Revised Policy-Based Triggering of Access Control Information
By introducing a policy-based triggering mechanism in the information technology system, the access control information is automatically evaluated and revised, and the problems of high cost, time-consuming and error-prone revision in the existing technology are solved, and efficient and accurate access control information management is achieved.
Patent Information
- Application Number
- CN202080027900.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-06-12
- Filing Date
- 2020-06-08
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2040-06-08
AI Technical Summary
The prior art has high cost, time-consuming and error-prone problems in the revision of access control information in information technology systems, resulting in the risk of useless revisions and delayed revisions.
Through a policy-based triggering mechanism, the control computing system is used to retrieve and evaluate state parameters related to the information technology system, and the trigger indicator is determined to automatically trigger the revision of access control information.
The necessary revisions to access control information are achieved accurately identifying and performing necessary revisions without increasing management costs, reducing the risks of useless revisions and delayed revisions, and improving the guarantees of data security and regulatory compliance.
Smart Images

Figure CN113711216B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information technology. More specifically, the present disclosure relates to the control of access to information technology systems. Background Art
[0002] The background art of the present disclosure is introduced by discussing technologies related to its context. However, even when the discussion involves documents, actions, articles, etc., it does not imply or indicate that the technologies discussed are part of the prior art or common general knowledge in the field related to the present disclosure.
[0003] The control of access to information technology systems is a key issue for their management. Generally speaking, this is related to the process of controlling the activities that can be performed by different entities (e.g., (human) users) on the (protected) resources of an information technology system. The access control process aims to enable the (correct) entity to perform the (correct) activity at the correct time and for the correct reason; this avoids (or at least significantly reduces) the risk that unauthorized entities may perform undesired (and usually dangerous) activities in the information technology system. This is very important for ensuring data security and regulatory compliance. Summary of the Invention
[0004] According to a first aspect of the present invention, there is provided a computer-implemented method, a computer program product, a computer system, and a control computing system for facilitating the control of access by one or more entities to an information technology system. The method includes retrieving, by a control computing system, one or more trigger policies, each trigger policy being based on one or more state parameters related to the information technology system, retrieving, by the control computing system, the state parameters, evaluating, by the control computing system, the trigger policies according to the corresponding state parameters, determining, by the control computing system, a trigger indicator according to the result of the evaluating trigger policies, and outputting; triggering, by the control computing system, an indication of the trigger indicator to trigger a revision of access control information for controlling access to the information technology system according to the trigger indicator.
[0005] A simplified overview of the present disclosure is presented herein to provide a basic understanding of the following; however, the sole purpose of this overview is to introduce some concepts of the present disclosure in a simplified form as a preamble to its more detailed description below, and it is not to be construed as an identification of its key elements or a delineation of its scope.
[0006] Generally speaking, the present disclosure is based on the concept of policy-based triggering for providing a revision of access control information.
[0007] Specifically, the embodiment provides a method for facilitating control of access to an information technology system. One or more trigger policies are evaluated based on one or more state parameters related to the information technology system. Based on the evaluation result of the trigger policy, a revision of access control information for controlling access to the information technology system is triggered.
[0008] On the other hand, a computer program for implementing the method is provided.
[0009] On the other hand, a corresponding computer program product is provided.
[0010] On the other hand, a corresponding control computing system is provided.
[0011] More specifically, one or more aspects of the present disclosure are set forth in the independent claims, and advantageous features are set forth in the dependent claims, where the wording of all claims is incorporated herein verbatim by reference (where any advantageous feature is provided with reference to any specific aspect, which is applied to each other aspect with necessary modifications). BRIEF DESCRIPTION OF THE DRAWINGS
[0012] These and other objects, features and advantages of the present invention will become apparent from the following detailed description of its illustrative embodiments read in conjunction with the accompanying drawings. The various features of the drawings are not to scale, as the illustrations are provided to facilitate understanding of the present invention by those skilled in the art in conjunction with the detailed description. In the drawings:
[0013] Figures 1A to 1D An example of the application of a solution according to an embodiment of the present disclosure is depicted;
[0014] Figure 2 A schematic block diagram of an information technology infrastructure in which a solution according to an embodiment of the present disclosure can be practiced is depicted;
[0015] Figure 3 The main software components that can be used to implement a solution according to an embodiment of the present disclosure are depicted;
[0016] Figures 4A to 4C An activity diagram showing a flow of activities describing the implementation of a solution according to an embodiment of the present disclosure is shown;
[0017] Figure 5 A cloud computing environment according to an embodiment of the present invention is depicted; and
[0018] Figure 6 An abstract model layer according to an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0019] This disclosure provides detailed embodiments of the claimed structures and methods; however, it is to be understood that the disclosed embodiments are merely illustrative of the claimed structures and methods that may be embodied in various forms. The present invention, however, may be embodied in many different forms and should not be construed as limited to the exemplary embodiments set forth herein. In the description, details of well-known features and techniques may be omitted to avoid unnecessarily obscuring the presented embodiments.
[0020] Embodiments of the present invention relate to the field of information technology. More specifically, the present disclosure relates to the control of access to information technology systems.
[0021] The exemplary embodiments described below provide a system, method, and program product to provide, among other things, a revised policy-based triggering of access control information in an information technology system. Accordingly, the present embodiments have the ability to improve the field of computing technology by facilitating the control of access to an information technology system by one or more principals, or users, or systems.
[0022] The access control process is typically implemented by an identity and access management (hereinafter referred to as "IAM") application. Briefly, the IAM application allows the management of digital identities associated with principals (e.g., an account of a user with its password). The IAM application also allows the granting of specific permissions that authorize each principal to perform specific activities in an information technology system (e.g., read / write a file). The IAM application then allows the enforcement of access to the information technology system by the principal according to its permissions (e.g., a principal having a read permission for a file may not update it). Additionally, the IAM application allows the monitoring of access to the information technology system and the compliance of the security policy governing the access control process.
[0023] The access control process may be based on different security models. For example, the most common security model is the role-based access control (hereinafter referred to as "RBAC") model. In this case, one or more roles are defined, each role having one or more permissions (to perform activities in an information technology system). Each principal is assigned one or more roles and then assigned the corresponding permissions. Another promising security model is the attribute-based access control (ABAC) model, also known as policy-based access control (PBAC) or claim-based access control (CBAC). In this case, one or more rules are defined based on one or more attributes, each rule for a permission; each principal is assigned the permissions of the rules satisfied by the corresponding attributes. This facilitates the management of the access control process, especially in large organizations (with thousands of principals and permissions).
[0024] However, access control processes are often subject to dynamic requirements (which change at a relatively high frequency); for example, this may be due to reorganization, acquisition and outsourcing operations, and regulatory modifications. Therefore, the control information used to control access to information technology systems is constantly revised (in an attempt to make it meet actual needs). In particular, where the access control process is based on the RBAC / ABAC model, role / rule mining techniques can be applied to discover typical patterns of subject-to-resource mappings, which are used to change the roles / rules accordingly. In any case, this role / rule mining activity is time consuming; in any case, heavy manual intervention is required. All of the above makes the revision of access control information quite expensive.
[0025] Therefore, revisions to access control information are typically performed only in response to events that are considered to involve significant changes; for example, this could be a surge in the organizational chart, the incorporation of a new company, the spin-off of assets for a business division, the creation of a new strategic region, etc.
[0026] However, it may happen that, although some events appear to be valid reasons for revising the access control information, the results obtained are not worth the cost; vice versa, it may happen that events that appear to be insignificant will require significant changes in the access control information. In any case, even individual minor events that do not involve any significant changes may do so when they occur in succession over a long period of time.
[0027] Therefore, determining the right time for revising access control information is challenging; in any case, it is a completely manual task that is strongly dependent on individual skills, prone to errors and hardly repeatable. Therefore, there is a risk of performing useless revisions of access control information; this adversely affects the management costs of information technology systems. Conversely, there is a risk of delaying useful revisions of access control information; this may expose data security and / or regulatory compliance.
