Patents by Inventor Gavin George Bray

Gavin George Bray has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10432666
    Abstract: A method of policy management in a Data Loss Prevention (DLP) system uses a policy model that associates a user with one or more DLP endpoints. When an endpoint is added to the system, a set of policies for that endpoint are determined using an identity of the user that is associated with the endpoint and a list of roles or groups for that user. At policy distribution time, the method determines a set of endpoints to which the policy is to be distributed.
    Type: Grant
    Filed: April 8, 2016
    Date of Patent: October 1, 2019
    Assignee: Sailpoint Technology Holdings, Inc.
    Inventors: Neil Ian Readshaw, Jayashree Ramanathan, Gavin George Bray
  • Publication number: 20160226918
    Abstract: A method of policy management in a Data Loss Prevention (DLP) system uses a policy model that associates a user with one or more DLP endpoints. When an endpoint is added to the system, a set of policies for that endpoint are determined using an identity of the user that is associated with the endpoint and a list of roles or groups for that user. At policy distribution time, the method determines a set of endpoints to which the policy is to be distributed.
    Type: Application
    Filed: April 8, 2016
    Publication date: August 4, 2016
    Applicant: International Business Machines Corporation
    Inventors: Neil Ian Readshaw, Jayashree Ramanathan, Gavin George Bray
  • Patent number: 9311495
    Abstract: A method of policy management in a Data Loss Prevention (DLP) system uses a policy model that associates a user with one or more DLP endpoints. When an endpoint is added to the system, a set of policies for that endpoint are determined using an identity of the user that is associated with the endpoint and a list of roles or groups for that user. At policy distribution time, the method determines a set of endpoints to which the policy is to be distributed.
    Type: Grant
    Filed: December 9, 2010
    Date of Patent: April 12, 2016
    Assignee: International Business Machines Corporation
    Inventors: Neil Ian Readshaw, Jayashree Ramanathan, Gavin George Bray
  • Patent number: 9134983
    Abstract: An endpoint machine has a unique endpoint identifier based on a configurable set of hardware attributes for an endpoint type. The endpoint agent running on that machine has an associated software identifier registered with the endpoint management solution upon install. The management server generates the unique endpoint identifier and provides it to the endpoint agent. Periodically, checks are run on the endpoint by the endpoint agent to determine if any of the hardware attributes have changed. If so, the endpoint identifier and the new hardware attribute values are sent to the management server, which uses the information to recognize the endpoint as the same endpoint or to detect a clone of known endpoint. If the endpoint type is unknown or does not exist, the unique software identifier may be used to facilitate the identification process, including the ability to detect a cloned machine.
    Type: Grant
    Filed: January 9, 2012
    Date of Patent: September 15, 2015
    Assignee: International Business Machines Corporation
    Inventors: Kalvinder Pal Singh, Gavin George Bray, Elizabeth Marie Hughes
  • Patent number: 8607322
    Abstract: A method and a system are presented in which federated domains interact within a federated environment. Domains within a federation can initiate federated single-sign-on operations for a user at other federated domains. A point-of-contact server within a domain relies upon a trust proxy within the domain to manage trust relationships between the domain and the federation. Trust proxies interpret assertions from other federated domains as necessary. Trust proxies may have a trust relationship with one or more trust brokers, and a trust proxy may rely upon a trust broker for assistance in interpreting assertions. When a user is provisioned at a particular federated domain, the federated domain can provision the user to other federated domains within the federated environment. A provision operation may include creating or deleting an account for a user, pushing updated user account information including attributes, and requesting updates on account information including attributes.
    Type: Grant
    Filed: July 21, 2004
    Date of Patent: December 10, 2013
    Assignee: International Business Machines Corporation
    Inventors: Heather Maria Hinton, Brian James Turner, Anthony Scott Moran, Shane Weeden, Ian Michael Glazer, Gavin George Bray, Venkat Raghavan
  • Publication number: 20130179548
    Abstract: An endpoint machine has a unique endpoint identifier based on a configurable set of hardware attributes for an endpoint type. The endpoint agent running on that machine has an associated software identifier registered with the endpoint management solution upon install. The management server generates the unique endpoint identifier and provides it to the endpoint agent. Periodically, checks are run on the endpoint by the endpoint agent to determine if any of the hardware attributes have changed. If so, the endpoint identifier and the new hardware attribute values are sent to the management server, which uses the information to recognize the endpoint as the same endpoint or to detect a clone of known endpoint. If the endpoint type is unknown or does not exist, the unique software identifier may be used to facilitate the identification process, including the ability to detect a cloned machine.
    Type: Application
    Filed: January 9, 2012
    Publication date: July 11, 2013
    Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Kalvinder Pal Singh, Gavin George Bray, Elizabeth Marie Hughes
  • Publication number: 20120151551
    Abstract: A method of policy management in a Data Loss Prevention (DLP) system uses a policy model that associates a user with one or more DLP endpoints. When an endpoint is added to the system, a set of policies for that endpoint are determined using an identity of the user that is associated with the endpoint and a list of roles or groups for that user. At policy distribution time, the method determines a set of endpoints to which the policy is to be distributed.
    Type: Application
    Filed: December 9, 2010
    Publication date: June 14, 2012
    Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventors: Neil Ian Readshaw, Jayashree Ramanathan, Gavin George Bray