IP Library Granted Patent US 10,257,051
Granted Patent B2
US 10,257,051 · App. 15/226,336 · Granted Apr 9, 2019

Method and device for managing resources with an external account

Inventors: Boyang Liu (Hangzhou, CN); Jun Li (Hangzhou, CN)
Assignee: ALIBABA GROUP HOLDING LIMITED
H04L41/28H04L63/083H04L63/0815H04L63/0876H04L63/102H04L67/10H04L41/0896H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,257,051
App. No.
15/226,336
Granted
Apr 9, 2019
Kind
B2
Abstract

Method and device for managing cloud computing resources with an external account, the resources being associated with one or more internal main accounts. The method includes verifying an identity of the external account via a server, determining, if the identity of the external account is verified, whether a virtual sub-account is bound to the external account, the virtual sub-account being subordinate to an internal main account of the one or more internal main accounts, and allowing, if it is determined that the virtual sub-account is bound to the external account, the external account to manage the resources associated with the internal main account based on pre-configured rights of the virtual sub-account.

Claims (39)

1. A method for managing cloud computing resources, the method comprising:

requesting, using an identity verification protocol, an identity verification for an external account via a verification server, the identity verification comprising an identifier of the external account and a verification server signature;

verifying the verification server signature returned by the verification server;

determining that the identity of the external account is verified if the server signature is verified;

if the identity of the external account is verified, determining whether a virtual sub-account is bound to the external account, the virtual sub-account having pre-configured rights to manage the cloud computing resources, the cloud computing resources being associated with one or more internal main accounts, the virtual sub-account being subordinate to one of the one or more internal main accounts the determining whether the virtual sub-account is bound to the external account comprising: querying whether any virtual sub-accounts subordinate to the one or more internal main accounts are bound to the external account, wherein each of the one or more internal main accounts has at least one subordinate virtual sub-account; and

if it is determined that the virtual sub-account is bound to the external account, allowing the external account to manage the cloud computing resources associated with the internal main account based on the pre-configured rights of the virtual sub-account.

2. The method according to claim 1 , further comprising: creating the virtual sub-account subordinate to the internal main account, the internal main account having a user name and a password, and the virtual sub-account not having a password for managing resources with the external account; allocating management rights to the virtual sub-account as pre-configured rights for managing the resources of the internal main account; and binding the virtual sub-account to the external account.

3. The method according to claim 2 , further comprising: modifying the pre-configured rights of the virtual sub-account in the internal main account, wherein the modifying the pre-configured rights is after the allocating.

4. The method according to claim 2 , further comprising: second binding the virtual sub-account to another external account after the step of binding.

5. The method according to claim 1 , wherein in the verifying the identity of the external account, if the identity is not verified via the external account, a cause of login failure is displayed.

6. The method according to claim 1 , wherein the identity verification protocol includes at least one of an OAuth protocol, a SAML protocol, and an OpenID protocol.

7. The method according to claim 1 , wherein the determining whether the virtual sub-account is bound to the external account comprises: querying whether a virtual sub-account of a target account of the one or more internal main accounts is bound to the external account, wherein each of the one or more internal main accounts has at least one subordinate virtual sub-account.

8. A device for managing cloud computing resources, the device comprising:

one or more processors;

a network interface; and

a memory storing computer-executable instructions executable by the one or more processors, the instructions causing the device to:

request, using an identity verification protocol, an identity verification for an external account via a verification server, the identity verification comprising an identifier of the external account and a verification server signature;

verify the verification server signature returned by the verification server;

determine that the identity of the external account is verified if the server signature is verified;

if the identity of the external account is verified, determine whether a virtual sub-account is bound to the external account, the virtual subaccount having pre-configured rights to manage the cloud computing resources, the cloud computing resources being associated with one or more internal main accounts, the virtual sub-account being subordinate to one of the one or more internal main accounts, the determining whether the virtual sub-account is bound to the external account comprising: querying whether any virtual sub-accounts subordinate to the one or more internal main accounts are bound to the external account, wherein each of the one or more internal main accounts has at least one subordinate virtual sub-account; and

if it is determined that the virtual sub-account is bound to the external account, allow the external account to manage the cloud computing resources associated with the internal main account based on the pre-configured rights of the virtual sub-account.