[0028] A simplified summary of the disclosure is presented herein in order to provide a basic understanding; however, its sole purpose is to introduce some concepts of the disclosure in a simplified form as a prelude to its more detailed description below and is not to be construed as an identification of its key elements or a delineation of its scope.
[0029] In general, the present disclosure is based on the concept of providing policy-based triggering of revisions of access control information.
[0030] Specifically, an embodiment provides a method for facilitating the maintenance of access control information for controlling access by one or more principals to one or more resources of an information technology system. One or more trigger policies are evaluated based on one or more policy parameters related to the resources, principals, and / or the access of principals to resources. Based on the evaluation result of the trigger policies, a revision of the access control information including a mining activity for mapping principals to resources is triggered.
[0031] On the other hand, a computer program for implementing the method is provided.
[0032] On the other hand, a corresponding computer program product is provided.
[0033] On the other hand, a corresponding control computing system is provided.
[0034] More specifically, one or more aspects of the present disclosure are set forth in the independent claims, and the advantageous features are set forth in the dependent claims, where the wording of all claims is incorporated herein verbatim by reference (where any advantageous feature is provided with reference to any specific aspect, which is applied to each other aspect with necessary modifications). BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Reference Figures 1A to 1D , shows an example of the application of a solution according to an embodiment of the present disclosure.
[0037] As Figure 1A shown, an access control process is implemented to control access to the information technology system 100. Specifically, activities that can be performed by different principals (e.g., (human) users) on one or more resources of the information technology system 100 are controlled according to corresponding access control information. For example, in the case where the access control process is based on the RBAC model, the access control information indicates the roles having permissions for performing activities and the assignment of roles to principals, and where the access control process is based on the ABAC model, the access control information indicates rules defining the permissions for principals to perform activities when satisfied by corresponding attributes.
[0038] In a solution according to an embodiment of the present disclosure, one or more trigger policies are provided for determining when a revision of the access control information is needed. Each trigger policy is based on one or more policy parameters related to the resources, principals, and / or the access of principals to resources (e.g., the number of new policy parameters among them). Over time, for example, periodically, the trigger policies and their policy parameters are retrieved.
[0039] As Figure 1B shown, the trigger policies are evaluated according to the corresponding policy parameters; for example, each trigger policy is evaluated by determining whether each trigger policy is true or false.
[0040] As Figure 1C shown, a trigger indicator is determined based on an evaluation of a trigger policy; for example, the trigger indicator is a trigger index calculated by weighting trigger policies that are true according to corresponding scores (depending on their effectiveness in triggering a revision of access control information).
[0041] As Figure 1D shown, the trigger indicator (e.g., as displayed) is output to cause a revision of access control information as a response (e.g., when the trigger index exceeds a threshold); in particular, this involves mining activities for mapping a subject to a resource (e.g., role mining for an RBAC model and rule mining for an ABAC model) and a possible update of access control information based on the results of the mining activities.
[0042] The above solution facilitates determining the correct time for revising access control information; for example, it is now possible to ascertain whether a revision of access control information is needed (i.e., whether it is appropriate, useful, or necessary). This result is achieved in a substantially automated manner such that it is highly accurate, reliable, and reproducible. Thus, the risk of performing a useless revision of access control information is avoided (or at least substantially reduced); this has a beneficial effect on the management costs of the information technology system 100. Conversely, the risk of delaying a useful revision of access control information is avoided (or at least substantially reduced); this prevents data security and / or regulatory compliance exposure.
[0043] Referring Figure 2 to, a schematic block diagram of an information technology infrastructure 200 is shown in which a solution according to an embodiment of the present disclosure may be practiced.
[0044] The information technology infrastructure 200 has a distributed architecture based on the client / server model. In particular, one or more server machines, or simply servers 205, provide services to one or more client machines, or simply clients 210. For this purpose, the clients 210 communicate with the servers 205 via a (communication) network 215 (e.g., Internet-based). One or more of the servers 205 are resource servers, distinguished by the reference numeral 205r, which implement the above-mentioned information technology systems whose access must be protected; the resource servers 205r (e.g., providing services such as customer relationship management (CRM), lightweight directory access protocol (LDAP), security information and event management (SIEM), software as a service (SaaS), email, etc.) have hardware and / or software resources (e.g., devices, machines, files, programs, web pages, etc.) that can only be accessed by (authorized) users of the clients 210. One of the servers 205 (or more) is a control server, distinguished by the reference numeral 205c, which controls the access of the users of the clients 210 to the resources of the resource servers 205r (e.g., using a device, starting / stopping a machine, reading / writing a file, running a program, downloading a web page, etc.).
[0045] Each of the above-mentioned computing machines (i.e., servers 205 and clients 210) includes a plurality of units connected to each other via a bus structure 220 having one or more levels (with an architecture appropriately scaled according to the type of the computing machines 205, 210). In particular, one or more microprocessors (μP) 225 control the operation of the computing machines 205, 210; the non-volatile memory (ROM) 230 stores the basic code for booting the computers 205, 210, while the volatile memory (RAM) 235 is used by the microprocessor 225 as a working memory. The computers 205, 210 have a mass storage 240 for storing programs and data (e.g., the storage devices of the data center where the server 205 is implemented and the hard disk for the client 210). In addition, the computing machines 205, 210 include a plurality of controllers for peripheral devices, or input / output (I / O) units 245; for example, the peripheral devices 245 of each server 205 include a network card for inserting the server 205 into the corresponding data center and then connecting it to the console of the data center for its control (e.g., a personal computer, also provided with a drive for reading / writing removable storage units, such as optical discs, e.g., DVDs), and connecting to the switch / router subsystem of the data center for its communication with the network 215, while the peripheral devices 245 of each client 210 include a keyboard, a mouse, a monitor, a network adapter (NIC) for connecting to the network 215, and a drive for reading / writing removable storage units.
[0046] Reference Figure 3 shows the main software components that can be used to implement the solution according to an embodiment of the present disclosure.
[0047] In particular, all software components (programs and data) are represented as a whole by reference numeral 300. The software component 300 is typically stored in a mass storage, and is (at least partially) loaded into the working memory of the control server when the program runs. The program is initially installed in the mass storage, for example, from a removable storage unit or from a network (not shown in the figure). In this regard, each program can be a module, a code segment, or a code portion that includes one or more executable instructions for implementing the specified logical function.
[0048] The access control manager 305 controls access to the information technology system from a client (not shown in the figure). The access control manager 305 runs in the background as a service; the access control manager 305 intercepts any request from the client for performing a selected activity (on the corresponding resources of the information technology system), and allows or blocks it according to the authorization of the corresponding principal (e.g., the user who logs in to the client). The access control manager 305 accesses (in read / write mode) the permission database 310 and the identity database 315, which store access control information for controlling access to the information technology system. In particular, when the access control manager 305 is based on the RBAC model, the permission database 310 has entries for each role (identified by a corresponding unique identifier); the entries indicate one or more permissions assigned to the role for performing one or more activities (e.g., a developer is authorized to read / write the project he / she is working on, a team leader is authorized to read / write all projects of the developers in his / her team, a manager is authorized to read all projects of the developers reporting to him / her, etc.).
[0049] The identity database 315 has an entry for each user, which is registered with the access control manager 305 (identified by a corresponding unique identifier); the entry indicates the user's account and password, as well as one or more roles assigned to the user. Alternatively, when the access control manager 305 is based on the ABAC model, the permission database 310 has an entry for each rule. The entry indicates the permission granted or denied for performing an activity (or more) when the rule is satisfied. The rule is based on one or more attributes; the attributes can be related to resources (e.g., their type, location, classification, etc.), users (e.g., responsibilities, duties, capabilities, departments, etc.), activities (e.g., read, write, delete, approve, etc.), and / or context (e.g., date, time, etc.). For example, the rule can indicate that an employee is authorized to update a report when she / he is at a specific location, a developer is authorized to update a program when it is in test mode, no user is authorized to read a document before a certain date, and so on. The identity database 315 has an entry for each user, which is registered with the access control manager 305; the entry indicates the user's account / password and its one or more attributes. A commercial example of the access control manager 305 is "IBM Security Identity and Access Manager" of IBM Corporation. IBM is a registered trademark of International Business Machines Corporation.
