EP1320018A2

Guaranteed delivery of changes to security policies in a distributed system

Abstract

The present invention relates to improved approaches for communicating changes to security policies (or rules) in a distributed security system. Depending on the status of an affected user in the system, the changes can be delivered to the user if the user is logged in the system or effectuated in a state message in a local server and the state message is delivered to the user next time the user is logged in the system. If a local server is not operative at the time that a change request is received for a user of the local server, the change request is redirected to another local server. The user is directed to the another local server to affect the change request. As a result, various changes are guaranteed to be delivered to the affected users without compromising the network efficiency.

EP1320018A2, drawing sheet 1
Sheet 1 of 18

Term

Term ended

Projected expiry passed 11 December 2022, 3.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

11 claims: 7 independent, 4 dependent

  1. 1
    A method for distributing a security policy change within a security system distributed over a computer network, the method comprising:- generating a command to include the security policy change in response to a request received from the central server;determining users that are to be affected by the security policy change;effectuating the security policy change in a state message for a user among the users when the user is not logged in the system, wherein the state message is to be pulled to the user whenever the user is logged in the system;anddelivering the command to the user when the user is currently logged in the system.
  2. 5
    A method according to any one of the preceding claims, wherein the request is received from the central server, and the request is generated manually by an operator of the central server or in accordance with an event to alter access privilege of the user.
  3. 7
    A method according to any one of the preceding claims, wherein the delivering of the security policy change to the user comprises:- pushing the command to the user;andeffectuating the security policy change locally with respect to the user such that access privilege of the user is altered.
  4. 8
    A method for distributing a security policy change within a security system distributed over a computer network, the method comprising:receiving a request from a central server to carry out the security policy change to alter access privilege of a user to secured items in the system;determining a first local server that services the user;generating a command in a second local server in response to the request when it is determined that the first local server is not operative, both the first and second local servers coupled to the central server;delivering the command to the user when the user is currently logged with the second local server;andeffectuating the security policy change in a state message for the user when the user is not logged in the system, wherein the state message is delivered to one of the first and second local servers whenever the user is logged with the one of the first and second local servers, wherein the state message is subsequently pulled to the user.
  5. 9
    An architecture for distributing a security policy change within a security system distributed over a computer network, the architecture comprising:- a central server providing access control management in the system;at least a first local server and a second local server, each carrying out some or all of the access control management for a plurality of users;wherein the central server initiates a request to alter access privilege of a user managed by the first local server and sends the request to the second local server upon detecting that the first local server is not operative, in response to the request, the second local server pushes a command to the user to carry out the security policy change if the user is logged with the second local server;and    wherein the central server effectuates the security policy change in a state message for the user when the user is not logged in the system, the state message is delivered to one of the first and second local servers whenever the user is logged with the one of the first and second local servers, the state message is subsequently pulled to the user.
  6. 10
    A computer readable medium including at least computer program code for distributing a security policy change within a security system, the computer readable medium comprising:program code for generating a command to include the security policy change in response to a request received from the central server;program code for determining users that are to be affected by the security policy change;program code for effectuating the security policy change in a state message for a user among the users when the user is not logged in the system, wherein the state message is to be pulled to the user whenever the user is logged in the system;andprogram code for delivering the command to the user when the user is currently logged in the system.
  7. 11
    A computer readable medium including at least computer program code for distributing a security policy change within a security system, the computer readable medium comprising:- program code for receiving a request from a central server to carry out the security policy change to alter access privilege of a user to secured items in the system;program code for determining a first local server that services the user;program code for generating a command in a second local server in response to the request when it is determined that the first local server is not operative, both the first and second local servers coupled to the central server;program code for delivering the command to the user when the user is currently logged with the second local server;andprogram code for effectuating the security policy change in a state message for the user when the user is not logged in the system, wherein the state message is delivered to one of the first and second local servers whenever the user is logged with the one of the first and second local servers, wherein the state message is subsequently pulled to the user.