Patents by Inventor Jeffrey R. Finz
Jeffrey R. Finz has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 7093125Abstract: A method and apparatus for delegating root access to non-root users of a computer system while maintaining computer system security are disclosed. Such a method may include authorizing a role for a user, wherein the authorized role includes one or more tools and the tools enable root access for certain tasks that the tools perform when run, whereby the one or more tools are delegated to the user and authorizing a machine of the computer system for the authorized role, wherein the computer system comprises a plurality of machines and the user is enabled to utilize the authorized role only on authorized machines, whereby utilizing the authorized role comprises running the one or more tools of the authorized role. Embodiments of the invention may comprise authorization objects that comprise attributes identifying a user and the roles and machine for which the user is authorized.Type: GrantFiled: May 8, 2001Date of Patent: August 15, 2006Assignee: Hewlett-Packard Development Company, L.P.Inventors: Mary Thomas Robb, Richard D. Harrah, Jeffrey R. Finz, Humberto A. Sanchez, II, Douglas P. Drees, Terence E. Lister, Paula Curtis
-
Patent number: 7039917Abstract: A service control manager (SCM) tool execution mechanism enables SCM users to execute SCM tools across a set of defined distributed nodes (systems). It provides a secure mechanism, referred to a distributed task facility (DTF), to integrate different operations and execute the operations across the set of distributed nodes.Type: GrantFiled: March 20, 2001Date of Patent: May 2, 2006Assignee: Hewlett-Packard Development Company, L.P.Inventors: Terence E. Lister, Humberto A Sanchez, II, Douglas P. Drees, Jeffrey R. Finz
-
Patent number: 6886100Abstract: A method and apparatus for managing tool execution via roles on a computer system while maintaining computer system security, wherein the computer system comprises a plurality of roles, are disclosed. Such a method and apparatus may include delegating tools to a user based on a role, wherein a tool provides root access for performing a specific task in the computer system and the role is an authorized role that enables the user to run the delegated tools, identifying one of the plurality of roles to be disabled, wherein the identified role is the authorized role, accessing the identified role, and, disabling the identified role so that the user cannot run the delegated tool(s). Disabled roles may likewise be enabled according to a disclosed method and apparatus. Embodiments of the invention may comprise authorization objects that comprise attributes identifying the roles and machine for which a user is authorized.Type: GrantFiled: May 15, 2001Date of Patent: April 26, 2005Assignee: Hewlett-Packard Development Company, L.P.Inventors: Richard D. Harrah, Humberto A Sanchez, II, Jeffrey R. Finz, Mary Thomas Robb, Terence E. Lister, Paula B. Curtis, Douglas P. Drees
-
Patent number: 6795855Abstract: A service control manager (SCM) module may, through a light weight centraized authorization process, assign certain tools to a role so that a non-root user with such role may run the authorized commands specified in the tools as a root user. The usage of these commands is tracked and logged, typically by a log manager who observes each of the commands that are run within the role. If the non-root user tries to run a command that is not assigned to the role, the log manager may block that attempt. Therefore the lightweight authorization may be achieved without compromising security. The user may also be given a finer granularity of running specific commands and options. In addition, the non-root user with the role may only need to be authorized on one node (machine) to be able to perform the commands on multiple nodes.Type: GrantFiled: April 5, 2001Date of Patent: September 21, 2004Assignee: Hewlett-Packard Development Company, L.P.Inventors: Carlos A. Bonilla, Douglas P. Drees, Mary Thomas Robb, Jeffrey R. Finz, Terence E. Lister, Humberto A. Sanchez, II, Paula Curtis, Richard Dale Harrah
-
Publication number: 20020178297Abstract: A service control manager (SCM) tool execution mechanism enables SCM users to execute SCM tools across a set of defined distributed nodes (systems). It provides a secure mechanism, referred to a distributed task facility (DTF), to integrate different operations and execute the operations across the set of distributed nodes.Type: ApplicationFiled: March 20, 2001Publication date: November 28, 2002Inventors: Terence E. Lister, Humberto A. Sanchez, Douglas P. Drees, Jeffrey R. Finz
-
Publication number: 20020174333Abstract: A method and apparatus for managing tool execution via roles on a computer system while maintaining computer system security, wherein the computer system comprises a plurality of roles, are disclosed. Such a method and apparatus may include delegating tools to a user based on a role, wherein a tool provides root access for performing a specific task in the computer system and the role is an authorized role that enables the user to run the delegated tools, identifying one of the plurality of roles to be disabled, wherein the identified role is the authorized role, accessing the identified role, and, disabling the identified role so that the user cannot run the delegated tool(s). Disabled roles may likewise be enabled according to a disclosed method and apparatus. Embodiments of the invention may comprise authorization objects that comprise attributes identifying the roles and machine for which a user is authorized.Type: ApplicationFiled: May 15, 2001Publication date: November 21, 2002Inventors: Richard D. Harrah, Humberto A. Sanchez, Jeffrey R. Finz, Mary Thomas Robb, Terence E. Lister, Paula B. Curtis, Douglas P. Drees
-
Publication number: 20020174256Abstract: A service control manager (SCM) module may, through a light weight centraized authorization process, assign certain tools to a role so that a non-root user with such role may run the authorized commands specified in the tools as a root user. The usage of these commands is tracked and logged, typically by a log manager who observes each of the commands that are run within the role. If the non-root user tries to run a command that is not assigned to the role, the log manager may block that attempt. Therefore the lightweight authorization may be achieved without compromising security. The user may also be given a finer granularity of running specific commands and options. In addition, the non-root user with the role may only need to be authorized on one node (machine) to be able to perform the commands on multiple nodes.Type: ApplicationFiled: April 5, 2001Publication date: November 21, 2002Inventors: Carlos A. Bonilla, Douglas P. Drees, Mary Thomas Robb, Jeffrey R. Finz, Terence E. Lister, Humberto A. Sanchez, Paula Curtis, Richard Dale Harrah
-
Publication number: 20020169956Abstract: A method and apparatus for delegating root access to non-root users of a computer system while maintaining computer system security are disclosed. Such a method may include authorizing a role for a user, wherein the authorized role includes one or more tools and the tools enable root access for certain tasks that the tools perform when run, whereby the one or more tools are delegated to the user and authorizing a machine of the computer system for the authorized role, wherein the computer system comprises a plurality of machines and the user is enabled to utilize the authorized role only on authorized machines, whereby utilizing the authorized role comprises running the one or more tools of the authorized role. Embodiments of the invention may comprise authorization objects that comprise attributes identifying a user and the roles and machine for which the user is authorized.Type: ApplicationFiled: May 8, 2001Publication date: November 14, 2002Inventors: Mary Thomas Robb, Richard D. Harrah, Jeffrey R. Finz, Humberto A. Sanchez, Douglas P. Drees, Terence E. Lister, Paula Curtis