[0050] In the solution according to an embodiment of the present disclosure, the trigger manager 320 triggers the revision of access control information. The trigger manager 320 interacts with the access control manager 305. The trigger manager 320 accesses (in read / write mode) the trigger policy repository 325 (e.g., manually populated by a system administrator through the user interface of the trigger manager 320). The trigger policy repository 325 has an entry for each trigger policy (identified by a corresponding unique identifier); the entry indicates the trigger policy and the corresponding score. The trigger policy is defined by a logical expression that produces a logical value (true or false); the logical expression includes one or more conditions (each condition produces a logical value based on one or more policy parameters), which can be combined with logical operators (e.g., AND, OR, NOT, etc.). The policy parameters are macro indicators related to the conditions of the entire information technology system or relevant parts thereof (i.e., not at the level of a single resource / user); in particular, the policy parameters can be related to resources (e.g., the number of new resources, the number of new resources in a specific location, etc.), users (e.g., the number of new users, the number of new users in a department, the number of changes in the organizational chart, etc.), and / or the access of users to resources (e.g., the number of new roles / rules, the number of new users corresponding to the roles / rules, the number of new permissions in the roles / rules, the number of new attributes in the rules, etc.).
[0051] A simple example of a trigger policy can be:
[0052] TP1 = (Nu > Thu) AND (Na > THa),
[0053] where Nu is the number of new users added to the identity database since the last evaluation of the trigger policy, THu is the corresponding threshold, Na is the number of new accounts added to the human resources database since the last evaluation of the trigger policy, THa is the corresponding threshold, and TP1 is the logical value of the trigger policy. The trigger policy can also be conditioned by one or more evaluation conditions that must be met before the (conditioned) trigger policy can be evaluated. Each evaluation condition is based on the completion of a conditioning task (such as, verifying information by a manager, achieving a certain progress of a project, etc.). In turn, the evaluation condition can depend on a logical expression (a part of the logical expression that defines the logical value of the trigger policy or a part independent of the logical value of the trigger policy), such as in the form of an IF / THEN construct.
[0054] Other examples of trigger policies with simple evaluation conditions can be:
[0055] TP2 = (Nr > THr) | EV,
[0056] TP3 = (Nr > THr) | if (TP3) then EV,
[0057] TP4 = (Nr > THr) | if (Np > THp) then EV,
[0058] Where Nr is the number of roles of users assigned to a particular department, THr is the corresponding threshold, Np is the number of permissions of the roles assigned to the department, THp is the corresponding threshold, EV is the validation of the roles assigned to the department by the manager, and TP2, TP3, and TP2 are the logical values for triggering the policy. Thus, in the first case, the task EV is executed, and once the task EV is completed, the logical expression (Nr > THr) is evaluated to determine the logical value TP2 of the triggering policy. In the second case, if the logical expression (Nr > THr) that defines the triggering policy TP3 is true, the task EV is executed, and once the task EV is completed, the logical expression (Nr > THr) is evaluated again to determine the logical value TP3 of the triggering policy. And in the third case, if the logical expression (Np > THp) is true, the task EV is executed, and once the task EV is completed, the logical expression (Nr > THr) is evaluated to determine the logical value TP4 of the triggering policy. The score of the triggering policy is a number (e.g., from 0 to 1), and the higher the score, the more effective the triggering policy is in triggering the revision of the access control information. In addition, the trigger manager 320 accesses (in read mode) one or more policy parameter sources 330. The policy parameter source 330 is an entity that provides the values of the policy parameters (such as, memory structures, services, applications, etc.); for example, the policy parameter source 330 includes the permission database 310, the identity database 315, the inventory database of the information technology system, the human resources database of the organization associated with the information technology system, etc.
[0059] The trigger manager 320 accesses (in write mode) the historical information database 335. The historical information database 335 has entries for each revision of the access control information that has been triggered by the above solution, for example, in the last 1 to 5 years. The entries indicate the (relevant) triggering policies that have been evaluated as true, meaning that they have contributed to triggering the revision of the access control information; in addition, the entries indicate the changes to the access control information caused by their revisions (such as, roles / rules that have been created, updated, or deleted, permissions that have been added, changed, or removed for each updated role / rule, roles that have been added or removed for each user, attributes that have been added or removed for each role / user, etc.). The ranking engine 340 updates the score of the policy using a feedback mechanism. For this purpose, the ranking engine 340 accesses (in read mode) the historical database 335, interacts with the access control manager 305, and accesses (in read / write mode) the trigger policy database 325.
[0060] The trigger manager 320 accesses (in write mode) the trigger index table 345 that stores the trigger index (the last value thereof). The output driver 350 outputs an indication of the trigger index, for example, by interacting with a monitor driver, an email client, the access control manager 305, etc. The output driver 350 accesses (in read mode) the trigger index table 345.
[0061] Reference Figures 4A to 4C , shows an activity diagram depicting the flow of activities related to the implementation of a solution according to an embodiment of the present disclosure.
[0062] In particular, the activity diagram represents an exemplary process that can be used to trigger a revision of access control information using the method 400. In this regard, each box may correspond to one or more executable instructions for implementing the specified logical function on a control server.
[0063] As Figure 4A shown, when an event occurs, the process transitions from verification at block 402 to retrieval at block 404, starting a verification operation for the need to revise access control information. For example, this may occur after a significant change in the policy parameters defining the trigger policy (such as a change of more than 10 - 20%), and / or periodically (e.g., every 1 to 7 days). At block 404, the trigger manager retrieves the trigger policy and its score from the corresponding database. Then it enters a loop for processing the trigger policy. The loop starts at block 406, where the trigger manager considers the (current) trigger policy (starting with the first in any order). The trigger manager retrieves the policy parameters indicated in the trigger policy at block 408; the policy parameters may be retrieved from a policy parameter source using a caching mechanism.
[0064] The activity flow branches at block 410 according to the type of trigger policy. If the trigger policy is regulated, it enters a further loop for processing the evaluation conditions of the (regulated) trigger policy. The loop starts at block 412, where the trigger manager considers the (current) evaluation condition (starting from the first in the corresponding order indicated in the trigger policy). The activity flow branches at block 414 according to the type of evaluation condition. If the evaluation condition depends on a logical expression, the trigger manager evaluates it at block 416. The activity flow branches at block 418 according to the logical value produced by the logical expression. If the logical expression has been evaluated as true, the process descends to block 420; if the evaluation condition does not depend on any logical expression, it also reaches the same point directly from block 414. At this point, the execution of the regulation task is caused (e.g., by sending a corresponding notification to a person, sending a corresponding command to a software application, etc.). Then, the trigger manager enters an idle loop at block 422, waiting for the completion of the regulation task. Once the regulation task has been completed (e.g., as notified by the corresponding message), and in any case after a predefined timeout, the process descends into block 424; if the logical expression is evaluated as false, it can also reach the same point directly from block 418. The trigger manager now verifies whether the last evaluation condition has been considered. If not, the process returns to block 412 to repeat the same operation for the next evaluation condition of the trigger policy. Instead, once all the evaluation conditions of the trigger policy have been considered, the corresponding loop is exited by descending into block 426; if the trigger policy is not regulated, it also reaches the same point directly from block 410.
