Patents by Inventor Timothy Simon Bartley
Timothy Simon Bartley has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 9612641Abstract: An approach is provided that responds to a connection request to connect to an external network entity using a connection from a managed connection pool. The connection pool is managed by selecting connections from the connection pool that includes one or more currently unused connections with the external network entity. One of the selected connections is validated by comparing an idle time associated with each of the selected connections to a maximum idle time value corresponding to the external network entity. The maximum idle time value being previously identified at the information handling system. The validated connection is then used to connect to the external network entity to satisfy the connection request.Type: GrantFiled: November 17, 2010Date of Patent: April 4, 2017Assignee: International Business Machines CorporationInventors: Timothy Simon Bartley, Scott Anthony Exton
-
Patent number: 8196195Abstract: A computer implemented method, data processing system, and computer program product for role-based privilege management is provided. A transformation request is received from a requester to form a received request, and a target environment of the received request is identified. A determination is made whether the target environment matches a predefined environment in a set of role-based privileges and, responsive to a determination that the target environment matches a predefined environment in the set of role-based privileges, the parameterized privileges from the set of role-based privileges are mapped to the target environment and the request is performed.Type: GrantFiled: July 11, 2008Date of Patent: June 5, 2012Assignee: International Business Machines CorporationInventors: Timothy Simon Bartley, Peter T. Cogill, Elizabeth M. Hughes, Philip A. J. Nye, Michael Andrew Powell
-
Publication number: 20120124217Abstract: An approach is provided that responds to a connection request to connect to an external network entity using a connection from a managed connection pool. The connection pool is managed by selecting connections from the connection pool that includes one or more currently unused connections with the external network entity. One of the selected connections is validated by comparing an idle time associated with each of the selected connections to a maximum idle time value corresponding to the external network entity. The maximum idle time value being previously identified at the information handling system. The validated connection is then used to connect to the external network entity to satisfy the connection request.Type: ApplicationFiled: November 17, 2010Publication date: May 17, 2012Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATIONInventors: Timothy Simon Bartley, Scott Anthony Exton
-
Patent number: 8065724Abstract: An unattended computer-based machine is authenticated by the present invention method, system or apparatus. The subject machine may be an auto-restarted machine or similar machine configured to be unattended. Upon receipt of initializing input from a user at a subject computer-based machine, a working process authenticates the user and generates resulting credentials. The working process stores the generated credentials in a memory area of the subject machine. Separate from and independent of the working process is a security monitor of the present invention. A monitoring module of the present invention monitors user activity on the subject machine and upon detecting suspect activity destroys the stored credentials of the working process. Suspect activity includes any activity raising a suspicion of compromise.Type: GrantFiled: December 14, 2007Date of Patent: November 22, 2011Assignee: International Business Machines CorporationInventors: Peter Theodore Waltenberg, Kenneth Stephen, Timothy Simon Bartley
-
Publication number: 20100011438Abstract: In one embodiment, a computer implemented method for role-based privilege management is provided. The computer implemented method receives a transformation request from a requester to form a received request, and identifies a target environment of the received request. The computer implemented method determines whether the target environment matches a predefined environment in a set of role-based privileges and, responsive to a determination that the target environment matches a predefined environment in the set of role-based privileges, maps the parameterized privileges from the set of role-based privileges to the target environment and performs the request.Type: ApplicationFiled: July 11, 2008Publication date: January 14, 2010Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATIONInventors: Timothy Simon Bartley, Peter T. Cogill, Elizabeth M. Hughes, Philip A. J. Nye, Michael Andrew Powell
-
Publication number: 20090158389Abstract: An unattended computer-based machine is authenticated by the present invention method, system or apparatus. The subject machine may be an auto-restarted machine or similar machine configured to be unattended. Upon receipt of initializing input from a user at a subject computer-based machine, a working process authenticates the user and generates resulting credentials. The working process stores the generated credentials in a memory area of the subject machine. Separate from and independent of the working process is a security monitor of the present invention. A monitoring module of the present invention monitors user activity on the subject machine and upon detecting suspect activity destroys the stored credentials of the working process. Suspect activity includes any activity raising a suspicion of compromise.Type: ApplicationFiled: December 14, 2007Publication date: June 18, 2009Inventors: Peter Theodore Waltenberg, Kenneth Stephen, Timothy Simon Bartley
-
Patent number: 7454788Abstract: In this invention, when security policy is attached to a file, a device protection manager is given the protected file's name. If the file is a special device file, then the device manager records the device specification in a device database. When a device access occurs, the device specification is extracted from the special device file used in the access. This extracted device specification is then used to search the device database. If a matching device specification is found in the database and the accessed device file has the same name as the protected resource, then authorization policy rules on that resource determine the access. If the match is a different device file name from the protected file name for the same device, then the search continues until the exact accessed device is found or until all device specification matches are found.Type: GrantFiled: April 26, 2001Date of Patent: November 18, 2008Assignee: International Business Machines CorporationInventors: Rodney Carlton Burnett, Timothy Simon Bartley, Michael Powell
-
