Patents by Inventor John Kling

John Kling has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11283838
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Grant
    Filed: November 25, 2019
    Date of Patent: March 22, 2022
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 10846382
    Abstract: Systems and methods are provided for monitoring access of computing resources. Usage rules may be created and stored that define a usage constraint based on actions available to be performed at the computing resources. An authenticator may verify login credentials received from a user and authorize the user to access a computing resource. A request to perform an action at the computing resource may be received, and a usage monitor may apply a usage rule to the requested action. If the requested action violates the usage constraint of the usage rule, the usage monitor may halt performance of the requested action and notify another user of the usage constraint violation. The authenticator may receive and verify another set of login credentials from that other user. In response to successful verification of the additional set of login credentials, the usage monitor may resume performance of the requested action.
    Type: Grant
    Filed: June 24, 2019
    Date of Patent: November 24, 2020
    Assignee: Bank of America Corporation
    Inventors: Armen Moloian, John Kling
  • Publication number: 20200099724
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Application
    Filed: November 25, 2019
    Publication date: March 26, 2020
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 10491633
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Grant
    Filed: January 25, 2017
    Date of Patent: November 26, 2019
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Publication number: 20190311093
    Abstract: Systems and methods are provided for monitoring access of computing resources. Usage rules may be created and stored that define a usage constraint based on actions available to be performed at the computing resources. An authenticator may verify login credentials received from a user and authorize the user to access a computing resource. A request to perform an action at the computing resource may be received, and a usage monitor may apply a usage rule to the requested action. If the requested action violates the usage constraint of the usage rule, the usage monitor may halt performance of the requested action and notify another user of the usage constraint violation. The authenticator may receive and verify another set of login credentials from that other user. In response to successful verification of the additional set of login credentials, the usage monitor may resume performance of the requested action.
    Type: Application
    Filed: June 24, 2019
    Publication date: October 10, 2019
    Inventors: Armen Moloian, John Kling
  • Publication number: 20170134435
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Application
    Filed: January 25, 2017
    Publication date: May 11, 2017
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 9558334
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Grant
    Filed: October 9, 2015
    Date of Patent: January 31, 2017
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 9536070
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Grant
    Filed: March 8, 2016
    Date of Patent: January 3, 2017
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 9529989
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Grant
    Filed: March 8, 2016
    Date of Patent: December 27, 2016
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 9495380
    Abstract: Systems and methods of conducting access reviews of access rights to logical computing resources are provided. An access reviewer may receive a selection indicating a user having access to one or more logical computing resources of a computer system. The access reviewer may identify a set of current logical computing resources that the user has access to and a set of current logical entitlements associated with the user. The access reviewer may generate an access review summary based on a comparison of the current logical computing resources to one or more of the current logical entitlements.
    Type: Grant
    Filed: July 18, 2013
    Date of Patent: November 15, 2016
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 9489390
    Abstract: Systems and methods for reconciling access rights provisioned for physical computing resources of a computer system are provided. A reconciler may identify current physical computing resources accessible to a user account of the computer system and a physical entitlement specification associated with the user account. The reconciler may determine whether adjustment of access rights is needed based on a comparison of the current physical computing resources to the physical entitlement specification. Access rights to at least one physical computing resource may be adjusted in response to a determination that adjustment of access rights is needed.
    Type: Grant
    Filed: July 18, 2013
    Date of Patent: November 8, 2016
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 9483488
    Abstract: Systems and methods of verifying separation-of-duties (SoD) for requested access rights to physical computing resources are provided. An SoD verifier may receive and access request and obtain a set of current permissions associated with a requestee specified in the access request. The SoD verifier may also obtain a set of new permissions to provision for the requestee based on the access request. The SoD verifier may determine whether one of the current permissions is incompatible with one of the new permissions. The SoD verifier may provide an indication of whether the access request represents an SoD violation.
    Type: Grant
    Filed: July 18, 2013
    Date of Patent: November 1, 2016
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Publication number: 20160224770
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Application
    Filed: March 8, 2016
    Publication date: August 4, 2016
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Publication number: 20160191536
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Application
    Filed: March 8, 2016
    Publication date: June 30, 2016
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Publication number: 20160036827
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Application
    Filed: October 9, 2015
    Publication date: February 4, 2016
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Patent number: 9189644
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Grant
    Filed: July 18, 2013
    Date of Patent: November 17, 2015
    Assignee: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Publication number: 20140181912
    Abstract: Systems and methods of conducting access reviews of access rights to logical computing resources are provided. An access reviewer may receive a selection indicating a user having access to one or more logical computing resources of a computer system. The access reviewer may identify a set of current logical computing resources that the user has access to and a set of current logical entitlements associated with the user. The access reviewer may generate an access review summary based on a comparison of the current logical computing resources to one or more of the current logical entitlements.
    Type: Application
    Filed: July 18, 2013
    Publication date: June 26, 2014
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Publication number: 20140181914
    Abstract: Systems and methods for reconciling access rights provisioned for physical computing resources of a computer system are provided. A reconciler may identify current physical computing resources accessible to a user account of the computer system and a physical entitlement specification associated with the user account. The reconciler may determine whether adjustment of access rights is needed based on a comparison of the current physical computing resources to the physical entitlement specification. Access rights to at least one physical computing resource may be adjusted in response to a determination that adjustment of access rights is needed.
    Type: Application
    Filed: July 18, 2013
    Publication date: June 26, 2014
    Applicant: Bank of America Corporation
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Publication number: 20140181965
    Abstract: Systems and methods are provided for provisioning access rights to physical computing resources using an IAM system implementing an IAM data model. The IAM data model may identify logical and physical computing resources. An access request handler may receive an access request and identify a set of logical permissions based on the access request. The access request handler may derive a set of logical entitlements based on the set of logical permissions. An entitlement translator may translate the set of logical entitlements to a physical entitlement specification based on a set of physical permission specifications associated with the set of logical permissions. A physical permission specification may be obtained by mapping a logical permission to one or more physical permissions. An access control manager may then provision access rights to at least one physical computing resource indicated in the physical entitlement specification.
    Type: Application
    Filed: July 18, 2013
    Publication date: June 26, 2014
    Inventors: John Kling, Bryan Thompson, Ward Green
  • Publication number: 20140181913
    Abstract: Systems and methods of verifying separation-of-duties (SoD) for requested access rights to physical computing resources are provided. An SoD verifier may receive and access request and obtain a set of current permissions associated with a requestee specified in the access request. The SoD verifier may also obtain a set of new permissions to provision for the requestee based on the access request. The SoD verifier may determine whether one of the current permissions is incompatible with one of the new permissions. The SoD verifier may provide an indication of whether the access request represents an SoD violation.
    Type: Application
    Filed: July 18, 2013
    Publication date: June 26, 2014
    Inventors: John Kling, Bryan Thompson, Ward Green