[0065] The trigger manager now evaluates the logical expression of the trigger policy to determine its logical value at block 426 (always set to false when any regulation task of the trigger policy has not been completed for any reason (i.e., false logical expression or timeout expiration)), and saves this logical value into a working variable. The trigger manager verifies at block 428 whether the last trigger policy has been processed. If not, the process returns to block 406 to repeat the same operation for the next trigger policy. Instead, once all trigger policies have been processed, the corresponding loop is exited by descending into block 430.
[0066] As Figure 4B shown, at block 430, the trigger manager determines the trigger index according to the logical value and score (appropriately normalized) of the trigger policy. For example, the trigger index is calculated by applying the following formula:
[0067]
[0068] where TOTp is the total number of trigger policies, TP iis a numerical value corresponding to the logical value of the i-th triggering policy (retrieved from the corresponding working variable), such as 1 for true and 0 for false, R i is the score of the i-th triggering policy, and TI is the value of the trigger index (similar considerations apply if the trigger index is calculated incrementally during the evaluation of the triggering policy). In this way, the trigger index has a value ranging from 0 to 1. In particular, only the triggering policies evaluated as true contribute to the trigger index, and the contribution of these triggering policies is proportional to their scores.
[0069] The trigger manager compares the trigger index with a (trigger) threshold (e.g., 0.5 - 0.7) at block 432. If the trigger index is (possibly strictly) higher than the trigger threshold, the trigger manager outputs an indication at block 434 to trigger a revision of the access control information; for example, the trigger manager sends a trigger message (such as via email, SMS, etc.) to the system administrator. The trigger message indicates the need to revise the access control information; the trigger message may also include additional information about the reason for doing so (such as the trigger index, the triggering policy with the highest score that has been evaluated as true, etc.). At the same time, the trigger manager adds a new entry to the historical database for the revision of the access control information (e.g., identified by the corresponding timestamp) at block 436; the trigger manager then adds an indication of the triggering policies that have been evaluated as true (and have then contributed to triggering the revision of the access control information) to the new entry. When the trigger index is (possibly strictly) lower than the trigger threshold (and then no revision of the access control information is required), the process now returns from block 436 or directly from block 432 to block 402 (waiting for the next event for the trigger verification process).
[0070] Whenever a revision of access control information has been triggered, at block 438, the access control manager is in a waiting state for its completion. Specifically, the revision relates to a mining activity where a mapping of users to resources is discovered based on the typical patterns of users accessing resources as needed; for example, the mining activity can be performed in a bottom-up approach, a top-down approach, or by way of examples. Then, based on the results of the mining activity, i.e., the mapping of users to resources (e.g., in roles for an RBAC model and users assigned to roles for an RBAC model, or in rules for an ABAC model and attributes for rules / users for an ABAC model), one or more changes to be applied to the access control information are determined. Then, the permission database and / or identity database are updated based on the changes resulting from the mining activity (e.g., by adding roles / rules, updating users assigned to roles, updating rules, adding / deleting attributes, deleting roles / rules, etc.). Once the trigger manager receives a notification that the revision of the access control information is complete (e.g., via a command manually entered by a system administrator), the process proceeds to block 440. In response thereto, the trigger manager retrieves an indication of the updates that have been applied to the access control information from the permission database and the identity database (via the access control manager). The trigger manager saves these updates to the corresponding entries in the history database at block 442. Then, the process returns to block 438, waiting for the completion of the next revision of the access control information.
[0071] In a completely independent manner, once a (ranking) period has expired, the process moves from ranking at block 444 to retrieving at block 446 for performing ranking operations on trigger policies to update their scores (e.g., every 7 - 14 days). In response thereto, the ranking engine retrieves the trigger policies and their scores from the corresponding databases. Then, a loop for processing the trigger policies is entered. The loop starts at block 448, where the ranking engine considers the (current) trigger policy (starting with the first in any order). At block 450, the ranking engine retrieves an indication of the affected controls (if any) that have been affected by the trigger policy from the history database; the affected controls are roles / rules that have been created and / or updated during each revision of the access control information for which the (relevant) trigger policy has contributed to triggering its revision (i.e., it has been evaluated as true).
[0072] Enter a further loop for processing the affected controls of the trigger policy. The loop starts at box 452, where the ranking engine verifies whether there are any affected controls still to be processed. If so, at box 454, the ranking engine considers the affected control (starting from the first in any order) that still has to be processed. At box 456, the ranking engine retrieves (from the permission database via the access control manager) the survival status of the affected control. The active flow branches at box 458 according to this survival status. If the affected control no longer exists, at box 460, the ranking engine sets the lifetime indicator of the affected control to a low value (e.g., 0). Conversely, if the affected control still exists, at box 462, the ranking engine sets the lifetime indicator of the affected control to a high value (e.g., 1). In the latter case, at box 464, the ranking engine also calculates the scope indicator of the affected control.
[0073] The scope indicator depends on the permission of the affected control and / or depends on the corresponding user, i.e., the user assigned to the (affected) role or the user whose attributes match the attributes of the (affected) rule (via the access control manager, based on the information retrieved from the role database and the identity database). For example, the scope indicator is calculated by applying the following formula:
[0074]
[0075] where Nu is the number of users corresponding to the affected role, TOTu is the total number of users, TOTa is the total number of (protected) resources of the information technology system (such as software applications), Np(A i ) is the number of permissions of the affected control related to the i-th software application, TOTp(A i ) is the total number of permissions related to the i-th software application, and S is the value of the score indicator (which then ranges from 0 to 1). In this way, the higher the user corresponding to the affected control and / or the permission of the affected control, the higher the scope indicator of the affected control.
[0076] Then, the process returns to box 452 to repeat the same operation. Referring again to box 452, once there are no more affected controls to process (which is always true when the trigger policy has no affected controls as it has not contributed to any revision of the access control information), the process drops to box 466.
[0077] At this point, the ranking engine calculates the score of the trigger policy based on the lifetime indicator and the scope indicator of its affected controls. For example, the score is calculated by applying the following formula:
[0078]
[0079] where TOTr is the total number of affected controls, L(r i ) is the lifetime indicator of the i-th affected control, S(r i ) is the scope indicator of the i-th affected control, and W is the score of the trigger policy (which then ranges from 0 to 1). In this way, the higher the lifetime indicator and / or the scope indicator of the affected control, the higher the score of the trigger policy.
[0080] Alternatively, the score can be updated incrementally. For example, for each affected control, when the affected control no longer exists, the score is decreased, when the affected control still exists, the score is increased, when the scope indicator (possibly strictly) is below the (scope) threshold, the score is decreased, and when the scope indicator (possibly strictly) is above the scope threshold, the score is increased; the decrease and increase are by corresponding incremental values, e.g., 1 to 5% of the score and 1 to 5% of its complement, respectively, of 1.
[0081] In both cases, at block 468, the ranking engine saves the (new) score of the trigger policy to the corresponding entry in the trigger policy database (by replacing its previous value, manually initializing or initializing to a default value). At block 470, the ranking engine verifies whether the last trigger policy has been processed. If not, the process returns to block 448 to repeat the same operation for the next trigger policy. Instead, once all trigger policies have been processed, the corresponding loop is exited by returning to block 444 to wait for the next expiration of the ranking cycle.
[0082] As a result, the scores of the triggering policies are adapted to their effectiveness when triggering revisions of access control information. In fact, any revision process for which one or more relevant triggering policies have contributed to triggering its execution has involved an update of the access control information; in particular, one or more affected control entries may have been created / updated. For each affected control entry, if it still exists at a later (ranking) time when the ranking process is executed, this means that its usefulness may be high; conversely, if the affected control entry no longer exists at a later ranking time, this means that its usefulness may be low. More importantly, if the affected control entry has a large scope (e.g., defined by a large number of permissions and / or a large number of corresponding users), this means that its usefulness may be very high; conversely, if the affected control entry has a sparse scope (e.g., defined by a small number of permissions and / or a small number of corresponding users), this means that its usefulness may be low. When the most affected counterpart is considered to have high usefulness, the revision may also have been useful, and then the relevant triggering policy (which has contributed to triggering it) may be very effective; in this case, the scores of the relevant triggering policies are increased so that they will have a higher weight in the next verification process. Conversely, when the most affected counterpart is considered to have low usefulness, the revision may also be useless, and then the relevant triggering policy (which has contributed to triggering it) may be ineffective; in this case, the scores of the relevant triggering policies are decreased so that they will have a lower weight in the next verification process.
