Generalized policy server
First Claim
1. A method for controlling access to information in a network, the method comprising:
- maintaining a local copy of one or more policies in a memory of a local access device, the one or more policies limiting access to information in a local area network associated with the local access device, and wherein a change in the local copy is propagated to one or more other policy databases in a global network by a policy manager server in communication with the local access device;
receiving a request from a user, the request received by the local access device, the request concerning access to information in the local area network;
executing instructions stored in memory of the local access device, wherein execution of the instructions by a processor;
consults the local copy of the one or more policies, wherein the local copy includes any changes made at the one or more other policy databases in the global network,determines that the user is authorized or unauthorized to access the information based on at least the local copy of the one or more policies, andcontrols access to information in the local area network based on the determination that the user is authorized or unauthorized.
28 Assignments
0 Petitions
Accused Products
Abstract
A scalable access filter that is used together with others like it in a virtual private network to control access by users at clients in the network to information resources provided by servers in the network. Each access filter use a local copy of an access control database to determine whether an access request made by a user. Changes made by administrators in the local copies are propagated to all of the other local copies. Each user belongs to one or more user groups and each information resource belongs to one or more information sets. Access is permitted or denied according to of access policies which define access in terms of the user groups and information sets.
-
Citations
25 Claims
-
1. A method for controlling access to information in a network, the method comprising:
-
maintaining a local copy of one or more policies in a memory of a local access device, the one or more policies limiting access to information in a local area network associated with the local access device, and wherein a change in the local copy is propagated to one or more other policy databases in a global network by a policy manager server in communication with the local access device; receiving a request from a user, the request received by the local access device, the request concerning access to information in the local area network; executing instructions stored in memory of the local access device, wherein execution of the instructions by a processor; consults the local copy of the one or more policies, wherein the local copy includes any changes made at the one or more other policy databases in the global network, determines that the user is authorized or unauthorized to access the information based on at least the local copy of the one or more policies, and controls access to information in the local area network based on the determination that the user is authorized or unauthorized. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14)
-
-
15. A system for controlling access to information in a network, the system comprising:
-
a local server in a local area network that provides authorized users access to information in the network; a local policy database that stores a local copy of one or more policies limiting access to the information at the local server; a policy server that propagates changes in the local copy to one or more other policy databases in a global network; and a local access filter stored in memory and executable by a processor to; consult the local copy of one or more policies in response to a request from a user, the request concerning access to information in the local server, wherein the local copy includes any changes made at the one or more other policy databases in the global network, determine that a user is authorized or unauthorized to receive access to information from the local server based on at least the local copy of the one or more policies, and control access to the information in the local server based on the determination that the user is authorized or unauthorized. - View Dependent Claims (16, 17, 18, 19, 20, 21, 22, 23)
-
-
24. A Non-transistory computer-readable storage medium having stored thereupon a program, the program being executable by a processor to perform a method for controlling access to network information, the method comprising:
-
maintaining a local copy of one or more policies, the one or more policies limiting access to information in a local network, wherein a change in the local copy is propagated to one or more other policy databases in a global network; receiving a request from a user, the request concerning access to information in the local network; consulting the local copy of the one or more policies, wherein the local copy includes any changes made at the one or more other policy databases in the global network, determining that the user is authorized or unauthorized to access the information based on at least the local copy of the one or more policies; and controlling access to the information in the local network based on the determination that the user is authorized or unauthorized. - View Dependent Claims (25)
-
Specification