IP Library Granted Patent US 9,444,808
Granted Patent B1
US 9,444,808 · App. 14/169,136 · Granted Sep 13, 2016

System and method for providing multtenant access to shared resources

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,444,808
App. No.
14/169,136
Granted
Sep 13, 2016
Kind
B1
Abstract

In one embodiment, a method includes maintaining a domain information cache. The method further includes receiving credentials from a client system. The credentials correspond to a user of the client system. The method also includes storing the credentials in a security cookie. In addition, the method includes, based, at least in part, on the domain information cache, resolving the credentials to an authentication server associated with a domain of the user. Also, the method includes authenticating, using the credentials, an identity of the user with the authentication server. Additionally, the method includes, responsive to successful authentication, building a list of groups and users to which the user belongs. Moreover, the method includes compiling a list of authorized resources to which the user has access. In addition, the method includes providing the list of authorized resources to the client system.

Claims (76)

1. A method comprising, on a multitenant shared-resources system:

maintaining a domain information cache, the domain information cache comprising domain information for a plurality of managed domains, wherein the plurality of managed domains are organized into a plurality of independent management hierarchies, wherein the plurality of independent management hierarchies each subsume therein one or more domains of the plurality of managed domains;

wherein each domain of the plurality of managed domains comprises a collection of network objects that share a same directory-services database;

wherein each management hierarchy of the plurality of independent management hierarchies defines an independent security boundary such that network objects of the one or more domains subsumed therein are not made accessible to network objects of any other management hierarchy of the plurality of independent management hierarchies;

receiving credentials from a client system, the credentials corresponding to a user of the client system;

storing the credentials in a security cookie;

extracting a domain-relevant portion from the credentials;

based, at least in part, on a search of the domain information cache, identifying a directory level of a particular management hierarchy of the plurality of independent management hierarchies that defines a security boundary for the user;

ascertaining a catalog server for the identified directory level;

retrieving user-identification information from the catalog server;

parsing the user-identification information to yield a domain of the user;

authenticating, using the credentials, an identity of the user with an authentication server associated with the domain of the user;

responsive to successful authentication:

compiling a list of authorized resources to which the user has access; and

providing the list of authorized resources to the client system.

2. The method of claim 1 , comprising:

receiving a request from the client system to access a target resource selected from the list of authorized resources;

resolving the target resource to a network location;

sending a message to the target resource, the message comprising an instruction to add the user to a resource group for the target resource; and

providing a ticket to the client system, the ticket comprising an identifier of the security cookie.

3. The method of claim 2 comprising, upon user logout, removing the user from the resource group.

4. The method of claim 1 , wherein:

the user-identification information comprises a distinguished name of the user; and

the parsing comprises parsing the distinguished name.

5. The method of claim 1 , comprising retrieving the authentication server from a domain name system (DNS) server associated with the domain of the user.

6. The method of claim 1 , wherein:

the directory level comprises an Active Directory forest;

the plurality of managed domains belong to multiple Active Directory forests; and

the identifying of the directory level comprises searching user principal name (UPN) suffixes of each forest in the domain information cache for a match with the domain-relevant portion.

7. The method of claim 1 , wherein the list of authorized resources comprises a list of virtual desktops.

8. The method of claim 1 , wherein the authentication server comprises an active directory server.

9. An information handling system comprising:

a hardware computer processor, wherein the hardware computer processor is operable to implement a method, the method comprising:

maintaining a domain information cache, the domain information cache comprising domain information for a plurality of managed domains, wherein the plurality of managed domains are organized into a plurality of independent management hierarchies, wherein the plurality of independent management hierarchies each subsume therein one or more domains of the plurality of managed domains;

wherein each domain of the plurality of managed domains comprises a collection of network objects that share a same directory-services database;

wherein each management hierarchy of the plurality of independent management hierarchies defines an independent security boundary such that network objects of the one or more domains subsumed therein are not made accessible to network objects of any other management hierarchy of the plurality of independent management hierarchies;

receiving credentials from a client system, the credentials corresponding to a user of the client system;

storing the credentials in a security cookie;

extracting a domain-relevant portion from the credentials;

based, at least in part, on a search of the domain information cache, identifying a directory level of a particular management hierarchy of the plurality of independent management hierarchies that defines a security boundary for the user;

ascertaining a catalog server for the identified directory level;

retrieving user-identification information from the catalog server;

parsing the user-identification information to yield a domain of the user;

authenticating, using the credentials, an identity of the user with an authentication server associated with the domain of the user;

responsive to successful authentication:

compiling a list of authorized resources to which the user has access; and

providing the list of authorized resources to the client system.

10. The information handling system of claim 9 , the method comprising:

receiving a request from the client system to access a target resource selected from the list of authorized resources;

resolving the target resource to a network location;

sending a message to the target resource, the message comprising an instruction to add the user to a resource group for the target resource; and

providing a ticket to the client system, the ticket comprising an identifier of the security cookie.

11. The information handling system of claim 10 , the method comprising, upon user logout, removing the user from the resource group.

12. The information handling system of claim 9 , wherein:

the user-identification information comprises a distinguished name of the user; and

the parsing comprises parsing the distinguished name.

13. The information handling system of claim 9 , comprising retrieving the authentication server from a domain name system (DNS) server associated with the domain of the user.

14. The information handling system of claim 9 , wherein:

the directory level comprises an Active Directory forest;

the plurality of managed domains belong to multiple Active Directory forests; and

the identifying of the directory level comprises searching user principal name (UPN) suffixes of each forest in the domain information cache for a match with the domain-relevant portion.

15. The information handling system of claim 9 , wherein the list of authorized resources comprises a list of virtual desktops.

16. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

maintaining a domain information cache, the domain information cache comprising domain information for a plurality of managed domains, wherein the plurality of managed domains are organized into a plurality of independent management hierarchies, wherein the plurality of independent management hierarchies each subsume therein one or more domains of the plurality of managed domains;

wherein each domain of the plurality of managed domains comprises a collection of network objects that share a same directory-services database;

wherein each management hierarchy of the plurality of independent management hierarchies defines an independent security boundary such that network objects of the one or more domains subsumed therein are not made accessible to network objects of any other management hierarchy of the plurality of independent management hierarchies;

receiving credentials from a client system, the credentials corresponding to a user of the client system;

storing the credentials in a security cookie; extracting a domain-relevant portion from the credentials;

based, at least in part, on a search of the domain information cache, identifying a directory level of a particular management hierarchy of the plurality of independent management hierarchies that defines a security boundary for the user;

ascertaining a catalog server for the identified directory level;

retrieving user-identification information from the catalog server;

parsing the user-identification information to yield a domain of the user;

authenticating, using the credentials, an identity of the user with an authentication server associated with the domain of the user;

responsive to successful authentication:

compiling a list of authorized resources to which the user has access; and

providing the list of authorized resources to the client system.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2016
From: DELL SOFTWARE INC.
To: DELL PRODUCTS L.P.
Reel/Frame 040100/0620 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 032810 FRAME 0206 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0204 →
RELEASE OF SECURITY INTEREST OF REEL 032809 FRAME 0930 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040045/0255 →
RELEASE OF REEL 032809 FRAME 0887 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040017/0314 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 032810/0206 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 032809/0930 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032809/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2014
From: SHERMAN, MARC ALEXANDER; ZAPF, MARC EDWARD
To: DELL SOFTWARE INC.
Reel/Frame 032316/0475 →