Patents by Inventor Jeffrey R. Finz

Jeffrey R. Finz has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 7093125
    Abstract: A method and apparatus for delegating root access to non-root users of a computer system while maintaining computer system security are disclosed. Such a method may include authorizing a role for a user, wherein the authorized role includes one or more tools and the tools enable root access for certain tasks that the tools perform when run, whereby the one or more tools are delegated to the user and authorizing a machine of the computer system for the authorized role, wherein the computer system comprises a plurality of machines and the user is enabled to utilize the authorized role only on authorized machines, whereby utilizing the authorized role comprises running the one or more tools of the authorized role. Embodiments of the invention may comprise authorization objects that comprise attributes identifying a user and the roles and machine for which the user is authorized.
    Type: Grant
    Filed: May 8, 2001
    Date of Patent: August 15, 2006
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Mary Thomas Robb, Richard D. Harrah, Jeffrey R. Finz, Humberto A. Sanchez, II, Douglas P. Drees, Terence E. Lister, Paula Curtis
  • Patent number: 7039917
    Abstract: A service control manager (SCM) tool execution mechanism enables SCM users to execute SCM tools across a set of defined distributed nodes (systems). It provides a secure mechanism, referred to a distributed task facility (DTF), to integrate different operations and execute the operations across the set of distributed nodes.
    Type: Grant
    Filed: March 20, 2001
    Date of Patent: May 2, 2006
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Terence E. Lister, Humberto A Sanchez, II, Douglas P. Drees, Jeffrey R. Finz
  • Patent number: 6886100
    Abstract: A method and apparatus for managing tool execution via roles on a computer system while maintaining computer system security, wherein the computer system comprises a plurality of roles, are disclosed. Such a method and apparatus may include delegating tools to a user based on a role, wherein a tool provides root access for performing a specific task in the computer system and the role is an authorized role that enables the user to run the delegated tools, identifying one of the plurality of roles to be disabled, wherein the identified role is the authorized role, accessing the identified role, and, disabling the identified role so that the user cannot run the delegated tool(s). Disabled roles may likewise be enabled according to a disclosed method and apparatus. Embodiments of the invention may comprise authorization objects that comprise attributes identifying the roles and machine for which a user is authorized.
    Type: Grant
    Filed: May 15, 2001
    Date of Patent: April 26, 2005
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Richard D. Harrah, Humberto A Sanchez, II, Jeffrey R. Finz, Mary Thomas Robb, Terence E. Lister, Paula B. Curtis, Douglas P. Drees
  • Patent number: 6795855
    Abstract: A service control manager (SCM) module may, through a light weight centraized authorization process, assign certain tools to a role so that a non-root user with such role may run the authorized commands specified in the tools as a root user. The usage of these commands is tracked and logged, typically by a log manager who observes each of the commands that are run within the role. If the non-root user tries to run a command that is not assigned to the role, the log manager may block that attempt. Therefore the lightweight authorization may be achieved without compromising security. The user may also be given a finer granularity of running specific commands and options. In addition, the non-root user with the role may only need to be authorized on one node (machine) to be able to perform the commands on multiple nodes.
    Type: Grant
    Filed: April 5, 2001
    Date of Patent: September 21, 2004
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Carlos A. Bonilla, Douglas P. Drees, Mary Thomas Robb, Jeffrey R. Finz, Terence E. Lister, Humberto A. Sanchez, II, Paula Curtis, Richard Dale Harrah
  • Publication number: 20020178297
    Abstract: A service control manager (SCM) tool execution mechanism enables SCM users to execute SCM tools across a set of defined distributed nodes (systems). It provides a secure mechanism, referred to a distributed task facility (DTF), to integrate different operations and execute the operations across the set of distributed nodes.
    Type: Application
    Filed: March 20, 2001
    Publication date: November 28, 2002
    Inventors: Terence E. Lister, Humberto A. Sanchez, Douglas P. Drees, Jeffrey R. Finz
  • Publication number: 20020174256
    Abstract: A service control manager (SCM) module may, through a light weight centraized authorization process, assign certain tools to a role so that a non-root user with such role may run the authorized commands specified in the tools as a root user. The usage of these commands is tracked and logged, typically by a log manager who observes each of the commands that are run within the role. If the non-root user tries to run a command that is not assigned to the role, the log manager may block that attempt. Therefore the lightweight authorization may be achieved without compromising security. The user may also be given a finer granularity of running specific commands and options. In addition, the non-root user with the role may only need to be authorized on one node (machine) to be able to perform the commands on multiple nodes.
    Type: Application
    Filed: April 5, 2001
    Publication date: November 21, 2002
    Inventors: Carlos A. Bonilla, Douglas P. Drees, Mary Thomas Robb, Jeffrey R. Finz, Terence E. Lister, Humberto A. Sanchez, Paula Curtis, Richard Dale Harrah
  • Publication number: 20020174333
    Abstract: A method and apparatus for managing tool execution via roles on a computer system while maintaining computer system security, wherein the computer system comprises a plurality of roles, are disclosed. Such a method and apparatus may include delegating tools to a user based on a role, wherein a tool provides root access for performing a specific task in the computer system and the role is an authorized role that enables the user to run the delegated tools, identifying one of the plurality of roles to be disabled, wherein the identified role is the authorized role, accessing the identified role, and, disabling the identified role so that the user cannot run the delegated tool(s). Disabled roles may likewise be enabled according to a disclosed method and apparatus. Embodiments of the invention may comprise authorization objects that comprise attributes identifying the roles and machine for which a user is authorized.
    Type: Application
    Filed: May 15, 2001
    Publication date: November 21, 2002
    Inventors: Richard D. Harrah, Humberto A. Sanchez, Jeffrey R. Finz, Mary Thomas Robb, Terence E. Lister, Paula B. Curtis, Douglas P. Drees
  • Publication number: 20020169956
    Abstract: A method and apparatus for delegating root access to non-root users of a computer system while maintaining computer system security are disclosed. Such a method may include authorizing a role for a user, wherein the authorized role includes one or more tools and the tools enable root access for certain tasks that the tools perform when run, whereby the one or more tools are delegated to the user and authorizing a machine of the computer system for the authorized role, wherein the computer system comprises a plurality of machines and the user is enabled to utilize the authorized role only on authorized machines, whereby utilizing the authorized role comprises running the one or more tools of the authorized role. Embodiments of the invention may comprise authorization objects that comprise attributes identifying a user and the roles and machine for which the user is authorized.
    Type: Application
    Filed: May 8, 2001
    Publication date: November 14, 2002
    Inventors: Mary Thomas Robb, Richard D. Harrah, Jeffrey R. Finz, Humberto A. Sanchez, Douglas P. Drees, Terence E. Lister, Paula Curtis