[0083] Of course, to meet local and specific requirements, those skilled in the art can apply many logical and / or physical revisions and changes to the present disclosure. More specifically, although the present disclosure has been described with a certain degree of particularity with reference to one or more of its embodiments, it should be understood that various omissions, substitutions, and changes in form and detail, as well as other embodiments, are possible. In particular, different embodiments of the present disclosure can even be practiced without the specific details (such as numerical values) set forth in the foregoing description to provide a more thorough understanding thereof; conversely, well-known features may be omitted or simplified so as not to obscure the description with unnecessary details. In addition, it is expressly intended that the specific elements and / or method steps described in connection with any embodiment of the present disclosure can be incorporated into any other embodiment as a matter of general design choice. Moreover, items presented in the same group and in different embodiments, examples, or alternatives are not to be construed as actually being equivalent to one another (but rather they are separate and autonomous entities). In any case, each numerical value should be read as being modified in accordance with the applicable tolerances; in particular, the terms "substantially", "about", "approximate", etc. should be understood to mean "within 10%". In addition, each range of numerical values should be intended to clearly specify any possible numerical value along the continuum within that range (including its endpoints). Ordinal numbers or other qualifiers are only used as labels to distinguish elements with the same name, but they do not in themselves imply any priority, ranking, or order. Terms such as including, comprising, having, containing, involving, etc. should be intended to have an open, non-exhaustive meaning (i.e., not limited to the listed items), terms based on, depending on, according to its function, etc. should be considered non-exclusive relationships (i.e., involving possible additional variables), the term "a / an" should be considered to mean one or more items (unless otherwise expressly stated), and the term "a component for..." (or any component-plus-function expression) should be considered to be any structure suitable for or configured to achieve the relevant function.
[0084] For example, an embodiment provides a method for facilitating the maintenance of access control information. However, the access control information can be of any type (e.g., based on roles for the RBAC model, rules and attributes for the ABAC model, tables for the access control list (ACL) model, etc.) for proving any type of control (e.g., enabling / disabling each activity, requesting a further action such as entering a second-level password to enable some activities, etc.).
[0085] In an embodiment, access control information is used to control access by one or more principals to one or more resources of an information technology system. However, the information technology system can be of any type (e.g., based on local area, wide area, global, cellular, or satellite networks, using any type of wired and / or wireless connection, having a stand-alone architecture, etc.), having any number and type of resources (e.g., portions, different, or additional resources relative to the above resources), the access to which must be controlled by any number and type of principals (e.g., users, programs, services, etc.).
[0086] In an embodiment, the method includes the following steps performed by a control computing system. However, the control computing system can be of any type (see below), and can perform the steps at any time (e.g., periodically, in response to a manual request, any combination thereof, etc. in response to any significant change in the access control information).
[0087] In an embodiment, the method includes (by the control computing system) retrieving one or more trigger policies. However, the trigger policies can be retrieved in any number and any manner (e.g., via read / query operations, local / remote commands, etc. from any memory structure such as a database, file, etc.).
[0088] In an embodiment, each trigger policy is based on one or more policy parameters related to a resource, a principal, and / or the access of the principal to the resource. However, the trigger policies can be based on any number and type of policy parameters in any manner (e.g., via logical expressions, rules, statements, etc.) (e.g., portions, different, or additional policy parameters relative to the above policy parameters, providing any macro information related to a resource, a principal, the access of the principal to the resource, any combination thereof, etc.).
[0089] In an embodiment, the method includes (by the control computing system) retrieving policy parameters. However, the policy parameters can be retrieved in any manner (e.g., via read / query operations, local / remote commands, etc. from portions, different, or additional policy parameter sources relative to the above policy parameter sources).
[0090] In an embodiment, the method includes (by the control computing system) evaluating a trigger policy based on the corresponding policy parameters. However, this operation can be performed in any manner (e.g., by evaluating a logical expression, a calculation formula, applying a rule, using an analysis technique, etc.) to determine any value (e.g., a logical value, a discrete level, a numerical value, etc.) of each trigger policy.
[0091] In an embodiment, the method includes (by a control computing system) determining a trigger indicator based on the result of the evaluation trigger policy. However, the trigger indicator can be of any type (e.g., a logical value, discrete values that can take any number of levels, a numerical value, etc.), and it can be determined in any way (e.g., by calculating any formula based on the values of the trigger policy, applying any threshold processing technique, using cognitive techniques, etc.).
[0092] In an embodiment, the method includes (by a control computing system) outputting an indication of the trigger indicator. However, the trigger indicator can be output in any way (e.g., displayed, transmitted to any individual(s), provided to any software application, etc.) and in any form (e.g., by its value, explanatory text, an alert, or any combination thereof, etc.).
[0093] In an embodiment, a revision of access control information is triggered in response to the trigger indicator. However, the revision of access control information can be triggered in any way (e.g., simply indicating the required access control information, providing corresponding priorities based on its value, etc.) according to the trigger indicator in any way (e.g., suggesting access control information to any individual(s), automatically initiating access control information, etc.).
[0094] In an embodiment, the revision of access control information includes a mining activity for mapping a subject to a resource. However, the mining activity can be of any type (e.g., role mining, rule mining, etc.) and is performed in any way (e.g., manually, with the help of an automated tool, such as based on analysis techniques, etc.).
[0095] In an embodiment, the revision of access control information includes a possible update of the access control information based on the result of the mining activity. However, the access control information can be updated in any way (e.g., by adding / updating / deleting roles, rules, attributes, identities, access control lists, etc. in any memory structure, such as one or more databases or files, etc.) until there is none.
[0096] In an embodiment, the method includes performing the mining activity in response to the trigger indicator having a positive value indicating that a revision is needed. However, the positive value of the trigger indicator can be of any type (e.g., indicating simply that a revision is needed, the revision is appropriate, useful, or necessary, etc.).
[0097] In an embodiment, the method includes updating the access control information based on the result of the mining activity. However, the access control information can be updated in any way (e.g., manually, automatically, accepting the proposed update, etc.) according to the result of the mining activity.
[0098] In an embodiment, the access control information includes an indication of one or more roles. However, the roles can be of any number and any type (e.g., executor, manager, developer, accountant, etc.).
[0099] In an embodiment, each role has one or more permissions to perform one or more activities in an information technology system. However, the permissions / activities can be of any number and any type (e.g., parts of, different from, or additional to the above permissions / activities).
[0100] In an embodiment, the access control information includes an indication of one or more roles out of the roles assigned to each principal in the principal. However, any number of roles can be assigned to each principal.
[0101] In an embodiment, the mining activity is role mining. However, the role mining can be of any type (e.g., bottom-up, top-down, resulting in adding roles, updating permissions / assignments of roles, deleting roles, etc.).
[0102] In an embodiment, the access control information includes one or more rules. However, the rules can be of any number and any type (e.g., IF / THEN constructs, logical expressions, etc.).
[0103] In an embodiment, each rule is based on one or more attributes. However, the attributes can be of any number and any type (e.g., related to resources, principals, activities, contexts, or any combination thereof).
[0104] In an embodiment, when a rule is satisfied, each rule indicates at least one permission related to an activity in the information technology system. However, the rules can indicate any number and type of permissions related to the activity in any way (e.g., enabling, denying, etc.) (see above).
