发明名称 System and method for secure management of mobile user access to network resources
摘要 A client-server system and method is provided for secure management of mobile user access to network resources from a wireless mobile device, such as a smart phone. A mobile access control layer resides between a wireless service provider network and host network, allowing for management of mobile access without overriding internal access policies. Access rules determining accessible resources and permitted operations are determined based on a user's group memberships, and optionally on other information received from the system, or from the mobile device, e.g. time or location. Each group is associated with a set of permitted accessible resources and operations, e.g. read or write access to a resource such as a file, list, shared calendar, et al. A list of accessible resources and permitted operations is generated, and the list is made available for subsequent processes, e.g. presented to the user for selection of an accessible resource and permitted operation.
申请公布号 US8798579(B2) 申请公布日期 2014.08.05
申请号 US201213625438 申请日期 2012.09.24
申请人 XE2 Ltd. 发明人 Hickie Thomas William
分类号 H04M1/66;H04M1/68;H04M3/16 主分类号 H04M1/66
代理机构 Hiscock & Barclay, LLP 代理人 Hiscock & Barclay, LLP
主权项 1. A method for managing secure mobile user access from a wireless mobile device via a wireless service provider network to a plurality of network resources of a host network, by steps comprising: in an access server comprising a mobile access control layer between the wireless service provider network and the host network, receiving, from a client of the wireless mobile device, a user request for mobile access; authenticating the user; determining group membership of the user based on a user ID and attributes of the user, each group having associated therewith a set of resources and associated operations for members of the group; determining access rules for the user based on each group membership of the user; generating a list of accessible resources and associated operations for the user based on said access rules; making said list available to a subsequent process for performing an operation on an accessible resource in accordance with said access rules, said operations on an accessible resource comprising one or more of displaying and otherwise interfacing said resource to the user for one or more of read, write, execute, modify, delete, email, download and synchronize operations.
地址 Surrey GB