IP Library Patent Application 12714234
Patent Application
App. No. 12/714,234

GROUP ACCESS CONTROL FOR A DISTRIBUTED SYSTEM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/714,234
Abstract

Briefly, embodiments of a method, apparatus or article for group access control of a distributed system are described.

Claims (43)

1 . A method, comprising:

electronically storing a group membership list for one or more accounts;

electronically storing a plurality of objects at different locations in a distributed computing system;

electronically storing a separate access control list for each of the plurality of objects, wherein searchable data defining each respective access control list for each respective object is embedded in or attached to the respective object, such that each respective access control list is located with its respective object at the different locations in the distributed computing system; and

electronically determining an intersection between said group membership list and the respective access control list for one of the plurality of objects to be accessed.

2 . The method of claim 1 , wherein said electronically storing a group membership list for one or more accounts comprises electronically storing a group membership list for one or more accounts on a distributed network; and

said electronically storing an access control list for an object comprises electronically storing an access control list for an object on a distributed network.

3 . The method of claim 2 , wherein said object comprises a securable object.

4 . The method of claim 3 , and further comprising: granting access rights to said one or more of said accounts on said distributed network based, at least in part, on the determined intersection between said group membership list and said access control list.

5 . The method of claim 4 , wherein said granting access rights with respect to said securable object comprises at least one of the following: granting permission to open said securable object; granting permission to read said securable object; granting permission to write to said securable object; granting permission to delete said securable object; granting permission to make a directory of said securable object; or any combination thereof

6 . The method of claim 3 , wherein said access control list for said securable object is stored within said securable object.

7 . The method of claim 3 , wherein said electronically determining an intersection comprises matching at least one of the following: a user name of said one or more accounts in said group membership list with a user name in said access control list.

8 . The method of claim 7 , wherein a user name of said one or more accounts comprises one or more group accounts on said distributed network.

9 . The method of claim 3 , wherein said group membership list and said access control list are stored as binary tree storage arrangements.

10 . The method of claim 9 , wherein said lists are stored as one or more lexicographically sorted lists.

11 . The method of claim 9 , wherein said electronically determining an intersection between said group membership list and said access control list includes performing a binary search of said binary tree storage arrangements.

12 . The method of claim 3 , wherein said securable object comprises at least one of the following: a file; or a folder.

13 . An article, comprising:

a non-transitory computer-readable storage medium having instructions stored thereon executable by a special purpose computing platform to:

electronically store a group membership list for accounts;

electronically store a plurality of objects at different locations in a distributed computing system;

electronically store a separate access control list for each of the plurality of objects, wherein searchable data defining each respective access control list for each respective object is embedded in or attached to the respective object such that each respective access control list is located with its respective object at the different locations in the distributed computing system; and

electronically determine an intersection between said group membership list and the respective access control list for one of the plurality of objects to be accessed.

14 . The article of claim 13 , wherein said instructions are further executable by a special purpose computing platform to:

electronically store a group membership list for accounts on a distributed network; and

electronically store an access control list for an object on a distributed network.

15 . The article of claim 14 , wherein said instructions are further executable by a special purpose computing platform to: electronically store an access control list for a securable object.

16 . The article of claim 15 , wherein said instructions are further executable by a special purpose computing platform to: grant access rights to said one or more of said accounts on said distributed network based, at least in part, on a determined intersection between said group membership list and said access control list.

17 . The article of claim 15 , wherein said instructions are further executable by a special purpose computing platform to: store said access control list for said securable object within said securable object.

18 . The article of claim 15 , wherein said instructions are further executable by a special purpose computing platform to determine an intersection through matching at least one of the following: a user name of said one or more accounts in said group membership list; or a user name in said access control list.

19 . The article of claim 18 , wherein said instructions are further executable by a special purpose computing platform so that a user name of said one or more accounts comprises one or more group accounts on said distributed network.

20 . An apparatus, comprising:

a special purpose computing platform having capability to:

electronically store a group membership list for accounts;

electronically store a plurality of objects at different locations in a distributed computing system;

electronically store a separate access control list for each of the plurality of objects, wherein searchable data defining each respective access control list for each respective object is embedded in or attached to the respective object such that each respective access control list is located with its respective object at the different locations in the distributed computing system; and

electronically determine an intersection between said group membership list and the respective access control list for one of the plurality of objects to be accessed.

21 . The apparatus of claim 21 , wherein said special purpose computing platform further having capability to:

electronically store a group membership list for accounts on a distributed network; and

electronically store an access control list for an object on a distributed network.

22 . The apparatus of claim 21 , wherein said special purpose computing platform further having capability to electronically store an access control list for a securable object.

23 . The apparatus of claim 22 , wherein said special purpose computing platform further having capability to grant access rights to said one or more of said accounts on said distributed network based, at least in part, on a determined intersection between said group membership list and said access control list.

24 . The apparatus of claim 22 , wherein said securable object comprises at least one of the following: a file; or a folder.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 024001 FRAME 0086. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 13, 2016
From: WORMLEY, MATT A.; COHEN, GARY B.; DRAGOMIR, SERGIU-ANDREI
To: ADOBE SYSTEMS INCORPORATED
Reel/Frame 038846/0658 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2010
From: WORMLEY, MATT A.; COHEN, GARY B.; DRAGOMIR, SERGIU-ANDREI
To: ADOBE SYSTEMS INC.
Reel/Frame 024001/0086 →