Patents by Inventor Brian Robert Matthiesen
Brian Robert Matthiesen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 10944759Abstract: An identity management system is augmented to provide for automated suspension of all dormant accounts before launching a re-certification campaign (pass). In one implementation, prior to receiving a recertification notice from the system, the affected user's account is already suspended and thus cannot be accessed. Once the recertification succeeds, however, the account is restored. Preferably, the technique is exposed to an IAM system administrator through a simple interface, e.g., a one-click “suspend and re-certify” button in an administrative menu. When the administrator initiates the re-certification process, he or she may select the button for a particular account or user.Type: GrantFiled: October 7, 2019Date of Patent: March 9, 2021Assignee: International Business Machines CorporationInventors: Jean Elizabeth Hidden, Gee Ngoo Chia, Brian Robert Matthiesen, Stephen J. Turcol
-
Patent number: 10679141Abstract: An identity and access management IAM system is augmented to provide for supervised, iterative machine learning (ML), preferably with a user-generated training set for classification. The training set may include various types of data, including characteristics or attributes of the account types, the users, or the like. A goal of the initial ML training, which may include one or multiple passes, is to enable the machine to identify specific characteristics or attributes that provide a good classification result, with the resulting classifications then applied within the IAM system. In particular, the output of the ML system may be used by the IAM system for enforcing rights associated with the identified accounts, managing accounts, and so forth.Type: GrantFiled: September 29, 2015Date of Patent: June 9, 2020Assignee: International Business Machines CorporationInventors: Brian Robert Matthiesen, Gee Ngoo Chia, John Leslie Harter, David Walsh Palmieri
-
Publication number: 20200145427Abstract: An identity management system is augmented to provide for automated suspension of all dormant accounts before launching a re-certification campaign (pass). In one implementation, prior to receiving a recertification notice from the system, the affected user's account is already suspended and thus cannot be accessed. Once the recertification succeeds, however, the account is restored. Preferably, the technique is exposed to an IAM system administrator through a simple interface, e.g., a one-click “suspend and re-certify” button in an administrative menu. When the administrator initiates the re-certification process, he or she may select the button for a particular account or user.Type: ApplicationFiled: October 7, 2019Publication date: May 7, 2020Inventors: Jean Elizabeth Hidden, Gee Ngoo Chia, Brian Robert Matthiesen, Stephen J. Turcol
-
Patent number: 10440029Abstract: An identity management system is augmented to provide for automated suspension of all dormant accounts before launching a re-certification campaign (pass). In one implementation, prior to receiving a recertification notice from the system, the affected user's account is already suspended and thus cannot be accessed. Once the recertification succeeds, however, the account is restored. Preferably, the technique is exposed to an IAM system administrator through a simple interface, e.g., a one-click “suspend and re-certify” button in an administrative menu. When the administrator initiates the re-certification process, he or she may select the button for a particular account or user.Type: GrantFiled: September 2, 2015Date of Patent: October 8, 2019Assignee: International Business Machines CorporationInventors: Jean Elizabeth Hidden, Gee Ngoo Chia, Brian Robert Matthiesen, Stephen J. Turcol
-
Patent number: 10243994Abstract: An identity management system is augmented to provide a methodology to generate an objective measure of administrative effectiveness with respect to account certification. In the approach, erroneous account information is intentionally inserted into a recertification campaign. The erroneous account information is tracked through the recertification process and used as a measurement to evaluate whether a particular manager/administrator whose accounts are impacted is successful in recognizing the erroneous account information (e.g., as a percentage of erroneous account records located). The dummy information is tracked and used to generate a quantitative measure of the effectiveness of a particular recertification campaign or a particular manager who is responsible for recertifying accounts. The results can also be used to drive other enterprise metrics and compliance systems.Type: GrantFiled: September 2, 2015Date of Patent: March 26, 2019Assignee: International Business Machines CorporationInventors: Brian Robert Matthiesen, Gee Ngoo Chia, Jean Elizabeth Hidden, Stephen James Turcol
-
Publication number: 20170091658Abstract: An identity and access management IAM system is augmented to provide for supervised, iterative machine learning (ML), preferably with a user-generated training set for classification. The training set may include various types of data, including characteristics or attributes of the account types, the users, or the like. A goal of the initial ML training, which may include one or multiple passes, is to enable the machine to identify specific characteristics or attributes that provide a good classification result, with the resulting classifications then applied within the IAM system. In particular, the output of the ML system may be used by the IAM system for enforcing rights associated with the identified accounts, managing accounts, and so forth.Type: ApplicationFiled: September 29, 2015Publication date: March 30, 2017Inventors: Brian Robert Matthiesen, Gee Ngoo Chia, John Leslie Harter, David Walsh Palmieri
-
Publication number: 20170063872Abstract: An identity management system is augmented to provide a methodology to generate an objective measure of administrative effectiveness with respect to account certification. In the approach, erroneous account information is intentionally inserted into a recertification campaign. The erroneous account information is tracked through the recertification process and used as a measurement to evaluate whether a particular manager/administrator whose accounts are impacted is successful in recognizing the erroneous account information (e.g., as a percentage of erroneous account records located). The dummy information is tracked and used to generate a quantitative measure of the effectiveness of a particular recertification campaign or a particular manager who is responsible for recertifying accounts. The results can also be used to drive other enterprise metrics and compliance systems.Type: ApplicationFiled: September 2, 2015Publication date: March 2, 2017Inventors: Brian Robert Matthiesen, Gee Ngoo Chia, Jean Elizabeth Hidden, Stephen James Turcol
-
