Patents by Inventor Marc Graveline

Marc Graveline has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8478894
    Abstract: Method and system for centralized control of data transfers between a Web client and a Web application by receiving a response from the Web application. After determining an offending character is present, cloaking the response from the Web application to a request from a Web client, and sending the cloaked response to the Web client through a security product which otherwise rejects the offending character.
    Type: Grant
    Filed: July 21, 2005
    Date of Patent: July 2, 2013
    Assignee: International Business Machines Corporation
    Inventors: Patrick Roy, Marc Graveline, Ulf Viney
  • Patent number: 7805513
    Abstract: Method and system for dynamically checking an access control list during the data transfers between a client web browser and a web server. The method and system allow checking of access control list by an application firewall, independent from the web application. The rules, upon which the checking is based, can be easily updated without affecting the web application.
    Type: Grant
    Filed: October 31, 2008
    Date of Patent: September 28, 2010
    Assignee: International Business Machines Corporation
    Inventors: Marc Graveline, Ulf Viney, Matt Masson
  • Patent number: 7765310
    Abstract: Mechanisms for external and distributed protection of Web application data against prying, tampering, and impersonation using cryptographic mechanisms are provided. The protection is offered opaquely so as to not expose the cryptographic mechanism to the Web application. Protection against prying prevents users from looking at data the Web application considers private. When protected against prying, protect data may be sent to the client but the user will not be able to understand it. Protection against tampering, guaranties the Web application that the data it is receiving originated from a trusted source, usually the Web application itself. A user session state stored client-side is a good candidate for tampering protection. Protection against impersonation ensures the Web application that the data it is receiving comes from a specific user.
    Type: Grant
    Filed: July 22, 2005
    Date of Patent: July 27, 2010
    Assignee: International Business Machines Corporation
    Inventors: Marc Graveline, Patrick Roy, Ulf Viney
  • Publication number: 20090055905
    Abstract: Method and system for dynamically checking an access control list during the data transfers between a client web browser and a web server. The method and system allow checking of access control list by an application firewall, independent from the web application. The rules, upon which the checking is based, can be easily updated without affecting the web application.
    Type: Application
    Filed: October 31, 2008
    Publication date: February 26, 2009
    Applicant: COGNOS INCORPORATED
    Inventors: MARC GRAVELINE, ULF VINEY, MATT MASSON
  • Patent number: 7475138
    Abstract: Method for dynamically checking an access control list during the data transfers between a client web browser and a web server. The method allows checking of access control list by an application firewall, independent from the web application. The rules, upon which the checking is based, can be easily updated without affecting the web application.
    Type: Grant
    Filed: June 23, 2005
    Date of Patent: January 6, 2009
    Assignee: International Business Machines Corporation
    Inventors: Marc Graveline, Ulf Viney, Matt Masson
  • Patent number: 7428748
    Abstract: A system and method for permitting a user of a business intelligence reporting system to be authenticated against one or more logon IDs and concurrently using access rights associated with those logon IDs in a terminal session. The user in a single terminal session is allowed to access the system with one of the logon IDs, a first logon ID, which gives that user access rights to data sources (or authorities) related to the first logon ID. The user may then add or remove further access rights by logging on or off with subsequent logon IDs. Each subsequent logon ID gives that user additional access rights to data sources related to the subsequent logon IDs. No attempt is made to reduce the number or change the nature of these logon IDs.
    Type: Grant
    Filed: May 27, 2004
    Date of Patent: September 23, 2008
    Assignee: International Business Machines Corporation
    Inventors: Vincent Joseph Babineau, Christian Legault, Leo Paul Cormier, Marc Graveline
  • Publication number: 20070022210
    Abstract: Method and system for centralized control of data transfers between a Web client and a Web application by receiving a response from the Web application. After determining an offending character is present, cloaking the response from the Web application to a request from a Web client, and sending the cloaked response to the Web client through a security product which otherwise rejects the offending character.
    Type: Application
    Filed: July 21, 2005
    Publication date: January 25, 2007
    Inventors: Patrick Roy, Marc Graveline, Ulf Viney
  • Publication number: 20060294206
    Abstract: A method and a system for external and distributed protection of Web application data against prying, tempering, and impersonation using cryptographic mechanisms. The protection is offered opaquely so as to not expose the cryptographic mechanism to the Web application. Protection against prying prevents users from looking at data the Web application considers private. When protected against prying, protect data may be sent to the client but the user will not be able to understand it. Protection against tempering, guaranties the Web application that the data it is receiving originated from a trusted source, usually the Web application itself. A user session state stored client-side is a good candidate for tempering protection. Protection against impersonation ensures the Web application that the data it is receiving comes from a specific user.
    Type: Application
    Filed: July 22, 2005
    Publication date: December 28, 2006
    Inventors: Marc Graveline, Patrick Roy, Ulf Viney
  • Publication number: 20060294194
    Abstract: Method and system for dynamically checking an access control list during the data transfers between a client web browser and a web server. The method and system allow checking of access control list by an application firewall, independent from the web application. The rules, upon which the checking is based, can be easily updated without affecting the web application.
    Type: Application
    Filed: June 23, 2005
    Publication date: December 28, 2006
    Inventors: Marc Graveline, Ulf Viney, Matt Masson
  • Publication number: 20050278546
    Abstract: A system and method for permitting a user of a business intelligence reporting system to be authenticated against one or more logon IDs and concurrently using access rights associated with those logon IDs in a terminal session. The user in a single terminal session is allowed to access the system with one of the logon IDs, a first logon ID, which gives that user access rights to data sources (or authorities) related to the first logon ID. The user may then add or remove further access rights by logging on or off with subsequent logon IDs. Each subsequent logon ID gives that user additional access rights to data sources related to the subsequent logon IDs. No attempt is made to reduce the number or change the nature of these logon IDs.
    Type: Application
    Filed: May 27, 2004
    Publication date: December 15, 2005
    Inventors: Vincent Babineau, Christian Legault, Leo Cormier, Marc Graveline