Invention Grant
- Patent Title: Evaluation of effective access permissions in identity and access management (IAM) systems
-
Application No.: US17333469Application Date: 2021-05-28
-
Publication No.: US12155666B2Publication Date: 2024-11-26
- Inventor: James Simonetti , Britton Lee , Joseph Chen , John Valin , Anika Gera , Nicholas Mirallegro , Jessica Feinstein , Nicholas Kotakis
- Applicant: Capital One Services, LLC
- Applicant Address: US VA McLean
- Assignee: Capital One Services, LLC
- Current Assignee: Capital One Services, LLC
- Current Assignee Address: US VA McLean
- Agency: Sterne, Kessler, Goldstein & Fox P.L.L.C.
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
Disclosed herein are system, method, and computer program product embodiments for generating a list of deny policy statements associated with an allow policy statement with respect to the effective access permissions for a principal in an identity and access management system. The operations can include identifying a first policy statement that specifies members of a first identity set including the principal are allowed to access a first system resource set. The operations further include identifying a second policy statement specifying that members of a second identity set are denied access to a second system resource set. Moreover, the operations include determining that the second policy statement overlaps with the first policy statement with respect to the effective access permissions for the principal, and placing the second policy statement into the list of deny policy statements associated with an allow policy statement.
Public/Granted literature
- US20220385668A1 EVALUATION OF EFFECTIVE ACCESS PERMISSIONS IN IDENTITY AND ACCESS MANAGEMENT (IAM) SYSTEMS Public/Granted day:2022-12-01
Information query