IP Library Granted Patent US 6,944,777
Granted Patent B1
US 6,944,777 · App. 09/594,869 · Granted Sep 13, 2005

System and method for controlling access to resources in a distributed environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,944,777
App. No.
09/594,869
Granted
Sep 13, 2005
Kind
B1
Abstract

A distributed access controller for controlling access to resources in a multi-domain distributed computing environment. The access controller is configured to receive a request from a user requesting performance of one or more operations on a particular resource. The access controller attempts to resolve the requested operations based on user hierarchy information and access list information for the particular resource. If all the operations in the user's request cannot be resolved based on the user hierarchy information and the access list information for the particular resource, the access controller then attempts to resolve the unresolved operations based on the particular user's user hierarchy information in combination with resource hierarchy information, and access list information for the resources in the resource hierarchy information. In alternate embodiments, the access controller attempts to resolve the requested operations based on the resource hierarchy information and access list information for the resources in the resource hierarchy information. If all the operations in the user's request cannot be resolved based on the resource hierarchy information and the access list information for the resources in the resource hierarchy information, the access controller then attempts to resolve the unresolved operations based on the resource hierarchy information in combination with the particular user's user hierarchy information, and the access list information for the resources in the resource hierarchy information.

Claims (34)

1. A computer implemented method for determining if a particular user is authorized to perform an operation on a particular resource, the method comprising:

providing resource hierarchy information describing hierarchical relationships between the particular resource and the particular resource's ancestor resources;

providing access list information for the resources in the resource hierarchy information; and

determining if a permission is asserted for the operation based on the resource hierarchy information and access list information for the resources in the resource hierarchy information;

wherein determining if the permission is asserted for the operation based on the resource hierarchy information and the access list information for the resources in the resource hierarchy information comprises:

(a) initializing a first resource collection to include the particular resource;

(b) determining if the permission is asserted for the operation in the access list information of the members of the first collection for the particular user;

(c) if the permission is not asserted, initializing a second resource collection to include only members of the first collection, and reinitializing the first resource collection, based on the resource hierarchy information, to include only parents of the members in the second resource collection;

(d) if the permission is not asserted, repeating steps (b) and (c) while the permission is not asserted and the first resource collection includes at least one ancestor resource of the particular resource; and

(e) if the permission is asserted, attributing the permission to the particular user for the operation to be performed on the particular resource.

2. The method of claim 1 wherein the permission for the operation is a positive permission indicating that the particular user is authorized to perform the operation on the particular resource, or a negative permission indicating that the particular user is prohibited from performing the operation on the particular resource.

3. The method of claim 1 wherein the access list information for the resources includes information indicating operations which can be performed on the resources, users which can perform operations on the resources, and permissions for the users and operations.

4. The method of claim 1 wherein determining if the permission has been asserted for the operation based on the resource hierarchy information and the access list information for the resources in the resource hierarchy information comprises:

determining if the permission is asserted for the operation in the access list information of the particular resource for the particular user;

if the permission is not asserted:

determining ancestor resources of the particular resource from the resource hierarchy information;

determining if the permission is asserted for the operation in the access list information of the ancestor resources for the particular user; and

if the permission is asserted for the operation in the access list information of the ancestor resources for the particular user, attributing the permission to the particular user for the operation to be performed on the particular resource; and

if the permission has been set for the user for the operation in the access list information of the particular resource, attributing the permission to the particular user for the operation to be performed on the particular resource.

5. The method of claim 1 further comprising:

if it cannot be determined if the permission is asserted based on the resource hierarchy information and the access list information of the resources in the resource hierarchy information;

providing user hierarchy information for the particular user, the user hierarchy information comprising information on hierarchical relationships between principals which include the particular user and the user's ancestors; and

determining if the permission has been asserted for the operation based on the user hierarchy information, the resource hierarchy information, and the access list information for the resources in the resource hierarchy information.

6. The method of claim 5 wherein determining if the permission is asserted for the operation based on the user hierarchy information, the resource hierarchy information, and access list information for the resources in the resource hierarchy information comprises:

determining ancestors of the particular user from the user hierarchy information;

determining if the permission is asserted for the operation in the access list information of the particular resource and ancestor resources of the particular for ancestors of the particular user; and

if the permission is asserted, attributing the permission to the particular user for the operation to be performed on the particular resource.

7. The method of claim 5 wherein determining if the permission is asserted for the operation based on the user hierarchy information, the resource hierarchy information, and access list information for the resources in the resource hierarchy information comprises:

(a) initializing a first variable to indicate a first user level;

(b) determining ancestors of the particular user from the resource hierarchy information at a level indicated by the first variable;

(c) determining if the permission is asserted for the operation in the access list information of the resources in the resource hierarchy information for the ancestor of the particular user determined in (b);

(d) if the permission is not asserted, incrementing the first variable by one user level;

(e) repeating (b), (c), and (d) while the permission is not asserted and the user hierarchy information comprises ancestors of the particular user at the level indicated by the first variable; and

(f) if the permission is asserted, attributing the permission to the particular user for the operation to be performed on the particular resource.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded May 29, 2020
From: BANK OF AMERICA, N.A.
To: LAWSON SOFTWARE, INC.; INFOR GLOBAL SOLUTIONS (MICHIGAN), INC.; INFOR (US), INC.; GT NEXUS, INC.
Reel/Frame 053314/0436 →
RELEASE OF SECURITY INTEREST Recorded Mar 5, 2019
From: WILMINGTON TRUST, NATIONAL ASSOCIATION
To: INFOR (US), INC.
Reel/Frame 048510/0349 →
CORRECTIVE ASSIGNMENT TO REMOVE THE INCORRECT PATENT NUMBER 6617869 AND REPLACE PATENT NUMBER 6617969 PREVIOUSLY RECORDED AT REEL: 036500 FRAME: 0896. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT. Recorded Sep 10, 2015
From: INFOR (US), INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 036585/0280 →
SECURITY AGREEMENT Recorded Aug 27, 2015
From: INFOR (US), INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 036500/0896 →