EP4589484A2

Systems and methods for secure policies-based information governance

Abstract

Disclosed are systems and methods for secure policies-based information governance. An exemplary method may display (405) a Graphical User Interface, GUI. The GUI may receive a business rule input from a business user. The method may further receive (410) a policy from a policy engine based on the business rule input. The policy engine generates a policy hierarchy that allows precedence of policies operation. The policy hierarchy allows the concept of guardrails to ensure that potentially dangerous policy actions may be controlled. The method may then define (415) a plurality of domain objects and a plurality of domain object representations in the GUI based on the policy and the policy hierarchy. The method may define (420) an extensible hierarchical domain model definition using the policy hierarchy. The extensible hierarchical domain model definition is modified using the plurality of domain object representations in the GUI. Based on the extensible hierarchical domain model definition, the method may define (425) a Policy Enforcement Point, PEP in an application. A mapping from the PEP in the application may then be provided (430) to the plurality of domain object representations in the GUI. The method may also receive (435), by the PEP, a user request to access a resource on the application. The user request comprises attributes of a user.

EP4589484A2, drawing sheet 1
Sheet 1 of 18

Term

14.1 yearsto projected expiry

Projected expiry 13 October 2040, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

15 claims: 5 independent, 10 dependent

  1. 1
    A method for secure policies-based information governance, the method comprising:displaying (405) a Graphical User Interface, GUI (150), the GUI (150) receiving a business rule input from a business user (105);receiving (410) a policy from a policy engine based on the business rule input, the policy engine generating a policy hierarchy that allows precedence of policies operation, the policy hierarchy allowing the concept of guardrails to ensure that potentially dangerous policy actions may be controlled;defining (415) a plurality of domain objects and a plurality of domain object representations in the GUI (150) based on the policy and the policy hierarchy;defining (420) an extensible hierarchical domain model definition using the policy hierarchy, the extensible hierarchical domain model definition being modified using the plurality of domain object representations in the GUI (150);defining (425) a Policy Enforcement Point, PEP (220) in an application based on the extensible hierarchical domain model definition;providing (430) a mapping from the PEP (220) in the application to the plurality of domain object representations in the GUI (150);and receiving (435), by the PEP (220), a user request to access a resource on the application, the user request comprising attributes of a user (105).
  2. 6
    The method as recited in any of claims 3-5, further comprising generating a custom domain model;wherein the evaluating, using the PIP, the attributes of the user (105) comprises using the custom domain model.
  3. 7
    The method as recited in any of the preceding claims, wherein the GUI (150) further comprises a policy designer screen for the business user (105).
  4. 10
    The method as recited in any of the preceding claims, wherein the decision regarding the user request to access the resource on the application is to deny access to the resource based on the policy;and wherein the enforcing (455), by the PEP (220), the decision regarding the user request to access the resource is denying access to the resource on the application.
  5. 11
    The method as recited in any of the preceding claims, wherein the decision regarding the user request to access the resource on the application is to grant access to the resource based on the policy;and wherein the enforcing (455), by the PEP (220), the decision regarding the user request to access the resource on the application is granting access to the resource on the application.
  6. 12
    A computer system comprising one or more processors (5) configured to perform the method of any of claims 1-11.
  7. 14
    A computer program comprising instructions (55) which, when the program is executed by a computer system (1), cause the computer system (1) to carry out the method of any of claims 1-11.
  8. 15
    A computer-readable medium comprising instructions (55) which, when executed by a computer system (1), cause the computer system (1) to perform the method of any of claims 1-11.