IP Library Granted Patent US 8,601,539
Granted Patent B1
US 8,601,539 · App. 11/850,561 · Granted Dec 3, 2013

Systems and methods for managing user permissions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,601,539
App. No.
11/850,561
Granted
Dec 3, 2013
Kind
B1
Abstract

Multi-tiered systems and methods for identifying and monitoring user permissions in a computer network are described. A data structure, such as an index, for each network device identifies all the security identifiers (SIDs) and their associated permissions for accessing the resources on the network device. Each data structure can be initially populated by scanning access control lists (ACLs) of the respective network device. A collection server in communication with the network devices stores an aggregate index that identifies the SIDs in the network and the network devices on which each SID is granted, denied or revoked one or more permissions. The individual data structures and/or aggregate index are updated based on permission changes detected through real-time or periodic monitoring. The aggregate index can also be replicated to multiple servers. In certain examples, the multi-tiered arrangement facilitates identifying the network resources for which a user has been granted, denied or revoked a permission.

Claims (51)

1. A system for managing user permissions in a computer network environment, the system comprising:

a collection server;

a first computing device of a plurality of network devices communicatively coupled to the collection server, the first computing device comprising:

a first resource,

a first data structure associated with the first resource, the first data structure identifying a first security identifier (SID) associated with at least a first user of the first computing device, the first data structure further comprising a first permission granted to the first SID with respect to the first resource,

a second resource,

a second data structure associated with the second resource, the second data structure identifying a second SID associated with at least a second user of the first computing device, the second data structure further comprising a second permission granted to the second SID with respect to the second resource, and

an at least two-tier distributed index structure comprising an aggregate index stored on the collection server, the aggregate index associating each of the first and second SIDs with the first computing device and the associated first and second users but not associating the first and second SIDs with the first and second resources, and a first SID index stored on the first computing device, the first SID index associating the first and second SIDs with, respectively, the first and second resources, the aggregate index further associating a third SID associated with at least a third user of a second computing device of the plurality of network devices;

an agent module that monitors the first and second resources to determine changes in the first and second permissions, wherein upon detecting a change to the first and second permissions, the agent module is configured to update the first SID index, and wherein the agent module is further configured to transmit incremental information about the change to the aggregate index; and

a user interface that displays the names of multiple computing devices, names of users and SIDs associated therewith, and permissions associated with resources stored in the aggregate index.

2. The system of claim 1 , wherein the second computing device comprises:

a third resource;

a third data structure associated with the third resource, the third data structure identifying the third SID and a third permission granted to the third SID with respect to the third resource;

a fourth resource;

a fourth data structure associated with the fourth resource, the fourth data structure identifying a fourth SID and a fourth permission granted to the fourth SID with respect to the fourth resource; and

a second SID index associating the third and fourth SIDs with, respectively, the third and fourth resources,

wherein the aggregate index further associates the fourth SID with the second computing device.

3. The system of claim 2 , wherein the first, second, third and fourth data structures each comprises an access control list (ACL).

4. The system of claim 1 , wherein at least one of the first and second SIDs comprises a group SID.

5. The system of claim 1 , further comprising:

a third device of the plurality of network devices; and

a fifth data structure associated with the third device, the fifth data structure identifying a fifth SID and a fifth permission granted to the fifth SID with respect to the third device, wherein the fifth data structure is stored on one of the plurality of network devices other than the third device.

6. The system of claim 5 , wherein the third device does not include an operating system.

7. The system of claim 6 , wherein the third device comprises an attached storage device.

8. The system of claim 1 , wherein the aggregate index further identifies a type of the first resource associated with the first SID.

