IP Library Granted Patent US 6,871,279
Granted Patent B2
US 6,871,279 · App. 09/813,419 · Granted Mar 22, 2005

Method and apparatus for securely and dynamically managing user roles in a distributed system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,871,279
App. No.
09/813,419
Granted
Mar 22, 2005
Kind
B2
Abstract

One embodiment of the present invention provides a system for managing user attributes that determines access rights in a distributed computing system. The system modifies an attribute database, wherein the attribute database includes a plurality of possible user attributes and a plurality of users. Next, for a given user the system obtains an identity certificate from a certificate authority. This identity certificate is associated with a user from the attribute database. The system also assigns an attribute to the user from the possible user attributes, whereby the user is granted access rights based on the attribute and the identity certificate. This attribute is stored in the attribute database. Finally, modifications to the attribute database are distributed to a plurality of hosts coupled together by a network.

Claims (57)

1. A method for managing user attributes in a distributed computing system, wherein user attributes determine access rights to a computer application: the method comprising:

modifying an attribute database in order to create modifications, wherein the attribute database includes a plurality of possible user attributes and a data structure identifying a plurality of users;

obtaining an identity certificate from a certificate authority;

associating the identity certificate with a user from the plurality of users within the attribute database, thus creating more of the modifications;

assigning an attribute from the plurality of possible user attributes to the user;

storing the attribute assigned to the user into the attribute database, thus creating more of the modifications; and

distributing the modifications to the attribute database to a plurality of hosts coupled together by a networks;

wherein the user is granted access rights based on the attribute and the identity certificate.

2. The method of claim 1 , further comprising:

assigning a second attribute from the plurality of possible user attributes to the user, in addition to said attribute; and

storing the second attribute assigned to the user into the attribute database, thus creating more of the modifications.

3. The method of claim 1 , further comprising using secure communications when distributing the modifications to the attribute database to the plurality of hosts.

4. The method of claim 1 , further comprising signing the attribute database with a cryptographic signature prior to the distributing to allow detection of unauthorized changes to the attribute database.

5. The method of claim 1 , wherein a host of the plurality of hosts can distribute the modifications to the attribute database to a subordinate host in a tree architecture.

6. The method of claim 1 , further comprising allowing the user to assume any attribute stored into the attribute database that is assigned to the user during the assigning.

7. The method of claim 1 , further comprising:

deleting the attribute assigned to the user from the attribute database, after the distributing, thus creating more of the modifications; and

redistributing the modifications to the attribute database to the plurality of hosts.

8. The method of claim 1 , wherein modifying the attribute database includes creating the attribute database.

9. A computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for managing user attributes in a distributed computing system, wherein user attributes determine access rights to a computer application: the method comprising:

modifying an attribute database in order to create modifications, wherein the attribute database includes a data structure identifying a plurality of possible user attributes and a plurality of users;

obtaining an identity certificate from a certificate authority;

associating the identity certificate with a user from the plurality of users within the attribute database, thus creating more of the modifications;

assigning an attribute from the plurality of possible user attributes to the user;

storing the attribute assigned to the user into the attribute database, thus creating more of the modifications; and

distributing the modifications to the attribute database to a plurality of hosts coupled together by a network;

wherein the user is granted access rights based on the attribute and the identity certificate.

10. The computer-readable storage medium of claim 9 , the method further comprising:

assigning a second attribute from the plurality of possible user attributes to the user, in addition to said attribute; and

storing the second attribute assigned to the user into the attribute database, thus creating more of the modifications.

11. The computer-readable storage medium of claim 9 , the method further comprising using secure communications when distributing the modifications to the attribute database to the plurality of hosts.

12. The computer-readable storage medium of claim 9 , the method further comprising signing the attribute database with a cryptographic signature prior to the distributing to allow detection of unauthorized changes to the attribute database.

13. The computer-readable storage medium of claim 9 , wherein a host of the plurality of hosts can distribute the modifications to the attribute database to a subordinate host in a tree architecture.

14. The computer-readable storage medium of claim 9 , the method further comprising allowing the user to assume any attribute stored into the attribute database that is assigned to the user during the assigning.

15. The computer-readable storage medium of claim 9 , the method further comprising:

deleting the attribute assigned to the user from the attribute database, after the distributing, thus creating more of the modifications; and

redistributing the modifications to the attribute database to the plurality of hosts.

16. The computer-readable storage medium of claim 9 , wherein modifying the attribute database includes creating the attribute database.

17. An apparatus that facilitates managing user attributes in a distributed computing system, wherein user attributes determine access rights to a computer application: the apparatus comprising:

a modifying mechanism configured to modify an attribute database in order to create modifications, wherein the attribute database includes a data structure identifying a plurality of possible user attributes and a plurality of users;

an identity certificate obtaining mechanism configured to obtain an identity certificate from a certificate authority;

an associating mechanism configured to associated the identity certificate with a user from the plurality of users within the attribute database, thus creating more of the modifications;

an assigning mechanism configured to assign an attribute from the plurality of possible user attributes to the user;

a storing mechanism configured to store the attribute assigned to the user into the attribute database, thus creating more of the modifications; and

a distributing mechanism that is configured to distribute the modifications to the attribute database to a plurality of hosts coupled together by a network;

wherein the user is granted access rights based on the attribute and the identity certificate.

18. The apparatus of claim 17 , further comprising:

the assigning mechanism that is further configured to assign a second attribute from the plurality of possible user attributes to the user, in addition to said attribute; and

the storing mechanism that is further configured to store the second attribute assigned to the user into the attribute database, thus creating more of the modifications.

19. The apparatus of claim 17 , further comprising a secure communications mechanism configured to distribute the modifications to the attribute database to the plurality of hosts, during the distributing.

20. The apparatus of claim 17 , further comprising a signing mechanism that is configured to sign the attribute database with a cryptographic signature prior to the distributing to allow detection of unauthorized changes to the attribute database.

21. The apparatus of claim 17 , wherein the communications mechanism associated with a host of the plurality of hosts is configured to distribute the modifications to the attribute database to a subordinate host in a tree architecture.

22. The apparatus of claim 17 , further comprising an authorization mechanism that is configured to authorize the user to assume any attribute stored into the attribute database that is assigned to the user during the assigning.

23. The apparatus of claim 17 , further comprising:

a deleting mechanism that as configured to delete the attribute assigned to the user from the attribute database, after the distributing, thus creating more of the modifications; and

a redistributing mechanism that is configured to redistribute the modifications to the attribute database to the plurality of hosts.

24. The apparatus of claim 17 , wherein the modifying mechanism is further configured to create the attribute database.

Assignments (15)
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Sep 18, 2007
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: MCAFEE, INC.
Reel/Frame 019843/0441 →
CONFIRMATORY LICENSE Recorded Feb 6, 2004
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: UNITED STATES AIR FORCE
Reel/Frame 014952/0093 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME, PREVIOUSLY RECORDED AT REEL 011633 FRAME 0779. Recorded Oct 4, 2001
From: SAMES, DAVID L.; TALLY, GREGG W.
To: NETWORKS ASSOCIATES TECHNOLOGY, INC.
Reel/Frame 012233/0455 →