IP Library Granted Patent US 9,280,646
Granted Patent B1
US 9,280,646 · App. 14/109,594 · Granted Mar 8, 2016

Methods, systems, and computer readable mediums for role-based access control involving one or more converged infrastructure systems

Inventors: Rajesh Nandyalam (Whitinsville, MA); Venkatesh Madhipatla (Westford, MA); Joshua P Onffroy (Upton, MA); Xiaohong Fu (Plano, TX)
Assignee: VCE Company, LLC
G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,280,646
App. No.
14/109,594
Granted
Mar 8, 2016
Kind
B1
Abstract

Methods, systems, and computer readable mediums for implementing role-based access control (RBAC) are disclosed. According to one method, the method includes authenticating a user for implementing RBAC across multiple components associated with one or more converged infrastructure systems, receiving, from the user, RBAC related information for implementing RBAC across the multiple components associated with the one or more converged infrastructure systems, and implementing, using the RBAC related information, RBAC across the multiple components associated with the one or more converged infrastructure systems.

Claims (22)

1. A method for implementing role-based access control (RBAC), the method comprising:

authenticating, by a first computer system, a user for implementing RBAC across multiple components associated with one or more computer systems;

receiving, from the user, RBAC related information for implementing RBAC across the multiple components associated with the one or more computer systems, wherein the RBAC related information includes an RBAC policy providing one or more role based permissions, where each of the one or more role based permissions is associated with a different heterogeneous component of the multiple components; and

implementing, using the RBAC related information, RBAC across the multiple components associated with the one or more computer systems, wherein implementing RBAC comprises sending control path information from the first computer system to a second computer system, wherein implementing RBAC across the multiple components includes implementing RBAC at a logical entity comprising at least two members selected from a group consisting of a computing component, a software component, a networking component, a physical resource, a virtual resource, a hardware component, and a firmware component, wherein implementing RBAC across the multiple components comprises generating one or more appropriate messages for triggering RBAC at the multiple components using a representational state transfer (REST) application programming interface (API) related message, wherein the control path information instructs the second computer system to implement the RBAC policy.

2. The method of claim 1 comprising:

storing the RBAC related information in a clustered database system accessible by the one or more computer systems.

3. The method of claim 1 wherein receiving the RBAC related information comprises receiving the RBAC related information via an application programming interface, a command line interface, or a graphical user interface associated with one of the one or more computer systems.

4. The method of claim 1 wherein the one or more appropriate messages include a simple network management (SNMP) related message, a telnet related message, a secure shell related message, a command line related message, an extensible markup language (XML) API related message, an XML related message, and/or a storage management interface (SMI) related message.

5. A system for implementing role-based access control (RBAC), the system comprising:

at least one processor;

memory; and

an RBAC module utilizing the at least one processor and the memory, wherein the RBAC module is configured to authenticate, by a first computer system, a user for implementing RBAC across multiple components associated with one or more computer systems, wherein the RBAC related information includes an RBAC policy providing one or more role based permissions, where each of the one or more role based permissions is associated with a different heterogeneous component of the multiple components, to receive, from the user, RBAC related information for implementing RBAC across the multiple components associated with the one or more computer systems, and to implement, using the RBAC related information, RBAC across the multiple components associated with the one or more computer systems, wherein implementing RBAC comprises sending control path information from the first computer system to a second computer system, wherein the RBAC module is further configured to implement RBAC at a logical entity comprising at least two members selected from a group consisting of a computing component, a software component, a networking component, a physical resource, a virtual resource, a hardware component, and a firmware component, and wherein the RBAC module is configured to implement RBAC across the multiple components by generating one or more appropriate messages for triggering RBAC at the multiple components using a representational state transfer (REST) application programming interface (API) related message, wherein the control path information instructs the second computer system to implement the RBAC policy.

6. The system of claim 5 wherein the RBAC module is configured to store the RBAC related information in a clustered database system accessible by the one or more computer systems.

7. The system of claim 5 wherein the RBAC module is configured to receive the RBAC related information via an application programming interface, a command line interface, or a graphical user interface associated with one of the one or more computer systems.

8. The system of claim 5 wherein the one or more appropriate messages include a simple network management (SNMP) related message, a telnet related message, a secure shell related message, a command line related message, an extensible markup language (XML) API related message, an XML related message, and/or a storage management interface (SMI) related message.

9. A non-transitory computer readable medium having stored thereon executable instructions that when executed by a processor of a computer control the computer to perform steps comprising:

authenticating, by a first computer system, a user for implementing RBAC across multiple components associated with one or more computer systems;

receiving, from the user, RBAC related information for implementing RBAC across the multiple components associated with the one or more computer systems, wherein the RBAC related information includes an RBAC policy providing one or more role based permissions, where each of the one or more role based permissions is associated with a different heterogeneous component of the multiple components; and

implementing, using the RBAC related information, RBAC across the multiple components associated with the one or more computer systems, wherein implementing RBAC comprises sending control path information from the first computer system to a second computer system, wherein implementing RBAC across the multiple components includes implementing RBAC at a logical entity comprising at least two members selected from a group consisting of a computing component, a software component, a networking component, a physical resource, a virtual resource, a hardware component, and a firmware component, wherein implementing RBAC across the multiple components comprises generating one or more appropriate messages for triggering RBAC at the multiple components using a representational state transfer (REST) application programming interface (API) related message, wherein the control path information instructs the second computer system to implement the RBAC policy.

10. The non-transitory computer readable medium of claim 9 comprising:

storing the RBAC related information in a clustered database system accessible by the one or more computer systems.

11. The non-transitory computer readable medium of claim 9 wherein the one or more appropriate messages include a simple network management (SNMP) related message, a telnet related message, a secure shell related message, a command line related message, an extensible markup language (XML) API related message, an XML related message, and/or a storage management interface (SMI) related message.

Assignments (5)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
MERGER Recorded Mar 26, 2020
From: VCE IP HOLDING COMPANY LLC
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 052236/0497 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2016
From: VCE COMPANY, LLC
To: VCE IP HOLDING COMPANY LLC
Reel/Frame 040576/0161 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2014
From: NANDYALAM, RAJESH; MADHIPATLA, VENKATESH; ONFFROY, JOSHUA; FU, XIAOHONG
To: VCE COMPANY, LLC
Reel/Frame 032401/0471 →