[0105] In an embodiment, the mining activity is rule mining. However, the rule mining can be of any type (e.g., bottom-up, top-down, by example, resulting in adding / updating / deleting rules, changing attributes, etc.)
[0106] In an embodiment, the method includes (by a control computing system) determining a trigger indicator according to a corresponding score assigned to a trigger policy. However, the scores can be of any type (e.g., discrete / continuous weights, flags, fixed / variable, etc.), and they can be used to determine the trigger indicator in any way (e.g., by weighting the values of the trigger policy, enabling / disabling their consideration, etc.); in any case, this feature can also be omitted in a simplified implementation.
[0107] In an embodiment, the method includes (by a control computing system) storing historical information indicative of a revision. However, the historical information can be of any type (e.g., all changes applied to access control information or only parts thereof, such as parts of the above information, different or additional pieces of information) and stored in any manner (e.g., in any memory structure such as a database, a file, etc.).
[0108] In an embodiment, the historical information indicates a revision associated with one or more trigger policies relevant in a trigger policy that contributed to triggering the revision. However, the relevant trigger policies can be any number and defined in any manner (e.g., all trigger policies evaluated as true, trigger policies evaluated as true and having a score above a threshold, a predefined number of trigger policies evaluated as true and having the highest score, etc.).
[0109] In an embodiment, the method includes (by a control computing system) updating the score of a relevant trigger policy. However, the score can be updated in any manner (e.g., by recalculation, by increasing / decreasing an incremental value, etc.) based on (any) information source(s) (e.g., historical information, access control information, policy information parameters, any combination thereof, etc.).
[0110] In an embodiment, at a ranked time after the revision, the score of a relevant trigger policy is updated based on historical information and access control information. However, the score can be updated in any manner at any ranked time (e.g., with a predefined delay, continuously according to a predefined period, etc.) based on historical information (e.g., only referring to the last revision, one or more revisions that may be weighted according to their age, etc.) and access control information (e.g., according to its context, comparison with historical information, etc.).
[0111] In an embodiment, the method includes (by a control computing system) storing historical information that includes an indication of one or more affected control items that contribute to defining access control information affected by the revision. However, the affected control items can be any number and any type (e.g., roles, rules, all created / updated control items, only created control items, etc.).
[0112] In an embodiment, the method includes (by a control computing system) updating the score of a relevant trigger policy based on the affected control items at a ranked time. However, the score can be updated in any manner (e.g., according to its lifetime, scope, or any combination thereof, etc.) based on the affected control items.
[0113] In an embodiment, the method includes (by a control computing system) retrieving corresponding lifetime indicators of the affected controls at a ranking time. However, the lifetime indicators can be of any type (e.g., simply indicating whether the affected controls still exist, measuring the time elapsed since their creation or last revision, etc.).
[0114] In an embodiment, the method includes (by a control computing system) updating the score of a relevant trigger policy based on the lifetime indicators of the affected controls. However, the score can be updated in any way based on the lifetime indicators (e.g., using them in any linear / non-linear way to calculate the score, increasing / decreasing the score by a fixed value or a value proportional to them, etc.).
[0115] In an embodiment, the method includes (by a control computing system) retrieving corresponding scope indicators of the affected controls at a ranking time. However, the scope indicators can be of any type (e.g., based on the user corresponding to the affected controls, the permissions of the affected controls, or any combination thereof, etc.).
[0116] In an embodiment, the method includes (by a control computing system) updating the score of a relevant trigger policy based on the scope indicators of the affected controls. However, the score can be updated in any way based on the scope indicators (e.g., using them in any linear / non-linear way to calculate the score, increasing / decreasing the score by a fixed value or a value proportional to them when they are below / above any threshold, etc.).
[0117] In an embodiment, the scope indicator of each affected control is based on the principal corresponding to the affected control. However, the scope indicator can be based on the principal corresponding to the affected control in any way (e.g., based on the principal assigned to the affected role, the principal whose attributes match one of the affected rules, their number, their number calculated by weighting the principals according to the type of principal, etc.).
[0118] In an embodiment, the scope indicator of each control of the affected controls is based on the permission of the affected controls to perform activities in an information technology system. However, the scope indicator can be based on the permission of the affected controls in any way (e.g., generally based on their number, their number relative to each resource, possibly weighted according to the resource type, etc.).
[0119] In an embodiment, one or more of the regulated trigger policies in the trigger policy include an indication of one or more evaluation conditions. However, the number of regulated trigger policies can be any number (as low as zero), and each trigger policy includes any number and type of evaluation conditions (e.g., completion of a requested task, occurrence of an event, or depending or not depending on any logical expression, etc.).
[0120] In an embodiment, the method includes adjusting, by a control computing system, the evaluation of each of the adjusted trigger policies on a corresponding evaluation condition. However, the evaluation of each adjusted trigger policy can be adjusted in any way (e.g., waiting for the completion of an adjustment task, waiting for an event to occur, with or without a corresponding timeout, etc.).
[0121] In an embodiment, at least one of the evaluation conditions is the completion of a corresponding adjustment task. However, the adjustment task can be of any type (e.g., a partial, different, or additional adjustment task with respect to the above tasks).
[0122] In an embodiment, the method includes, by a control computing system, determining a significant change in a policy parameter. However, a significant change can be defined in any way (e.g., with reference to any number of policy parameters that have changed in an absolute or relative sense) and determined in any way (e.g., by monitoring policy parameters, by receiving a corresponding notification, etc.).
[0123] In an embodiment, the method includes, by a control computing system, performing a verification process (including retrieving the trigger policy, retrieving the policy parameter, evaluating the trigger policy, determining the trigger indicator, and outputting an indication of the trigger indicator) in response to a significant change in a policy parameter. However, the verification process can be performed in response to a significant change in a policy parameter in any way (e.g., automatically, requiring manual confirmation, etc.).
[0124] Generally, if the same solution is implemented using equivalent methods (by using similar steps with more steps or parts of the same function, removing some non-essential steps, or adding additional optional steps), then similar considerations apply; furthermore, these steps can be performed in a different order, simultaneously, or in an interleaved manner (at least in part).
[0125] Embodiments provide a computer program configured to cause a control computing system to perform the above-described method. Embodiments provide a computer program product for facilitating control of access to an information technology system by one or more entities. The computer program product includes a computer-readable storage medium having program instructions embodied therewith. The program instructions are executable by the control computing system to cause the control computing system to perform the above-described method. However, the software program can be implemented as a stand-alone module, as a plug-in for a pre-existing software program (e.g., an access control manager), or even directly implemented within the latter; clearly, the same solution can also be deployed as a service accessible via a network (such as on the Internet). Additionally, the program can be executed on any control computing system (see below). In any case, the solution according to embodiments of the present disclosure helps to implement itself even by leveraging a hardware structure (e.g., via electronic circuits integrated in one or more chips of a semiconductor material) or by using a combination of appropriately programmed or otherwise configured software and hardware.
[0126] Embodiments provide a control computing system including components configured to perform the steps of the above-described method. Embodiments provide a control computing system including circuitry (i.e., any hardware appropriately configured, e.g., by software) for performing each step of the same method. However, the control computing system can be of any type (e.g., one or more physical / virtual machines, their static or dynamic combinations, such as in a cloud computing environment, a system the same as or different from the computing environment for controlling access to an information technology system, etc.).
[0127] Generally, similar considerations apply if the control computing system has a different structure or includes equivalent components or has other operating characteristics. In any case, each of its components can be divided into more elements, or two or more components can be combined together into a single element; additionally, each component can be replicated to support parallel execution of corresponding operations. Moreover, unless otherwise specified, any interaction between different components generally does not need to be continuous, and it can be direct or indirect through one or more intermediaries.
[0128] The present invention can be a system, method, and / or computer program product at any possible level of integration of technical details. The computer program product can include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to perform aspects of the present invention.
