IP Library › Granted Patent US 8,793,355
Granted Patent B2
US 8,793,355 · App. 12/768,407 · Granted Jul 29, 2014

Techniques for directory data resolution

Inventors: Nathan Moser (Cedar Park, TX); Ayman Mobarak (San Francisco, CA); Chad Jamart (Clayton, CA)
Assignee: Symantec Corporation
H04L61/1523
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,793,355
App. No.
12/768,407
Granted
Jul 29, 2014
Kind
B2
Abstract

Techniques for directory data resolution are disclosed. In one particular exemplary embodiment, the techniques may be realized as a method for directory data resolution comprising receiving data identifying one or more groups of interest of a directory server, traversing, using a processor, one or more directory entries contained in hierarchical directory data, the traversal starting at a directory entry corresponding to a current group of interest, reading a first directory entry to identify a member contained in the first directory entry, adding, in the event a member is contained in the first directory entry, the current group of interest to a mapping for the member. The method may also include use of caching and recursion.

Claims (52)

1. A method for directory data resolution comprising:

receiving data identifying one or more groups of interest of a directory server;

traversing, using at least one computer processor, one or more directory entries contained in hierarchical directory data, the traversal starting at a directory entry corresponding to a current group of interest;

reading a first directory entry to identify a member contained in the first directory entry;

adding, in the event a member is contained in the first directory entry, the current group of interest to a mapping for the member;

determining whether the first directory entry contains a further directory entry;

reading, in the event a further directory entry is contained in the first directory entry, the further directory entry to determine whether the current group of interest is to be added to a mapping for another member and whether additional hierarchical directory data levels are to be traversed for the current group of interest; and

expiring a directory entry of the one or more directory entries in cache based on an expiration time determined by a separate random value assigned to each of the one or more directory entries, the random value used to distribute expiration times for the cached one or more directory entries to reduce a load required to refresh expired directory entries in cache at a point in time, wherein the expiration time determined by the separate random value is within a specified range of permissible expiration times.

2. The method of claim 1 , wherein the one or more directory entries comprise at least one of: a user, a group, and a distribution list.

3. The method of claim 1 , further comprising repeating a traversal of one or more directory entries contained in hierarchical directory data for a second group of interest.

4. The method of claim 1 , further comprising caching a list of identified users associated with a group membership map.

5. The method of claim 1 , further comprising caching a list of identified distribution lists associated with a group membership map.

6. The method of claim 1 , further comprising caching a list of identified groups associated with a group membership map.

7. The method of claim 1 , wherein policies are applied to groups of interest and a mapping of one or more members to a group of interest improves performance associated with applying a policy.

8. The method of claim 1 , wherein in the event a directory entry is available in cache, analysis is performed using the cache, and wherein in the event a directory entry is unavailable in cache, a query is made to the directory server.

9. The method of claim 8 , wherein a directory entry is unavailable in cache if the directory entry is expired.

10. The method of claim 9 , further comprising:

determining that the directory server is unavailable; and

using the expired corresponding directory entry for directory data resolution.

11. The method of claim 8 , wherein cached directory entries allow concurrent use by a process traversing hierarchical directory data to generate a mapping of one or more users to a group and by a directory data service client.

12. The method of claim 1 , wherein the data identifying one or more groups of interest of a directory server is received from an application and wherein at least one mapping of a member to a group of interest is provided to the application for application of a policy.

13. The method of claim 1 , further comprising:

identifying a circular group relationship in the one or more directory entries contained in hierarchical directory data during traversal; and

providing an alert containing data integrity error information associated with the circular group relationship to the administrator.

14. The method of claim 1 , wherein the directory server is a LDAP compliant directory server.

15. At least one non-transitory processor readable storage medium for storing a computer program of instructions configured to be readable by at least one processor for instructing the at least one processor to execute a computer process for performing the method as recited in claim 1 .

16. An article of manufacture for directory data resolution, the article of manufacture comprising:

at least one non-transitory processor readable storage medium; and

instructions stored on the at least one medium;

wherein the instructions are configured to be readable from the at least one medium by at least one processor and thereby cause the at least one processor to operate so as to:

receive data identifying one or more groups of interest of a directory server;

traverse one or more directory entries contained in hierarchical directory data, the traversal starting at a directory entry corresponding to a current group of interest;

read a first directory entry to identify a member contained in the first directory entry;

add, in the event a member is contained in the first directory entry, the current group of interest to a mapping for the member;

determine whether the first directory entry contains a further directory entry;

read, in the event a further directory entry is contained in the first directory entry, the further directory entry to determine whether the current group of interest is to be added to a mapping for another member and whether additional hierarchical directory data levels are to be traversed for the current group of interest; and

expire a directory entry of the one or more directory entries in cache based on an expiration time determined by a separate random value assigned to each of the one or more directory entries, the random value used to distribute expiration times for the cached one or more directory entries to reduce a load required to refresh expired directory entries in cache at a point in time, wherein the expiration time determined by the separate random value is within a specified range of permissible expiration times.

17. A system for directory data resolution comprising:

one or more processors communicatively coupled to a network; wherein the one or more processors are configured to:

receive data identifying one or more groups of interest of a directory server;

traverse one or more directory entries contained in hierarchical directory data, the traversal starting at a directory entry corresponding to a current group of interest;

read a first directory entry to identify a member contained in the first directory entry;

add, in the event a member is contained in the first directory entry, the current group of interest to a mapping for the member;

determine whether the first directory entry contains a further directory entry;

read, in the event a further directory entry is contained in the first directory entry, the further directory entry to determine whether the current group of interest is to be added to a mapping for another member and whether additional hierarchical directory data levels are to be traversed for the current group of interest; and

expire a directory entry of the one or more directory entries in cache based on an expiration time determined by a separate random value assigned to each of the one or more directory entries, the random value used to distribute expiration times for the cached one or more directory entries to reduce a load required to refresh expired directory entries in cache at a point in time, wherein the expiration time determined by the separate random value is within a specified range of permissible expiration times.

18. The system of claim 17 , wherein the one or more directory entries comprise at least one of: a member, a group, and a distribution list.

19. The system of claim 17 , wherein the one or more processors are further configured to:

repeat a traversal of one or more directory entries contained in hierarchical directory data for a second group of interest.

20. The system of claim 17 , wherein in the event a directory entry is available in cache, analysis is performed using the cache, and wherein in the event a directory entry is unavailable in cache, a query is made to the directory server.

21. The system of claim 20 , wherein a directory entry available in cache is identified by a cache index using query filter token allowing directory entry matching using a full name derived from a local part of an email address.

22. The system of claim 17 , wherein the data identifying one or more groups of interest of a directory server is received from an application and wherein at least one mapping of a member to a group of interest is provided to the application to apply a policy.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2010
From: MOSER, NATHAN; MOBARAK, AYMAN; JAMART, CHAD
To: SYMANTEC CORPORATION
Reel/Frame 024296/0964 →
Continuity (1)
Related Publication 20110264781A1 · Oct 27, 2011