9. A method for managing user permissions in a network system, the method comprising:

for each of a plurality of computing devices of a network system:

scanning a plurality of data structures, each data structure being associated with at least one of a plurality of resources on the computing device,

identifying from the plurality of data structures a plurality of security identifiers (SIDs) associated with a plurality of users of the computing devices, and further associated with a plurality of permissions granted to the plurality of SIDs with respect to the plurality of resources, and

compiling a first SID index for each computing device associating the plurality of SIDs with the plurality of resources and the plurality of users;

transmitting from each of the plurality of computing devices the respective plurality of SIDs and an identification of the corresponding computing device; and

compiling at a collection server an aggregate index associating each of the plurality of SIDs with the identification of the corresponding computing device on which the particular SID was found and the plurality of users associated therewith, wherein the aggregate index lacks sufficient information to directly associate SIDs with resources;

monitoring the computing devices determine changes in the permissions, wherein upon detecting a change to the permissions updating the first SID index;

transmitting incremental information about the changes to the aggregate index; and

displaying with a user interface, the names of multiple computing devices, names of users, and SIDS associated therewith, and the associated permissions stored in the aggregate index.

10. The method of claim 9 , wherein each of the plurality of data structures comprises a plurality of entries, wherein each data structure entry consists essentially of one of the plurality of SIDs and an identification of one of the plurality of resources.

11. The method of claim 10 , wherein the aggregate index comprises a plurality of entries, wherein each aggregate index entry consists essentially of one of the plurality of SIDs and the identification of the corresponding computing device on which the particular SID was found.

12. The method of claim 9 , additionally comprising monitoring changes in permissions of the plurality of resources on each of the plurality of computing devices.

13. The method of claim 12 , additionally comprising determining if the changes in permissions affect the existence of one of the plurality of SIDs on one of the plurality of computing devices.

14. The method of claim 9 , wherein one of the plurality of SIDs identified in the aggregate index is associated with multiple computing devices.

15. The method of claim 9 , additionally comprising replicating the aggregate index to a plurality of servers.

16. A multi-tiered system for managing user permissions on a plurality of network devices, the multi-tiered system comprising:

a plurality of computing devices, each computing device further comprising:

means for identifying from a plurality of data structures attached to a plurality of resources on the computing device a plurality of security identifiers (SIDs) associated with a plurality of users of the computing device, and further associated with a plurality of permissions granted to the plurality of SIDs for accessing the plurality of resources, and

first means for associating each of the plurality of SIDs with the plurality of resources and the plurality of users with a first SID index;

means for transmitting from each of the plurality of computing devices the respective plurality of SIDs and an identification of the corresponding computing device; and

second means for associating each of the plurality of SIDs with the identification of the corresponding computing device on which each particular SID was found; and

means for compiling an aggregate index associating each of the plurality of SIDs with the identification of the corresponding computing device on which the particular SID was found and the plurality of users associated therewith, wherein the aggregate index lacks sufficient information to directly associate SIDs with resources;

means for monitoring changes in the plurality of permissions and for updating said first and second means for associating;

means for transmitting incremental information about the changes to the aggregate index; and

means for displaying the names of multiple computing devices, names of users, and SIDs associated therewith, and the associated permissions stored in the aggregate index.

Assignments (31)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 70194 FRAME 888. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 27, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTITY SOFTWARE INTERNATIONAL DAC
Reel/Frame 070678/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2025
From: QUEST SOFTWARE INC.
To: ONE IDENTIFY SOFTWARE INTERNATIONAL DAC
Reel/Frame 070194/0888 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CHANGE OF NAME Recorded Sep 11, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 043811/0564 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
CHANGE OF NAME Recorded Aug 19, 2013
From: QUEST SOFTWARE, INC.
To: DELL SOFTWARE INC.
Reel/Frame 031035/0914 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Sep 28, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC (FORMERLY KNOWN AS WELLS FARGO FOOTHILL, LLC)
To: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
Reel/Frame 029050/0679 →
PATENT SECURITY AGREEMENT Recorded Feb 18, 2009
From: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
To: WELLS FARGO FOOTHILL, LLC
Reel/Frame 022277/0091 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2007
From: BOBEL, ROBERT
To: QUEST SOFTWARE, INC.
Reel/Frame 020106/0857 →