[0129] A computer-readable storage medium can be a tangible device that is capable of retaining and storing instructions for use by an instruction execution device. The computer-readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer-readable storage medium includes the following: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanical encoding device such as a punched card or raised structures in a groove having instructions recorded thereon, and any appropriate combination of the foregoing. As used herein, a computer-readable storage medium is not construed to be a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0130] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device, or downloaded to an external computer or an external storage device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network). The network can include a copper transmission cable, an optical transmission fiber, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the corresponding computing / processing device.
[0131] The computer-readable program instructions for performing the operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine-related instructions, microcode, firmware instructions, state-setting data, configuration data for an integrated circuit, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network connection, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, to perform aspects of the present invention, an electronic circuit, including, for example, a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), may execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to personalize the electronic circuit.
[0132] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0133] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to operate in a particular manner, such that the computer-readable storage medium storing instructions therein comprises an article of manufacture including instructions for implementing aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0134] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0135] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions, which includes one or more executable instructions for implementing the specified (multiple) logical function. In some alternative implementations, the functions noted in the block may not occur in the order noted in the figures. For example, two blocks shown in succession may in fact be executed substantially simultaneously, or these blocks may sometimes be executed in the reverse order, depending on the functions involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by a special-purpose hardware-based system that performs the specified functions or acts, or combinations of special-purpose hardware and computer instructions.
[0136] The programs described herein are identified based on the applications in which they are implemented in particular embodiments of the present invention. However, it should be understood that any specific program terms herein are used for convenience only, and thus the present invention should not be limited to use only in any particular application identified and / or implied by such terms.
[0137] Embodiments of the present invention may be provided to end users via a cloud computing infrastructure. Cloud computing generally refers to the provision of scalable computing resources as a service over a network. More formally, cloud computing can be defined as the computing ability that provides an abstraction between computing resources and their underlying technical architectures (e.g., servers, storage devices, networks), thereby enabling convenient on-demand network access to a shared pool of configurable computing resources, which can be rapidly provisioned and released with minimal management effort or service provider interaction. Thus, cloud computing allows users to access virtual computing resources (e.g., storage, data, applications, even complete virtualized computing systems) in the "cloud" without regard to the underlying physical systems (or the locations of those systems) used to provide the computing resources.
[0138] Typically, cloud computing resources are provided to users on a pay-per-use basis, where users are charged only for the computing resources actually used (e.g., the amount of storage space consumed by the user or the number of virtualized systems instantiated by the user). Users can access any resources residing in the cloud at any time and from anywhere on the Internet. In the context of the present invention, users can access a normalized search engine or related data available in the cloud. For example, the normalized search engine may execute on a computing system in the cloud and perform a normalized search. In this case, the normalized search engine may normalize an information corpus and store the normalized index at a storage location in the cloud. Doing so allows users to access this information from any computing system attached to a network connected to the cloud (e.g., the Internet).
[0139] It should be understood that although this disclosure includes a detailed description of cloud computing, the implementation of the teachings recited herein is not limited to a cloud computing environment. Instead, embodiments of the present invention can be implemented in conjunction with any other type of computing environment now known or later developed.
[0140] Cloud computing is a service delivery model for enabling convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage devices, applications, virtual machines, and services), which can be rapidly provisioned and released with minimal management effort or interaction with the provider of the service. The cloud model can include at least five characteristics, at least three service models, and at least four deployment models.
[0141] The characteristics are as follows:
[0142] On-demand self-service: Cloud consumers can unilaterally and automatically provision computing capabilities (such as server time and network storage) as needed without human interaction with the service provider.
[0143] Wide area network access: The capabilities are available over a network and accessed through standard mechanisms that facilitate use by heterogeneous, thin, or thick client platforms (e.g., mobile phones, laptop computers, and PDAs).
[0144] Resource pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically allocated and reallocated according to demand. There is a location-independent meaning, because consumers generally do not control or know the exact location of the resources provided, but can specify a location at a higher level of abstraction (e.g., country, state, or data center).
[0145] Rapid elasticity: In some cases, the ability to rapidly scale out and rapidly scale in can be provided quickly and elastically. For consumers, the capabilities available for provisioning generally appear to be unlimited and can be purchased in any quantity at any time.
[0146] Measured service: The cloud system automatically controls and optimizes resource use by leveraging metering capabilities at some level of abstraction appropriate to the service type (e.g., storage, processing, bandwidth, and active user accounts). Resource use can be monitored, controlled, and reported, providing transparency for both the provider and the consumer of the utilized service.
[0147] The service models are as follows:
[0148] Software as a Service (SaaS): The ability provided to the consumer is to use the provider's applications running on a cloud infrastructure. The applications can be accessed from various client devices through a thin client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure including the network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.
[0149] Platform as a Service (PaaS): The ability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications that are created using programming languages and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including the network, servers, operating systems, or storage, but has control over the deployed applications and possibly the application hosting environment configuration.
[0150] Infrastructure as a Service (IaaS): The ability provided to the consumer is to provide processing, storage, networks, and other fundamental computing resources where the consumer can deploy and run arbitrary software, which can include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but has control over the operating systems, storage, deployed applications, and possibly limited control over selected networking components (e.g., host firewalls).
[0151] The deployment models are as follows:
[0152] Private cloud: The cloud infrastructure is operated solely for an organization. It can be managed by the organization or a third party and can exist either on-premises or off-premises.
[0153] Community cloud: The cloud infrastructure is shared by multiple organizations and supports a specific community with shared concerns (e.g., mission, security requirements, policies, and compliance considerations). It can be managed by the organizations or a third party and can exist either on-premises or off-premises.
[0154] Public cloud: The cloud infrastructure is available for general public or large industry groups and is owned by an organization selling cloud services.
[0155] Hybrid cloud: The cloud infrastructure is a combination of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technologies that enable data and application portability (e.g., cloud bursting for load balancing between clouds).
[0156] The cloud computing environment is service-oriented, with a focus on statelessness, low coupling, modularity, and semantic interoperability. At the core of cloud computing is an infrastructure of networks that includes interconnected nodes.
[0157] Now refer toFigure 5 , depicts an illustrative cloud computing environment 500. As shown, the cloud computing environment 500 includes one or more cloud computing nodes 510 with which local computing devices used by cloud consumers can communicate, such as local computing devices like a personal digital assistant (PDA) or cellular phone 540A, a desktop computer 540B, a laptop computer 540C, and / or an in-vehicle computer system 540N that can communicate. The cloud computing nodes 510 can communicate with each other. They can be physically or virtually grouped (not shown) in one or more networks (such as, for example, a private cloud, a community cloud, a public cloud, or a hybrid cloud or a combination thereof as described above). This allows the cloud computing environment 500 to provide infrastructure, platform, and / or software as a service, and the cloud consumer does not need to maintain resources on a local computing device for it. It should be understood that Figure 5 the types of computing devices 540A-N shown in
[0158] are merely illustrative, and the cloud computing nodes 510 and the cloud computing environment 500 can communicate with any type of computing device through any type of network and / or network addressable connection (e.g., using a web browser). Figure 6 , a set of functional abstraction layers provided by the cloud computing environment 500 (as Figure 5 shown) is illustrated. It should be understood in advance that Figure 6 the components, layers, and functions shown in
[0159] are only for illustration, and embodiments of the present invention are not limited thereto. As depicted, the following layers and corresponding functions are provided:
[0160] The hardware and software layer 660 includes hardware and software components. Examples of hardware components include: mainframes 661; servers 662 based on RISC (Reduced Instruction Set Computer) architecture; servers 663; blade servers 664; storage devices 665; and network and networking components 666. In some embodiments, the software components include network application server software 667 and database software 668.
