IP Library Granted Patent US 7,774,472
Granted Patent B2
US 7,774,472 · App. 11/878,290 · Granted Aug 10, 2010

System and method for cross-authoritative configuration management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,774,472
App. No.
11/878,290
Granted
Aug 10, 2010
Kind
B2
Abstract

A system and method for cross-authoritative, user-based network configuration management is provided. Users log-in to a network using any device coupled to the network, and an identity manager may provide the user with a custom computing environment by verifying the user's identity and identifying content, assignments, and other configuration information associated with the user. For instance, the identity manager may retrieve a unique identifier assigned to the user, query one or more authoritative source domains based on the unique identifier, and deliver a computing environment assigned to the user. By seamlessly integrating multiple authoritative sources, administrators can make assignments to users across multiple authoritative source domains, and queries to the sources will always be up-to-date without having to perform synchronization processes.

Claims (36)

1. A method for cross-authoritative configuration management, comprising:

integrating a plurality of authoritative sources with an identity manager that natively supports schemas used in the plurality of authoritative sources, wherein the identity manager integrated with the plurality of authoritative sources operates on a processor and provides a single point of control for managing assignments that define access rights across the plurality of authoritative sources;

determining the assignments that define the access rights for at least one of a plurality of users that are managed across the plurality of authoritative sources, wherein determining the assignments that define the access rights for the at least one user includes:

capturing, by the identity manager operating on the processor, identifiers for any directory objects assigned to the at least one user in the plurality of authoritative sources, wherein the directory objects assigned to the at least one user in the plurality of authoritative sources include the assignments that define the access rights for the at least one user across the plurality of authoritative sources;

retrieving, by the identity manager operating on the processor, a globally unique identifier assigned to the at least one user from a data repository coupled to the identity manager; and

storing, by the identity manager operating on the processor, the globally unique identifier assigned to the at least one user in a table that associates the globally unique identifier with the identifiers for the directory objects assigned to the at least one user in the plurality of authoritative sources; and

delivering a customized computing environment to the at least one user, wherein delivering the customized computing environment to the at least one user includes:

receiving, at the identity manager operating on the processor, a login request from a device in communication with the identity manager over a network, wherein the login request includes one or more credentials provided by the at least one user;

validating, by the identity manager operating on the processor, the one or more credentials included in the login request, wherein the identity manager queries at least one of the directory objects assigned to the at least one user in the plurality of authoritative sources to validate the one or more credentials included in the login request;

retrieving, by the identity manager operating on the processor and in response to validating the one or more credentials included in the login request, the assignments that define the access rights for the at least one user from the directory objects in the table that are assigned to the at least one user in the plurality of authoritative sources; and

delivering, by the identity manager operating on the processor and in response to validating the one or more credentials included in the login request, the customized computing environment to the device, wherein the customized computing environment delivered to the device includes the assignments in the directory objects in the table that are assigned to the at least one user.

2. The method of claim 1 , wherein the directory objects assigned to the at least one user in the plurality of authoritative sources further include one or more attributes associated with the at least one user, one or more attributes associated with one or more groups that include the at least one user, and one or more attributes associated with one or more containers that include the at least one user.

3. The method of claim 2 , wherein the directory objects assigned to the at least one user in the plurality of authoritative sources further include one or more assignments associated with the one or more groups and the one or more containers that include the at least one user, the assignments including one or more of software, policies, group memberships, content, or devices associated with the at least one user, the one or more groups that include the at least one user, and the one or more containers that include the at least one user.

4. The method of claim 2 , the attributes including one or more of e-mail addresses, names, locations, or descriptive information associated with the at least one user, the one or more groups that include the at least one user, and the one or more containers that include the at least one user.

5. The method of claim 3 , wherein at least one of the one or more groups that include the at least one user further include one or more other users, and wherein the at least one user and the one or more users in the group are managed by different ones of the plurality of authoritative sources.

6. The method of claim 1 , further comprising updating, by the identity manager operating on the processor, one or more of the identifiers for the directory objects in the table that are assigned to the at least one user in response to the identity manager detecting a change to the directory objects associated with the one or more identifiers in the plurality of authoritative sources.