9. The device according to claim 8 , the instructions further causing the device to: create the virtual sub-account subordinate to the internal main account, the internal main account having a user name and a password, and the virtual sub-account not having a password for managing resources with the external account; allocate management rights to the virtual sub-account as pre-configured rights for managing the resources of the internal main account; and bind the virtual sub-account to the external account.

10. The device according to claim 9 , the instructions further causing the device to: modify the pre-configured rights of the virtual sub-account in the internal main account, wherein the modifying the pre-configured rights is after the allocating.

11. The device according to claim 9 , the instructions further causing the device to: second bind the virtual sub-account to another external account after the instruction to bind.

12. The device according to claim 8 , wherein in the instruction to verify the identity of the external account, if the identity is not verified via the external account, a cause of login failure is displayed.

13. The device according to claim 8 , wherein the identity verification protocol includes at least one of an OAuth protocol, a SAML protocol, and an OpenID protocol.

14. The device according to claim 8 , wherein the instruction to determine further causes the device to: query whether a virtual sub-account of a target account of the one or more internal main accounts is bound to the external account, wherein each of the one or more internal main accounts has at least one subordinate virtual sub-account.

15. A non-transitory computer-readable storage medium storing computer-executable instructions that when executed by a processor, cause the processor to perform a method for managing cloud computing resources, the method comprising

requesting, using an identity verification protocol, an identity verification for an external account via a verification server, the identity verification comprising an identifier of the external account and a verification server signature;

verifying the verification server signature returned by the verification server;

determining that the identity of the external account is verified if the server signature is verified;

if the identity of the external account is verified, determining whether a virtual sub-account is bound to the external account, the virtual subaccount having pre-configured rights to manage the cloud computing resources, the cloud computing resources being associated with one or more internal main accounts, the virtual sub-account being subordinate to one of the one or more internal main accounts, the determining whether the virtual sub-account is bound to the external account comprising: querying whether any virtual sub-accounts subordinate to the one or more internal main accounts are bound to the external account, wherein each of the one or more internal main accounts has at least one subordinate virtual sub-account; and

if it is determined that the virtual sub-account is bound to the external account, allowing the external account to manage the cloud computing resources associated with the internal main account based on the pre-configured rights of the virtual sub-account.

16. The non-transitory computer-readable storage medium according to claim 15 , the method further comprising: creating the virtual sub-account subordinate to the internal main account, the internal main account having a user name and a password, and the virtual sub-account not having a password for managing resources with the external account; allocating management rights to the virtual sub-account as pre-configured rights for managing the resources of the internal main account; and binding the virtual sub-account to the external account.

17. A method for managing cloud computing resources, the method comprising:

receiving an identity verification result of an external account returned by a verification server, the verification result comprising an identifier of the external account and a verification server signature;

verifying the verification server signature returned by the verification server;

determining whether a virtual sub-account is bound to the external account, the virtual sub-account having pre-configured rights to manage the cloud computing resources, the cloud computing resources being associated with one or more internal main accounts, the virtual sub-account being subordinate to one of the one or more internal main accounts, the determining whether the virtual sub-account is bound to the external account comprising: querying whether any virtual sub-accounts subordinate to the one or more internal main accounts are bound to the external account, wherein each of the one or more internal main accounts has at least one subordinate virtual sub-account; and

if it is determined that the virtual sub-account is bound to the external account, allowing the external account to manage the cloud computing resources associated with the internal main account based on the pre-configured rights of the virtual sub-account.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2026
From: ALIBABA GROUP HOLDING LIMITED
To: CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PRIVATE LIMITED
Reel/Frame 075478/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2016
From: LIU, BOYANG; LI, JUN
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 040350/0086 →
Priority Claims (1)
CN 2015 1 0487834 · Aug 10, 2015 · national
Continuity (1)
Related Publication 20170048114A1 · Feb 16, 2017