IP Library Granted Patent US 9,906,419
Granted Patent B1
US 9,906,419 · App. 14/193,194 · Granted Feb 27, 2018

System and method for discovering and exposing controlling-user networks

Inventors: Michel Albert Brisebois (Renfrew, CA); Mikhail Anatolievich Plavskiy (Sankt-Peterburg, RU)
Assignee: Quest Software Inc.
H04L43/04H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,906,419
App. No.
14/193,194
Granted
Feb 27, 2018
Kind
B1
Abstract

In one embodiment, a method is performed by a computer system comprising physical computer hardware. The method includes discovering a controlling-user network for at least one user. The controlling-user network comprising a plurality of controlling users. The plurality of controlling users each control one or more sites of a content-management system. The method further includes profiling the plurality of controlling users based, at least in part, on information gleaned from sites on the content-management system controlled by the plurality of controlling users. In addition, the method includes exposing the controlling-user network to the at least one controlling user using a result of the profiling.

Claims (63)

1. A method of discovering a user-specific controlling-user network for a particular user of a content-management system, the content-management system comprising a plurality of managed sites, the user-specific controlling-user network comprising a plurality of controlling users of the content-management system, the method comprising, by a computer system:

passing a security identifier of the particular user to a directory-services system;

responsive to the passing, receiving, from the directory-services system, user groups of which the particular user is a member;

requesting, from an administrative system, security identifiers of controlling users of the plurality of managed sites of the content-management system, network locations of the plurality of managed sites and access control lists for the plurality of managed sites, wherein the controlling users represent specific users who are primarily responsible for the plurality of managed sites of the content-management system;

responsive to the requesting, receiving, from the administrative system, the security identifiers of the controlling users of the plurality of managed sites of the content-management system, the network locations of the plurality of managed sites and the access control lists for the plurality of managed sites;

determining, via the security identifiers of the controlling users, which of the controlling users are members of at least one of the user groups of which the particular user is a member;

compiling information related to managed sites of the content-management system that are controlled by the determined controlling users, the compiled information comprising, for each managed site that is controlled by a controlling user of the determined controlling users, the network location of the managed site and the access control list of the managed site;

acquiring, via the access control lists in the compiled information, security principals of the managed sites that are controlled by the determined controlling users;

ascertaining whether each of the security principals refers to a user or a group of users;

resolving each said security principal that refers to a group of users to individual users;

integrating each said security principal that refers to a user and the individual users of each said resolved security principal into a set of permissioned users who have been granted access to one or more of the managed sites that are controlled by the determined controlling users; and

removing from the set of permissioned users those users who are not a controlling user of at least one managed site of the content-management system, the removing yielding the plurality of controlling users of the user-specific controlling-user network.

2. The method of claim 1 comprising, prior to the acquiring, removing from the compiled information those managed sites for which the particular user is not a controlling user.

3. The method of claim 1 , comprising:

generating one or more profiles of the plurality of controlling users based, at least in part, on information gleaned from sites on the content-management system controlled by the plurality of controlling users; and

exposing the user-specific controlling-user network to the particular user using a result of the generating.

4. The method of claim 3 , wherein the generating comprises generating a plurality of controlling-user profiles corresponding to the plurality of controlling users.

5. The method of claim 4 , wherein each controlling-user profile comprises information selected from the group consisting of: security information, content information, infrastructure information, directory information, and site-configuration information.

6. The method of claim 4 , wherein the exposing comprises:

providing a searchable interface to the particular user;

receiving search criteria;

comparing the search criteria to the plurality of controlling-user profiles;

generating controlling-user information responsive to the search criteria; and

providing the controlling-user information to the particular user.

7. The method of claim 6 , wherein the controlling-user information comprises a list of controlling users.

8. The method of claim 7 , comprising allowing the particular user to contact one or more controlling users on the list of controlling users.

9. An information handling system comprising a computer processor and memory, wherein the computer processor and memory in combination are operable to implement a method of discovering a user-specific controlling-user network for a particular user of a content-management system, the content-management system comprising a plurality of managed sites, the user-specific controlling-user network comprising a plurality of controlling users of the content-management system, the method comprising:

passing a security identifier of the particular user to a directory-services system;

responsive to the passing, receiving, from the directory-services system, user groups of which the particular user is a member;

requesting, from an administrative system, security identifiers of controlling users of the plurality of managed sites of the content-management system, network locations of the plurality of managed sites and access control lists for the plurality of managed sites, wherein the controlling users represent specific users who are primarily responsible for the plurality of managed sites of the content-management system;