[0161] In one example, the management layer 680 can provide the functions described below. Resource provisioning 681 provides for the dynamic procurement of computing resources and other resources used to perform tasks in a cloud computing environment. Metering and pricing 682 provides cost tracking when resources are utilized in a cloud computing environment, as well as billing or pricing for the consumption of these resources. In the example, these resources can include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. The user portal 683 provides access to the cloud computing environment for consumers and system administrators. Service level management 684 provides cloud computing resource allocation and management such that the required service levels are met. Service level agreement (SLA) planning and fulfillment 685 provides for the pre-arrangement and procurement of cloud computing resources, where future requirements are anticipated according to the SLA.
[0162] The workload layer 690 provides examples of functions that can utilize a cloud computing environment. Examples of workloads and functions that can be provided from this layer include: mapping and navigation 691; software development and life cycle management 692; virtual classroom education delivery 693; data analysis processing 694; transaction processing 695; and access control 696. Access control 696 can manage access control for information technology systems.
[0163] The description of the various embodiments of the present invention has been given for purposes of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to a person of ordinary skill in the art without departing from the scope of the described embodiments. The terms used herein were chosen to best explain the principles of the embodiments, the practical application, or improvements made to the technology found in the marketplace, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A method for facilitating the maintenance of access control information for controlling access by one or more principals to one or more resources of an information technology system, the method comprising: Retrieving, by a control computing system, one or more trigger policies, each trigger policy being based on one or more policy parameters related to the resource, the principal, and the principal's access to the resource; wherein each of the one or more trigger policies identifies a condition for a revision to the access control information related to the one or more resources of the information technology system, the one or more principals, and the access to the one or more resources of the information technology system; wherein each of the one or more trigger policies is evaluated by determining whether it is true and based on one or more policy parameters; Retrieving, by the control computing system, the policy parameters; wherein the policy parameters include changes in a number of new users greater than a threshold number since the last evaluation of the one or more trigger policies, changes in new users in departments greater than a second threshold number, changes in an organizational chart greater than a third threshold number, and changes in new roles of the principal greater than a fourth threshold number; Evaluating, by the control computing system, the trigger policies according to the corresponding policy parameters; Determining, by the control computing system, a trigger indicator based on the result of evaluating the trigger policies; wherein the trigger indicator is a trigger index that is calculated by weighting true trigger policies according to their corresponding scores associated with the effectiveness of triggering the revision of the access control information; Outputting, by the control computing system, an indication of the trigger indicator to trigger a revision to the access control information in response to the trigger indicator, the revision including a mining activity for mapping the principal to the resource and an update to the access control information based on the result of the mining activity; and Modifying, by an access control manager, the access control information based on the output.
2. The method according to claim 1, further comprising: Performing the mining activity in response to the trigger indicator having a positive value indicating a need for revision.
3. The method according to any one of claims 1 to 2, further comprising: Updating the access control information according to the result of the mining activity.
4. The method according to any one of claims 1 to 2, Among them, wherein the access control information includes an indication of one or more roles and an indication of one or more of the roles assigned to each principal among the principals, each of the one or more roles having one or more permissions to perform one or more activities in the information technology system, and the mining activity is role mining.
5. The method according to any one of claims 1 to 2, wherein wherein the access control information includes one or more rules, each of the one or more rules being based on one or more attributes and indicating at least one permission related to an activity in the information technology system when the rule is satisfied, and the mining activity is rule mining.
6. The method according to any one of claims 1 to 2 further comprises: determining, by the control computing system, the trigger indicator based on the corresponding score assigned to the trigger policy.
7. The method according to any one of claims 1 to 2 further comprises: storing, by the control computing system, historical information indicating a revision in association with one or more trigger policies in the trigger policy that contribute to triggering the revision; and updating, by the control computing system, the score of the relevant trigger policy based on the historical information and the access control information at a ranking time after the revision.
8. The method according to claim 7 further comprises: storing, by the control computing system, the historical information including an indication of one or more affected control items at the ranking time; and updating, by the control computing system, the score of the relevant trigger policy based on the one or more affected control items at the ranking time.
9. The method according to claim 8 further comprises: retrieving, by the control computing system, a corresponding lifetime indicator of the one or more affected control items at the ranking time; and updating, by the control computing system, the score of the relevant trigger policy based on the lifetime indicator of the one or more affected control items.
10. The method according to claim 9 further comprises: retrieving, by the control computing system, a corresponding scope indicator of the one or more affected control items at the ranking time; and updating, by the control computing system, the score of the relevant trigger policy based on the scope indicator of the one or more affected control items.
11. In the method according to claim 10, Among them, the scope indicator of each affected control item among the one or more affected control items is based on the subject corresponding to the one or more affected control items.
12. In the method according to claim 11, wherein the scope indicator of each affected control item among the one or more affected control items is based on the permission of the one or more affected control items to perform an activity in the information technology system.
13. The method according to any one of claims 1 to 2, Among them, the one or more adjusted trigger policies in the trigger policy include an indication of one or more evaluation conditions, and the method further comprises: adjusting, by the control computing system, the evaluation of each trigger policy in the adjusted trigger policy on the corresponding evaluation condition.
14. In the method according to claim 13, Among them, at least one of the evaluation conditions is the completion of a corresponding adjustment task.
15. The method according to any one of claims 1 to 2 further comprises: determining, by the control computing system, a significant change in the policy parameter; and A verification process is performed by the control computing system, including retrieving the trigger policy, retrieving the policy parameters, evaluating the trigger policy, determining the trigger indicator, and outputting an indication of the trigger indicator in response to the significant change of the policy parameters.
16. A computer program product for facilitating the maintenance of access control information for controlling access by one or more subjects to one or more resources of an information technology system, the computer program product comprising: One or more computer-readable tangible storage media and program instructions stored on at least one of the one or more tangible storage media, the program instructions being executable by a processor, the program instructions comprising: Program instructions for retrieving one or more trigger policies, each trigger policy being based on one or more policy parameters related to the resource, the subject, and the subject's access to the resource; Wherein each trigger policy of the one or more trigger policies identifies a condition for a revision to the access control information related to the one or more resources of the information technology system, the one or more subjects, and the access to the one or more resources of the information technology system; Wherein each trigger policy of the one or more trigger policies is evaluated by determining whether it is true and based on one or more policy parameters; Program instructions for retrieving the policy parameters; Wherein the policy parameters include changes in a number of new users greater than a threshold number since the last evaluation of the one or more trigger policies, changes in new users in departments greater than a second threshold number, changes in an organizational chart greater than a third threshold number, and changes in new roles of the subjects greater than a fourth threshold number; Program instructions for retrieving and evaluating the trigger policy according to the corresponding policy parameters; Program instructions for determining a trigger indicator based on the result of evaluating the trigger policy; Wherein the trigger indicator is a trigger index, and the trigger index is calculated by weighting the true trigger policies according to their corresponding scores associated with the effectiveness of triggering the revision of the access control information; Program instructions for outputting an indication of the trigger indicator to trigger a revision to the access control information in response to the trigger indicator, the revision including a mining activity for mapping the subject to the resource and an update to the access control information based on the result of the mining activity; and The access control information is modified by the access control manager based on the output.
17. The computer program product according to claim 16, further comprising: Program instructions for performing the mining activity in response to the trigger indicator having a positive value indicating a need for revision.
18. The computer program product according to any one of claims 16 to 17, further comprising: Program instructions for updating the access control information based on the result of the mining activity.
19. The computer program product according to any one of claims 16 to 17, Among them, The access control information includes an indication of one or more roles and an indication of one or more of the roles assigned to each of the subjects in the subjects, each of the one or more roles having one or more permissions to perform one or more activities in the information technology system, and the mining activity is role mining.
20. A computer program product according to any one of claims 16 to 17, wherein, The access control information includes one or more rules, each of the one or more rules being based on one or more attributes and indicating at least one permission related to an activity in the information technology system when the rule is satisfied, and the mining activity is rule mining.
Citation Information
Patent Citations
System and method for access decision evaluation for building automation and control systems
CN104137007A