Enforcing Control Policies in an Information Management System with Two or More Interactive Enforcement Points
    6.
    发明申请
    Enforcing Control Policies in an Information Management System with Two or More Interactive Enforcement Points 审中-公开
    在具有两个或更多互动执行点的信息管理系统中实施控制策略

    公开(公告)号:US20170063935A1

    公开(公告)日:2017-03-02

    申请号:US15352522

    申请日:2016-11-15

    申请人: NextLabs, Inc.

    发明人: Keng Lim

    IPC分类号: H04L29/06

    摘要: A method and apparatus for controlling document access and application usage using centrally managed rules. The rules are stored and manipulated in a central rule database via a rule server. Policy enforcers are installed on client systems and/or on servers and perform document access and application usage control for both direct user document accesses and application usage, and application program document accesses by evaluating the rules sent to the policy enforcer. The rule server decides which rules are required by each policy enforcer. A policy enforcer can also perform obligation and remediation operations as a part of rule evaluation. Policy enforcers on client systems and servers can operate autonomously, evaluating policies that have been received, when communications have been discontinued with the rule server.

    摘要翻译: 一种使用集中管理的规则来控制文档访问和应用程序使用的方法和装置。 规则通过规则服务器存储和操纵在中央规则数据库中。 政策执行者安装在客户端系统和/或服务器上,并通过评估发送给策略执行者的规则,对直接用户文档访问和应用程序使用以及应用程序文档访问执行文档访问和应用程序使用控制。 规则服务器决定每个策略执行者需要哪些规则。 作为规则评估的一部分,政策执行者也可以履行义务和补救行动。 客户端系统和服务器上的策略执行器可以自主运行,评估当通过规则服务器停止通信时已收到的策略。

    APPARATUS AND METHOD FOR ACCESSING WIFI NETWORKS
    7.
    发明申请
    APPARATUS AND METHOD FOR ACCESSING WIFI NETWORKS 有权
    用于接入WIFI网络的装置和方法

    公开(公告)号:US20160021540A1

    公开(公告)日:2016-01-21

    申请号:US14866473

    申请日:2015-09-25

    摘要: A method and apparatus are for automatically accessing a social network account that provides member information about each of a plurality of social network members. The member information about at least one of the social network members, denoted as a particular member, includes a network detection portion and a security portion. The network detection portion is retrieved from the social network for at least the particular member. A detection is made that the wireless device is within range of a secure wireless network associated with the particular member. The detection uses the network detection portion of the particular member as an input. The security portion of the member information of the particular member is retrieved from the social network. The security portion is used to derive access credentials for the secure wireless network. The derived access credentials are used to securely access the secure wireless network.

    摘要翻译: 一种方法和装置用于自动访问提供关于多个社交网络成员中的每一个的成员信息的社交网络帐户。 关于表示为特定成员的至少一个社交网络成员的成员信息包括网络检测部分和安全部分。 对于至少该特定成员,从社交网络检索网络检测部分。 检测到无线设备在与特定成员相关联的安全无线网络的范围内。 检测使用特定成员的网络检测部分作为输入。 从社交网络检索特定成员的成员信息的安全部分。 安全部分用于导出安全无线网络的访问凭证。 导出的访问凭据用于安全地访问安全无线网络。

    APPLICATION SECURITY FRAMEWORK
    8.
    发明申请
    APPLICATION SECURITY FRAMEWORK 有权
    应用安全框架

    公开(公告)号:US20150294092A1

    公开(公告)日:2015-10-15

    申请号:US14751779

    申请日:2015-06-26

    申请人: AbbVie INC.

    摘要: In accordance with the teaching described herein, systems and methods are provided for prodding secure access to a software application on a computing device. The software application may include a security framework having a set of predetermined security requirements. Prior to enabling access to the software application by a user, the computing device may, (i) verify installation of a device security configuration profile on the computing device, wherein the device security configuration profile certifies that the software application includes the set of predetermined security requirements, (ii) receive identifying information from the user via a user interface, (iii) verify the identifying information with an authentication server, and (iv) based on a successful verification of the identifying information, receive and store a security token. Access to the software application on the computing device may be provided for a specified period identified by the security token.

    摘要翻译: 根据本文所述的教导,提供系统和方法用于对计算设备上的软件应用进行安全访问。 软件应用可以包括具有一组预定安全要求的安全框架。 在使用户能够访问软件应用程序之前,计算设备可以(i)验证计算设备上的设备安全配置简档的安装,其中设备安全配置简档证明软件应用程序包括一组预定安全性 要求,(ii)经由用户界面从用户接收识别信息,(iii)使用认证服务器验证识别信息,以及(iv)基于识别信息的成功验证,接收和存储安全令牌。 在计算设备上的软件应用程序的访问可以被提供在由安全令牌标识的指定时间段内。

    Multiplexer for multi-tenant architectures
    9.
    发明授权
    Multiplexer for multi-tenant architectures 有权
    多租户架构的多路复用器

    公开(公告)号:US09065705B2

    公开(公告)日:2015-06-23

    申请号:US13908947

    申请日:2013-06-03

    摘要: A tenant multiplexer in an administrative tenant of a multi-tenant software architecture can call an administrative agent in the administrative tenant and receive, from the administrative agent, an action framework and a trusted connection protocol for accessing each of the plurality of client tenants. The trusted connection protocol can establish, without tenant-specific authentication information, a trusted system connection to an update agent in each of the plurality of client tenants. An action framework can be simultaneously implemented using the update agent of each of at least a subset of the plurality of client tenants under control of the multiplexer via the trusted system connection to begin execution of the software process for the at least the subset of client tenants.

    摘要翻译: 多租户软件架构的管理租户中的租户多路复用器可以呼叫管理租户中的管理代理,并从管理代理接收用于访问多个客户租户中的每一个的动作框架和可信连接协议。 可信连接协议可以在没有租户特定认证信息的情况下建立到所述多个客户端租户中的每一个中的更新代理的可信系统连接。 可以使用经由可信系统连接的多路复用器的控制下的多个客户租户的至少一个子集中的每一个的更新代理来同时实现一个动作框架,以开始至少对客户租户的子集执行软件过程 。