IP Library Granted Patent US 7,908,648
Granted Patent B2
US 7,908,648 · App. 12/378,497 · Granted Mar 15, 2011

Method and system for enabling remote access to a computer system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,908,648
App. No.
12/378,497
Granted
Mar 15, 2011
Kind
B2
Abstract

Method and systems configured for allowing a non-local remote user to access a computer system with a particular authorization level. Such access is facilitated by examining non-local directory services group memberships of the user and performing a mapping of the user's identity to a corresponding universal local user account that have the proper authorization level or levels. Such methods and systems allow any number of non-local remote users access to the computer system in such a way that the remote user assumes the identity of (i.e., is mapped to) a corresponding universal local user account of an appropriate privilege level. All non-local remote users that the computer system determines to be of the same privilege level will share the identity of the same universal local user account.

Claims (51)

1. A computer-implemented method for enabling a user to remotely access a computer system using an active shared directory account maintained on a different computer system, comprising:

facilitating authentication of the user of the computer system using only information derived from the shared directory account, wherein said facilitating authentication includes the computer system accessing the shared directory account on the different computer system;

determining that the user does not have a local account on the computer system in response to the computer system successfully authenticating the user thereby recognizing that the user is a non-local user with respect to the computer system; and

associating the user with a universal local user account of the computer system in response to the computer system successfully identifying a recognized group membership affiliation for the user that corresponds to said shared directory account such that the universal local user account is selected dependent upon said shared directory account and the recognized group membership affiliation.

2. The method of claim 1 wherein the universal local user account has access privilege on the computer system.

3. The method of claim 1 wherein said associating includes:

selecting the universal local user account of the computer system in response to successfully identifying the recognized group membership affiliation for the user that corresponds to the shared directory account.

4. The method of claim 3 wherein selecting the universal local user account of the computer system dependent upon said shared directory account includes determining at least one of directory services group membership information associated with said shared directory account and access privilege information associated with said shared directory account.

5. The method of claim 1 wherein said associating includes:

mapping the user to the universal local user account, wherein said mapping enables access to the computer system by the user in accordance with an access privilege level corresponding to the universal local user account.

6. The method of claim 1 wherein said selecting the universal user account includes correlating a universal local user account access level to a corresponding group membership of the user.

7. The method of claim 1 wherein:

the universal local user account is one of a plurality of universal local user accounts; and

each one of said universal local user accounts has a respective access privilege level associated therewith.

8. A computer system, comprising:

at least one data processing device;

instructions processable by said at least one data processing device; and

an apparatus from which said instructions are accessible by said at least one data processing device;

wherein said instructions are configured for enabling said at least one data processing device to facilitate:

facilitating authentication of a user remotely accessing a computer system using an active shared directory account maintained on a different computer system, wherein facilitating said authentication includes using only information derived from the shared directory account;

determining that the user does not have a local account on the computer system in response to successfully authenticating the user thereby recognizing that the user is a non-local user with respect to the computer system; and

associating the user with a universal local user account of the computer system in response to successfully identifying a recognized group membership affiliation for the user that corresponds to said shared directory account such that the universal local user account is selected dependent upon said shared directory account and the recognized group membership affiliation.

9. The computer system of claim 8 wherein:

the universal local user account has access privilege on the computer system; and

said facilitating authentication includes the computer system accessing said shared directory account on the different computer system.

10. The computer system of claim 8 wherein said associating includes:

selecting the universal local user account of the computer system in response to successfully identifying the recognized group membership affiliation for the user that corresponds to the shared directory account.

11. The computer system of claim 10 wherein selecting the universal local user account includes determining at least one of directory services group membership information associated with said shared directory account and access privilege information associated with said shared directory account.

12. The computer system of claim 10 wherein selecting the universal user account includes correlating a universal local user account access level to a corresponding group membership of the user.

13. The computer system of claim 8 wherein said associating includes:

mapping the user to the universal local user account, wherein said mapping enables access to the computer system by the user in accordance with an access privilege level corresponding to the universal local user account.

14. An apparatus, comprising:

an instruction storage device configured for being coupled to and accesses by a storage device accessing unit of a computer system, wherein the instruction storage device includes memory space configured for having instructions stored therein; and

instructions processable by at least one data processing device, wherein said instructions are stored in said memory space of the instruction storage device;

wherein said instructions are configured for causing at least one data processing device of the computer system to:

authenticate a user remotely accessing the computer system using an active shared directory account maintained on a different computer system, wherein causing said at least one data processing device of the computer system to authenticate the user includes using only information derived from a shared directory account, wherein causing said at least one data processing device to authenticate the user includes causing said at least one data processing device to access the shared directory account on the different computer system;

determine that the user does not have a local account on the computer system in response to the computer system successfully authenticating the user thereby recognizing that the user is a non-local user with respect to the computer system; and

associate the user with a universal local user account of the computer system in response to the computer system successfully identifying a recognized group membership affiliation for the user that corresponds to said shared directory account such that the universal local user account is selected dependent upon said shared directory account and the recognized group membership affiliation.

15. The apparatus of claim 14 wherein:

the universal local user account has access privilege on the computer system.

16. The apparatus of claim 14 wherein being configured for causing said at least one data processing device of the computer system to associate includes being configured for causing said at least one data processing device of the computer system to:

select the universal local user account of the computer system in response to successfully identifying the recognized group membership affiliation for the user that corresponds to the shared directory account.

17. The me apparatus of claim 14 wherein being configured for causing said at least one data processing device of the computer system to associate includes being configured for causing said at least one data processing device of the computer system to:

map the user to the universal local user account to enable access to the computer system by the user in accordance with an access privilege level corresponding to the universal local user account.

18. The apparatus of claim 14 wherein being configured for causing said at least one data processing device of the computer system to select includes being configured for causing said at least one data processing device of the computer system to:

correlate a universal local user account access level to a corresponding group membership of the user.

19. The apparatus of claim 14 wherein:

the universal local user account is one of a plurality of universal local user accounts;

each one of said universal local user accounts has a respective access privilege level associated therewith;

said instructions are further configured for causing said at least one processor of the computer system to create said universal local user accounts prior to performing said selecting; and

each one of said universal local user access accounts has a respective access privilege level associated therewith.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Jun 5, 2019
From: U.S. BANK NATIONAL ASSOCIATION, SOLELY AS NOTES COLLATERAL AGENT
To: SANMINA CORPORATION; HADCO CORPORATION; HADCO SANTA CLARA; SCI TECHNOLOGY; SENSORWISE, INC.
Reel/Frame 049378/0927 →
SECURITY INTEREST Recorded Aug 3, 2018
From: SANMINA CORPORATION
To: U.S. BANK NATIONAL ASSOCIATION, NOT IN ITS INDIVIDUAL CAPACITY BUT SOLELY AS NOTES COLLATERAL AGENT
Reel/Frame 046797/0063 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2018
From: MEMORY INTEGRITY, LLC
To: SANMINA CORPORATION
Reel/Frame 046249/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2013
From: SANMINA CORPORATION
To: MEMORY INTEGRITY, LLC
Reel/Frame 030585/0980 →
MERGER Recorded Nov 28, 2012
From: SANMINA-SCI CORPORATION
To: SANMINA CORPORATION
Reel/Frame 029368/0472 →
MERGER Recorded Jul 27, 2012
From: NEWISYS, INC.
To: SANMINA-SCI CORPORATION
Reel/Frame 028652/0891 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2012
From: ELLINGTON, JEREMY MARK
To: NEWISYS, INC.
Reel/Frame 028548/0001 →