Patent number: 7260718Abstract: The method of the invention assumes there is a security manager and mechanism present for defining, attaching, and evaluating external authorization policy to file resources based on the file's path name. In this invention, protected symbolic links and the resources that the link points to are stored in a protected object database. When a system access attempt occurs, the file attribute is extracted from the file used in the access. The file attribute is then used to search the protected object database. If a matching system resource is found, and that resource is protected but does not have independent security policy on it, then the resource will have the security policy of a symbolic link that points to it. In this case, the security of each protected symbolic link pointing to the system resource has to grant access in order for allowance of the access attempt. This approach insures that the most restrictive outcome prevails.Type: GrantFiled: April 26, 2001Date of Patent: August 21, 2007Assignee: International Business Machines CorporationInventors: Rodney Carlton Burnett, Timothy Simon Bartley, Michael Powell
-
Patent number: 7191337Abstract: An apparatus and method for wildcarded security policy are implemented. These include associating wildcarded resource identifiers with a corresponding security policy. A resource identifier received in an access request is matched to one of a list of said wildcarded resource identifiers, Matching is determined in accordance with a predetermined set of precedence values, each precedence value of the set corresponding to a predetermined wildcard element.Type: GrantFiled: June 30, 2001Date of Patent: March 13, 2007Assignee: International Business Machines CorporationInventor: Timothy Simon Bartley
-
Patent number: 6928585Abstract: The present invention provides a method for detecting a termination of a process within a plurality of processes in a data processing system. A monitoring policy is established, within the plurality of processes, wherein the monitoring policy assigns a first process within the plurality of processes to monitor a second process within the plurality of processes. Responsive to a termination of execution of the second process, a cause of the execution termination is determined by the first process. Responsive to a determination that the second process terminated execution in an abnormal manner, the first process attempts to restart the second process. Furthermore, the present invention provides a method for inserting a process within a plurality of processes containing a first process and a monitoring policy in a data processing system. A request is received from a second process to join the plurality of processes.Type: GrantFiled: May 24, 2001Date of Patent: August 9, 2005Assignee: International Business Machines CorporationInventor: Timothy Simon Bartley
-
Publication number: 20030005307Abstract: An apparatus and method for wildcarded security policy are implemented. These include associating wildcarded resource identifiers with a corresponding security policy. A resource identifier received in an access request is matched to one of a list of said wildcarded resource identifiers, Matching is determined in accordance with a predetermined set of precedence values, each precedence value of the set corresponding to a predetermined wildcard element.Type: ApplicationFiled: June 30, 2001Publication date: January 2, 2003Applicant: International Business Machines CorporationInventor: Timothy Simon Bartley
-
Publication number: 20020184295Abstract: The present invention provides a method for detecting a termination of a process within a plurality of processes in a data processing system. A monitoring policy is established, within the plurality of processes, wherein the monitoring policy assigns a first process within the plurality of processes to monitor a second process within the plurality of processes. Responsive to a termination of execution of the second process, a cause of the execution termination is determined by the first process. Responsive to a determination that the second process terminated execution in an abnormal manner, the first process attempts to restart the second process. Furthermore, the present invention provides a method for inserting a process within a plurality of processes containing a first process and a monitoring policy in a data processing system. A request is received from a second process to join the plurality of processes.Type: ApplicationFiled: May 24, 2001Publication date: December 5, 2002Applicant: IBM CorporationInventor: Timothy Simon Bartley
-
Publication number: 20020162012Abstract: In this invention, when security policy is attached to a file, a device protection manager is given the protected file's name. If the file is a special device file, then the device manager records the device specification in a device database. When a device access occurs, the device specification is extracted from the special device file used in the access. This extracted device specification is then used to search the device database. If a matching device specification is found in the database and the accessed device file has the same name as the protected resource, then authorization policy rules on that resource determine the access. If the match is a different device file name from the protected file name for the same device, then the search continues until the exact accessed device is found or until all device specification matches are found.Type: ApplicationFiled: April 26, 2001Publication date: October 31, 2002Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATIONInventors: Rodney Carlton Burnett, Timothy Simon Bartley, Michael Powell
-
Publication number: 20020162013Abstract: The method of the invention assumes there is a security manager and mechanism present for defining, attaching, and evaluating external authorization policy to file resources based on the file's path name. In this invention, protected symbolic links and the resources that the link points to are stored in a protected object database. When a system access attempt occurs, the file attribute is extracted from the file used in the access. The file attribute is then used to search the protected object database. If a matching system resource is found, and that resource is protected but does not have independent security policy on it, then the resource will have the security policy of a symbolic link that points to it. In this case, the security of each protected symbolic link pointing to the system resource has to grant access in order for allowance of the access attempt. This approach insures that the most restrictive outcome prevails.Type: ApplicationFiled: April 26, 2001Publication date: October 31, 2002Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATIONInventors: Rodney Carlton Burnett, Timothy Simon Bartley, Michael Powell
-
Publication number: 20020078365Abstract: The present invention is an algorithm that manages the ability of an impersonator program to impersonate a user identity. This invention operates in the context of an external security manager. One aspect of the invention is a technique in which a security manager is used to control the security of an impersonator program and to allow that impersonator program's impersonated user to be represented as a user identity in that external security manager. A second aspect of the present invention is a technique that controls an impersonator program's ability to change its user identity. This invention will allow the specification of security policy to control which users an impersonator program can impersonate.Type: ApplicationFiled: December 15, 2000Publication date: June 20, 2002Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATIONInventors: Rodney Carl Burnett, Timothy Simon Bartley, Michael Powell