EVALUATING DEPLOYMENT READINESS IN DELIVERY CENTERS THROUGH COLLABORATIVE REQUIREMENTS GATHERING
    3.
    发明申请
    EVALUATING DEPLOYMENT READINESS IN DELIVERY CENTERS THROUGH COLLABORATIVE REQUIREMENTS GATHERING 审中-公开
    通过合作要求评估交付中心的部署准确性

    公开(公告)号:US20130311220A1

    公开(公告)日:2013-11-21

    申请号:US13472986

    申请日:2012-05-18

    IPC分类号: G06Q10/06

    CPC分类号: G06Q10/06

    摘要: A method and data processing system for determining deployment readiness of a service is disclosed. A computer identifies tasks that must be performed to address requirements associated with categories of complexity for deploying the service in one or more locations. The computer assigns the identified tasks to experts based on skill and availability of the experts. The computer verifies whether the assigned tasks have been completed. The computer then provides an indication that the service is ready to be deployed in one or more locations responsive to the verification that the tasks have been completed.

    摘要翻译: 公开了一种用于确定服务的部署准备状态的方法和数据处理系统。 计算机识别必须执行的任务以解决与在一个或多个位置部署服务的复杂性类别相关的需求。 计算机根据专家的技能和可用性将所识别的任务分配给专家。 计算机验证分配的任务是否已完成。 然后,计算机提供指示该服务准备好部署在一个或多个位置中,以响应于验证任务已经完成。

    Service compliance enforcement using user activity monitoring and work request verification
    6.
    发明授权
    Service compliance enforcement using user activity monitoring and work request verification 有权
    使用用户活动监视和工作请求验证的服务合规执行

    公开(公告)号:US08826403B2

    公开(公告)日:2014-09-02

    申请号:US13364157

    申请日:2012-02-01

    IPC分类号: G06F17/30

    CPC分类号: G06F21/552 H04L63/10

    摘要: Auditing system logs of a remote client device is provided. Login session information entered at a workstation device accessing the remote client device to perform an activity associated with a work request is received. An access token is generated based on the login session information and information associated with the work request on the remote client device. The access token is compared with an audit log report of the remote client device that includes the activity associated with the work request performed by the workstation device on the remote client device. It is determined whether information in the access token matches information in the audit log report of the remote client device. In response to determining that the information in the access token does not match the information in the audit log report of the remote client device, an action alert is sent.

    摘要翻译: 提供远程客户端设备的审计系统日志。 接收在访问远程客户端设备以执行与工作请求相关联的活动的工作站设备输入的登录会话信息。 基于登录会话信息和与远程客户端设备上的工作请求相关联的信息生成访问令牌。 将访问令牌与远程客户端设备的审核日志报告进行比较,其中包括与远程客户端设备上的工作站设备执行的工作请求相关联的活动。 确定访问令牌中的信息是否匹配远程客户端设备的审核日志报告中的信息。 响应于确定访问令牌中的信息与远程客户端设备的审计日志报告中的信息不匹配,则发送动作警报。

    SYSTEM AND METHOD FOR HYBRID ROLE MINING
    7.
    发明申请
    SYSTEM AND METHOD FOR HYBRID ROLE MINING 失效
    混合动力采矿的系统与方法

    公开(公告)号:US20130111583A1

    公开(公告)日:2013-05-02

    申请号:US13283371

    申请日:2011-10-27

    IPC分类号: G06F21/00

    CPC分类号: G06F21/6218

    摘要: An embodiment of the invention is directed to a data processing system having a plurality of users, a portion of which were previously assigned permissions respectively corresponding to system resources. The embodiment includes acquiring data from a first data source, containing information pertaining to the portion of users and their permissions, and further includes acquiring data from a second data source, containing information pertaining to attributes of each user of the plurality. A set of permissions is determined for a given role, from both first and second data sources. First and second criteria are determined for assigning users to the given role, from information in the first and second data sources, respectively. A particular user is selected for admission to the given role only if the particular user is in compliance with both the first criterion and second criterion.

    摘要翻译: 本发明的实施例涉及一种数据处理系统,其具有多个用户,其一部分先前被分配对应于系统资源的许可。 该实施例包括从第一数据源获取包含与用户部分及其许可有关的信息的数据,并且还包括从第二数据源获取包含与多个用户的属性有关的信息的数据。 对于给定的角色,从第一和第二数据源确定一组权限。 确定从第一和第二数据源中的信息将用户分配给给定角色的第一和第二标准。 仅当特定用户符合第一准则和第二标准时才选择特定用户才能进入给定角色。

    Methods and Apparatus for Role-Based Shared Access Control to a Protected System Using Reusable User Identifiers
    8.
    发明申请
    Methods and Apparatus for Role-Based Shared Access Control to a Protected System Using Reusable User Identifiers 审中-公开
    使用可重用的用户标识符对受保护系统进行基于角色的共享访问控制的方法和设备

    公开(公告)号:US20110247059A1

    公开(公告)日:2011-10-06

    申请号:US12751461

    申请日:2010-03-31

    IPC分类号: H04L9/32 G06F21/00

    CPC分类号: G06F21/62 G06F21/31

    摘要: Methods and apparatus are provided for role-based shared access control to a protected system using reusable user identifiers while maintaining individual accountability. Role-based access control is provided for a protected system by receiving a request from an end user to access a given protected system; determining a role of the end user for the access to the given protected system; receiving a privileged reusable user identifier and password for the given protected system and role; and providing the privileged reusable user identifier and password to the given protected system on behalf of the end user. Role-based access control is also provided for a protected system by receiving a request to verify an end user requesting access to a given protected system; determining a role of the end user for the access to the given protected system; and providing a privileged reusable user identifier and password for the given protected system and role. A status of the privileged reusable user identifier and password can optionally be maintained. One or more events associated with the privileged reusable user identifier and password can be logged and investigated.

    摘要翻译: 提供了方法和装置,用于基于角色的共享访问控制到使用可重用的用户标识符的受保护系统,同时保持个人的责任。 通过接收来自最终用户访问给定受保护系统的请求,为受保护的系统提供基于角色的访问控制; 确定最终用户对于给定的受保护系统的访问的作用; 为给定的受保护的系统和角色接收特权的可重复使用的用户标识符和密码; 以及代表最终用户向给定的受保护系统提供特权的可重复使用的用户标识符和密码。 还通过接收用于验证请求访问给定受保护系统的最终用户的请求来为受保护的系统提供基于角色的访问控制; 确定最终用户对于给定的受保护系统的访问的作用; 并为给定的受保护系统和角色提供特权可重用的用户标识符和密码。 可以可选地维护特权可重用用户标识符和密码的状态。 可以记录和调查与特权的可重用用户标识符和密码相关联的一个或多个事件。