IP Library Granted Patent US 9,076,168
Granted Patent B2
US 9,076,168 · App. 13/299,157 · Granted Jul 7, 2015

Defining an authorizer in a virtual computing infrastructure

Inventors: Willem Robert Van Biljon (Cape Town, ZA); Christopher Conway Pinkham (Los Gatos, CA); Russell Andrew Cloran (Cape Town, ZA); Michael Carl Gorven (Cape Town, ZA); Alexandre Hardy (Capetown, ZA); Brynmor K. B. Divey (Cape Town, ZA); Quinton Robin Hoole (Cape Town, ZA); Girish Kalele (Sunnyvale, CA)
Assignee: Oracle International Corporation
G06Q30/04H04L29/06H04L41/0213G06Q40/02G06Q40/10G06Q40/00G06F21/6218G06F2221/2141G06F2221/2145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,076,168
App. No.
13/299,157
Granted
Jul 7, 2015
Kind
B2
Abstract

An authorizing entity is allowed to grant permission to a subject to perform an action on an object in a cloud computing environment. An authorizer is defined as the entity having granting authority to delegate a predetermined permission. A subject is defined as a group to whom the permission is being delegated. An object is defined upon which an action is authorized within the cloud computing environment. The action being authorized in the cloud computing environment is defined. Members of the subject group are authorized to perform the permitted action on the object.

Claims (22)

1. A method of allowing an authorizing entity to grant permission to a subject to perform an action on an object in a cloud computing environment having a plurality of computing nodes, the method comprising:

defining an authorizer value for an authorizer key in a permission, the authorizer value identifying an entity delegating the permission;

defining a subject value for a subject key in the permission, the subject value identifying a group to whom the permission is being delegated;

defining an object value for an object key in the permission, the object value identifying an object upon which action is authorized by the permission within the cloud computing environment;

defining an action value for an action key in the permission, the action value identifying an action authorized by the permission in the cloud computing environment;

determining that a path exists in a directed graph between (a) a node corresponding to the authorizer value and (b) another node corresponding to an initial set of permissions created in connection with a creation of a customer to which the group belongs; and

authorizing members of the subject group to perform a requested action on a requested object based on the defined values of the permission and the existence of the path.

2. The method of claim 1 , wherein the object is a machine image from which data is accessed.

3. The method of claim 1 , wherein the object is executed code.

4. The method of claim 1 , wherein the object is a data store.

5. A cloud computing system, comprising:

at least one storage device configured to store a plurality of instructions; and

at least one processor device in communication with the at least one storage device, and configure to execute the plurality of instructions to:

define an authorizer value for an authorizer key in a permission, the authorizer value identifying an entity delegating the permission;

define a subject value for a subject key in the permission, the subject value identifying a group to whom the permission is being delegated;

define an object value for an object key in the permission, the object value identifying an object upon which action is authorized by the permission within the cloud computing environment;

define an action value for an action key in the permission, the action value identifying an action authorized by the permission in the cloud computing environment;

determine that a path in a directed graph exists between (a) a node corresponding to the authorizer value and (b) another node corresponding to an initial set of permissions created in connection with a creation of a customer to which the group belongs; and

authorize members of the subject group to perform a requested action on a requested object based on the defined values of the permission and the existence of the path.

6. The system of claim 5 , wherein the object is a machine image from which data is accessed.

7. The system of claim 5 , wherein the object is executed code.

8. The system of claim 5 , wherein the object is a data store.

Assignments (2)
MERGER Recorded May 3, 2013
From: NIMBULA, INC.
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 030350/0031 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2011
From: VAN BILJON, WILLEM ROBERT; PINKHAM, CHRISTOPHER CONWAY; CLORAN, RUSSELL ANDREW; GORVEN, MICHAEL CARL; HARDY, ALEXANDRE; DIVEY, BRYNMOR K.B.; HOOLE, QUINTON ROBIN; KALELE, GIRISH
To: NIMBULA, INC.
Reel/Frame 027463/0204 →
Continuity (3)
Continuation PCTUS2011040590 · Jun 15, 2011
Provisional Application 61355078 · Jun 15, 2010
Related Publication 20120110636A1 · May 3, 2012