responsive to the requesting, receiving, from the administrative system, the security identifiers of the controlling users of the plurality of managed sites of the content-management system, the network locations of the plurality of managed sites and the access control lists for the plurality of managed sites;

determining, via the security identifiers of the controlling users, which of the controlling users are members of at least one of the user groups of which the particular user is a member;

compiling information related to managed sites of the content-management system that are controlled by the determined controlling users, the compiled information comprising, for each managed site that is controlled by a controlling user of the determined controlling users, the network location of the managed site and the access control list of the managed site;

acquiring, via the access control lists in the compiled information, security principals of the managed sites that are controlled by the determined controlling users;

ascertaining whether each of the security principals refers to a user or a group of users;

resolving each said security principal that refers to a group of users to individual users;

integrating each said security principal that refers to a user and the individual users of each said resolved security principal into a set of permissioned users who have been granted access to one or more of the managed sites that are controlled by the determined controlling users; and

removing from the set of permissioned users those users who are not a controlling user of at least one managed site of the content-management system, the removing yielding the plurality of controlling users of the user-specific controlling-user network.

10. The information handling system of claim 9 , the method comprising, prior to the acquiring, removing from the compiled information those managed sites for which the particular user is not a controlling user.

11. The information handling system of claim 9 , the method comprising:

generating one or more profiles of the plurality of controlling users based, at least in part, on information gleaned from sites on the content-management system controlled by the plurality of controlling users; and

exposing the user-specific controlling-user network to the particular user using a result of the generating.

12. The information handling system of claim 11 , wherein the generating comprises generating a plurality of controlling-user profiles corresponding to the plurality of controlling users.

13. The information handling system of claim 12 , wherein the exposing comprises:

providing a searchable interface to the particular user;

receiving search criteria;

comparing the search criteria to the plurality of controlling-user profiles;

generating controlling-user information responsive to the search criteria; and

providing the controlling-user information to the particular user.

14. The information handling system of claim 13 , wherein the controlling-user information comprises a list of controlling users.

15. The information handling system of claim 14 , the method comprising allowing the particular user to contact one or more controlling users on the list of controlling users.

16. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method of discovering a user-specific controlling-user network for a particular user of a content-management system, the content-management system comprising a plurality of managed sites, the user-specific controlling-user network comprising a plurality of controlling users of the content-management system, the method comprising:

passing a security identifier of the particular user to a directory-services system;

responsive to the passing, receiving, from the directory-services system, user groups of which the particular user is a member;

requesting, from an administrative system, security identifiers of controlling users of the plurality of managed sites of the content-management system, network locations of the plurality of managed sites and access control lists for the plurality of managed sites, wherein the controlling users represent specific users who are primarily responsible for the plurality of managed sites of the content-management system;

responsive to the requesting, receiving, from the administrative system, the security identifiers of the controlling users of the plurality of managed sites of the content-management system, the network locations of the plurality of managed sites and the access control lists for the plurality of managed sites;

determining, via the security identifiers of the controlling users, which of the controlling users are members of at least one of the user groups of which the particular user is a member;

compiling information related to managed sites of the content-management system that are controlled by the determined controlling users, the compiled information comprising, for each managed site that is controlled by a controlling user of the determined controlling users, the network location of the managed site and the access control list of the managed site;

acquiring, via the access control lists in the compiled information, security principals of the managed sites that are controlled by the determined controlling users;

ascertaining whether each of the security principals refers to a user or a group of users;

resolving each said security principal that refers to a group of users to individual users;

integrating each said security principal that refers to a user and the individual users of each said resolved security principal into a set of permissioned users who have been granted access to one or more of the managed sites that are controlled by the determined controlling users; and

removing from the set of permissioned users those users who are not a controlling user of at least one managed site of the content-management system, the removing yielding the plurality of controlling users of the user-specific controlling-user network.

Assignments (27)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044719/0565 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CHANGE OF NAME Recorded Nov 20, 2017
From: DELL SOFTWARE INC
To: QUEST SOFTWARE INC.
Reel/Frame 044487/0553 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF REEL 032810 FRAME 0038 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040027/0686 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 032809 FRAME 0987 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040026/0953 →
RELEASE OF REEL 032810 FRAME 0023 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, INC.
Reel/Frame 040014/0320 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032810/0023 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 032809/0987 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 1, 2014
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 032810/0038 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2014
From: BRISEBOIS, MICHEL ALBERT; PLAVSKIY, MIKHAIL ANATOLIEVICH
To: DELL SOFTWARE INC.
Reel/Frame 032369/0409 →