IP Library Granted Patent US 9,516,032
Granted Patent B2
US 9,516,032 · App. 14/498,284 · Granted Dec 6, 2016

Methods and systems for using derived user accounts

Inventor: Ulfar Erlingsson (San Francisco, CA)
Assignee: GOOGLE INC.
H04L63/102G06F21/6218G06F21/6281
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,516,032
App. No.
14/498,284
Filed
Sep 26, 2014
Granted
Dec 6, 2016
Kind
B2
Art Unit
2434
USPC
726/4
Abstract

Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.

Claims (34)

1. A computer-implemented method for accessing a resource in a computer system comprising an operating system, comprising:

receiving a request to access a named abstraction from an application;

determining if the application is running in a derived user account (DUA) context, wherein the DUA context represents a security context of a DUA that is derived from an original user account (OUA) associated with a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not running in the DUA context, creating the DUA and directing the application to run in the DUA context; and

granting the application access to the named abstraction.

2. The computer-implemented method of claim 1 , wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA.

3. The computer-implemented method of claim 1 , wherein directing the application to run in the DUA context comprises modifying the access token to generate a modified access token and associating the application with the modified access token.

4. The computer-implemented method of claim 1 , wherein creating the DUA comprises generating the DUA using a user account creation mechanism of the operating system.

5. The computer-implemented method of claim 1 , wherein the DUA comprises different access rights than the OUA.

6. The computer-implemented method of claim 1 , wherein the named abstraction is a hardware device.

7. The computer-implemented method of claim 6 , wherein the named abstraction is an email account or a social networking account.

8. The computer-implemented method of claim 1 , wherein directing the application to run in the DUA context comprises annotating activity associated with the application as belonging to the DUA.

9. The computer-implemented method of claim 8 , wherein annotating the activity associated with the application comprises annotating the activity associated with the application in a kernel thread control block or a kernel process control block.

10. An apparatus, comprising:

at least one memory having program instructions to execute an operating system; and

at least one processor configured to execute the program instructions to perform the operations of:

receiving a request to access a named abstraction from an application;

determining if the application is running in a derived user account (DUA) context, wherein the DUA context represents a security context of a DUA that is derived from an original user account (OUA) associated with a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not running in the DUA context, creating a DUA and directing the application to run in the DUA context; and

granting the application access to the named abstraction.

11. The apparatus of claim 10 , wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA.

12. The apparatus of claim 10 , wherein directing the application to run in the DUA context comprises modifying the access token to generate a modified access token and associating the modified access token with the application.

13. The apparatus of claim 10 , wherein directing the application to run in the DUA context comprises annotating activity associated with the application as belonging to the DUA.

14. The apparatus of claim 13 , wherein annotating the activity associated with the application comprises annotating the activity associated with the application in a kernel thread control block or a kernel process control block.

15. A non-transitory computer-readable medium containing computer-readable instructions enabling a computer to perform a method, the method comprising:

receiving a request to access a named abstraction from an application;

determining if the application is running in a derived user account (DUA) context, wherein the DUA context represents a security context of a DUA that is derived from an original user account (OUA) associated with a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not running in the DUA context, creating the DUA and directing the application to run in the DUA context; and

granting the application access to the named abstraction.

16. The non-transitory computer-readable medium of claim 15 , wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA.

17. The non-transitory computer-readable medium of claim 15 , wherein directing the application to run in the DUA context comprises modifying the access token to generate a modified access token and associating the modified access token with the application.

18. The non-transitory computer-readable medium of claim 15 , wherein the named abstraction is a hardware device or an email account or a social networking account.

19. The non-transitory computer-readable medium of claim 15 , wherein directing the application to run in the DUA context comprises annotating activity associated with the application as belonging to the DUA.

20. The non-transitory computer-readable medium of claim 19 , wherein annotating the activity associated with the application comprises annotating the activity associated with the application in a kernel thread control block or a kernel process control block.

Assignments (3)
CHANGE OF NAME Recorded Oct 5, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044129/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2016
From: ERLINGSSON, ULFAR
To: GREEN BORDER TECHNOLOGIES
Reel/Frame 038709/0265 →
MERGER Recorded May 24, 2016
From: GREEN BORDER TECHNOLOGIES, INC.
To: GOOGLE INC.
Reel/Frame 038709/0270 →
Continuity (5)
Continuation 14171512 · Feb 3, 2014
Continuation 13565483 · Aug 2, 2012
Continuation 10144048 · May 10, 2002
Provisional Application 60335894 · Nov 1, 2001
Related Publication 20150052592A1 · Feb 19, 2015