Publication number: 20170063873Abstract: An identity management system is augmented to provide for automated suspension of all dormant accounts before launching a re-certification campaign (pass). In one implementation, prior to receiving a recertification notice from the system, the affected user's account is already suspended and thus cannot be accessed. Once the recertification succeeds, however, the account is restored. Preferably, the technique is exposed to an IAM system administrator through a simple interface, e.g., a one-click “suspend and re-certify” button in an administrative menu. When the administrator initiates the re-certification process, he or she may select the button for a particular account or user.Type: ApplicationFiled: September 2, 2015Publication date: March 2, 2017Inventors: Jean Elizabeth Hidden, Gee Ngoo Chia, Brian Robert Matthiesen, Stephen J. Turcol
-
Patent number: 9411963Abstract: An identity management system is augmented to enable a manager to associate “risk” metadata with different types of access requests representing computer system accounts that can be requested by authorized users. When an authorized user then requests access to a particular account, any “risk” associated with that access is shown to the user, typically in the form of a visual “badge” or other such indicator. The badge includes an appropriate informational display (e.g., “High Risk” or “Regulated”) that provides an appropriate risk warning. The risk metadata badge information preferably also is displayed for risk-based access request approval routing; in such context, the risk metadata may also determine the risk approval workflow itself. Thus, for example, if the risk metadata is present when the authorized user requests access, an approval workflow may be modified so that the request approval is routed appropriately.Type: GrantFiled: July 7, 2014Date of Patent: August 9, 2016Assignee: International Business Machines CorporationInventors: Jeffrey Tobias Robke, John Leslie Harter, Brian Robert Matthiesen
-
Publication number: 20160004868Abstract: An identity management system is augmented to enable a manager to associate “risk” metadata with different types of access requests representing computer system accounts that can be requested by authorized users. When an authorized user then requests access to a particular account, any “risk” associated with that access is shown to the user, typically in the form of a visual “badge” or other such indicator. The badge includes an appropriate informational display (e.g., “High Risk” or “Regulated”) that provides an appropriate risk warning. The risk metadata badge information preferably also is displayed for risk-based access request approval routing; in such context, the risk metadata may also determine the risk approval workflow itself. Thus, for example, if the risk metadata is present when the authorized user requests access, an approval workflow may be modified so that the request approval is routed appropriately.Type: ApplicationFiled: July 7, 2014Publication date: January 7, 2016Inventors: Jeffrey Tobias Robke, John Leslie Harter, Brian Robert Matthiesen
-
Patent number: 8302088Abstract: Embodiments of the invention provide a method, a system and a computer program product for analyzing the effect of a software maintenance patch on configuration items of a CMDB. One embodiment, directed to a method, is associated with a CMDB containing information that relates to configuration items (CIs) included in one or more managed configurable systems. The method includes the step of generating a manifest that defines a target system, and contains a description of a maintenance patch disposed to update one or more specified software components. The method further includes using information contained in the manifest to search the CMDB, in order to detect each configurable system in the CMDB that corresponds to the definition of the target system, and contains at least one CI that includes at least one of the specified software components.Type: GrantFiled: October 15, 2008Date of Patent: October 30, 2012Assignee: International Business Machines CorporationInventor: Brian Robert Matthiesen
-
Patent number: 7865466Abstract: A system for synchronizing account names from a plurality of source security systems. In response to coupling a conversion system between the plurality of source security systems and a target security system, identity data from a human resource system and account data from the plurality of local source security systems is loaded into the conversion system. A name resolution rule set is retrieved and a unique account name identification is generated for a set of account names associated with an identity using the name resolution rule set. The set of account names associated with the identity is converted to the unique account name identification to produce a synchronized set of account names associated with the identity. Then, the synchronized set of account names associated with the identity is stored in the target security system.Type: GrantFiled: August 27, 2007Date of Patent: January 4, 2011Assignee: International Business Machines CorporationInventors: Alexander Phillip Amies, Dennis Raymond Doll, Bassam H. Hassoun, Brian Robert Matthiesen
-
Publication number: 20100095273Abstract: Embodiments of the invention provide a method, a system and a computer program product for analyzing the effect of a software maintenance patch on configuration items of a CMDB. One embodiment, directed to a method, is associated with a CMDB containing information that relates to configuration items (CIs) included in one or more managed configurable systems. The method includes the step of generating a manifest that defines a target system, and contains a description of a maintenance patch disposed to update one or more specified software components. The method further includes using information contained in the manifest to search the CMDB, in order to detect each configurable system in the CMDB that corresponds to the definition of the target system, and contains at least one CI that includes at least one of the specified software components.Type: ApplicationFiled: October 15, 2008Publication date: April 15, 2010Applicant: International Businass Machines CorporationInventor: Brian Robert Matthiesen
-
Publication number: 20090063494Abstract: A system for synchronizing account names from a plurality of source security systems. In response to coupling a conversion system between the plurality of source security systems and a target security system, identity data from a human resource system and account data from the plurality of local source security systems is loaded into the conversion system. A name resolution rule set is retrieved and a unique account name identification is generated for a set of account names associated with an identity using the name resolution rule set. The set of account names associated with the identity is converted to the unique account name identification to produce a synchronized set of account names associated with the identity. Then, the synchronized set of account names associated with the identity is stored in the target security system.Type: ApplicationFiled: August 27, 2007Publication date: March 5, 2009Inventors: Alexander Phillip Amies, Dennis Raymond Doll, Bassam H. Hassoun, Brian Robert Matthiesen