7. The method of claim 3 , wherein the customized computing environment delivered to the device further includes the assignments in the directory objects assigned to the at least one user in the table that are associated with the one or more groups and the one or more containers that include the at least one user.

8. The method of claim 1 , wherein the identity manager formulates a Lightweight Directory Access Protocol query to capture the identifiers for the directory objects assigned to the at least one user in the plurality of authoritative sources.

9. A system for cross-authoritative configuration management, comprising:

a plurality of authoritative sources integrated with an identity manager that natively supports schemas used in the plurality of authoritative sources, wherein the identity manager integrated with the plurality of authoritative sources provides a single point of control for managing assignments that define access rights across the plurality of authoritative sources; and

a data repository coupled to the identity manager, wherein the data repository stores a globally unique identifier assigned to at least one of a plurality of users that are managed across the plurality of authoritative sources; and

one or more processors that execute the identity manager, wherein the one or more processors that execute the identity manager are configured to:

capture identifiers for any directory objects assigned to the at least one user in the plurality of authoritative sources, wherein the directory objects assigned to the at least one user in the plurality of authoritative sources include the assignments that define the access rights for the at least one user across the plurality of authoritative sources;

retrieve the globally unique identifier assigned to the at least one user from the data repository;

store the globally unique identifier assigned to the at least one user in a table that associates the globally unique identifier with the identifiers for the directory objects assigned to the at least one user in the plurality of authoritative sources;

receive a login request from a device in communication with the identity manager over a network, wherein the login request includes one or more credentials provided by the at least one user;

validate the one or more credentials included in the login request, wherein the identity manager queries at least one of the directory objects assigned to the at least one user in the plurality of authoritative sources to validate the one or more credentials included in the login request;

retrieve, in response to validating the one or more credentials included in the login request, the assignments that define the access rights for the at least one user from the directory objects in the table that are assigned to the at least one user in the plurality of authoritative sources; and

deliver, in response to validating the one or more credentials included in the login request, a customized computing environment to the device, wherein the customized computing environment delivered to the device includes the assignments in the directory objects in the table that are assigned to the at least one user.

10. The system of claim 9 , wherein the directory objects assigned to the at least one user in the plurality of authoritative sources further include one or more attributes associated with the at least one user, one or more attributes associated with one or more groups that include the at least one user, and one or more attributes associated with one or more containers that include the at least one user.

11. The system of claim 10 , wherein the directory objects assigned to the at least one user in the plurality of authoritative sources further include one or more assignments associated with the one or more groups and the one or more containers that include the at least one user, the assignments including one or more of software, policies, group memberships, content, or devices associated with the at least one user, the one or more groups that include the at least one user, and the one or more containers that include the at least one user.

12. The system of claim 10 , the attributes including one or more of e-mail addresses, names, locations, or descriptive information associated with the at least one user, the one or more groups that include the at least one user, and the one or more containers that include the at least one user.

13. The system of claim 11 , wherein at least one of the one or more groups that include the at least one user further include one or more other users, and wherein the at least one user and the one or more users in the group are managed by different ones of the plurality of authoritative sources.

14. The system of claim 9 , wherein the one or more processors that execute the identity manager are further configured to update one or more of the identifiers for the directory objects in the table that are assigned to the at least one user in response to the identity manager detecting a change to the directory objects associated with the one or more identifiers in the plurality of authoritative sources.

15. The system of claim 11 , wherein the customized computing environment delivered to the device further includes the assignments in the directory objects assigned to the at least one user in the table that are associated with the one or more groups and the one or more containers that include the at least one user.

16. The system of claim 9 , wherein the one or more processors that execute the identity manager formulate a Lightweight Directory Access Protocol query to capture the identifiers for the directory objects assigned to the at least one user in the plurality of authoritative sources.

Assignments (11)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2011
From: NOVELL, INC.
To: CPTN HOLDINGS, LLC
Reel/Frame 027169/0200 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2011
From: CPTN HOLDINGS LLC
To: EMC CORPORATON
Reel/Frame 027016/0160 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2007
From: TANNER, RONALD MARTIN; SORENSON, MATTHEW JOHN; CARLSON, RICK JAMES; LEWIS, DAVID EVANS
To: NOVELL, INC.
Reel/Frame 019653/0335 →