Managing elevated rights on a network
First Claim
Patent Images
1. A method comprising:
- associating a task with one or more elevated rights using a task association table stored in a computer'"'"'s memory, wherein the task is associated with a user'"'"'s job responsibility; and
granting an elevated right account to the user, the granting comprising;
basing the elevated right account on a principle of least right; and
constraining the elevated right account to provide the one or more elevated rights necessary to perform only the task associated with the elevated rights, wherein the rights associated with the elevated right account are non-overlapping with basic rights provided in a basic user account, wherein the basic user account comprises a non-elevated user account.
2 Assignments
0 Petitions
Accused Products
Abstract
A method includes associating a task with one or more elevated rights, wherein the task is associated with a user'"'"'s job responsibility and granting an elevated right account to the user based on a principle of least privilege, wherein the elevated right account provides the one or more elevated rights necessary to perform only the task associated with the elevated rights.
118 Citations
12 Claims
-
1. A method comprising:
-
associating a task with one or more elevated rights using a task association table stored in a computer'"'"'s memory, wherein the task is associated with a user'"'"'s job responsibility; and granting an elevated right account to the user, the granting comprising; basing the elevated right account on a principle of least right; and constraining the elevated right account to provide the one or more elevated rights necessary to perform only the task associated with the elevated rights, wherein the rights associated with the elevated right account are non-overlapping with basic rights provided in a basic user account, wherein the basic user account comprises a non-elevated user account. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A system comprising:
-
a memory; a task association table stored on the memory and associating a task with a set of one or more rights required to perform the task; and means for generating an elevated right account enabling an associated user to perform only the task by virtue of the one or more rights, wherein the rights associated with the elevated right account are non-overlapping with basic rights provided in a basic user account, wherein the basic user account comprises a non-elevated user account.
-
Specification