IP Library Granted Patent US 10,834,086
Granted Patent B1
US 10,834,086 · App. 15/235,770 · Granted Nov 10, 2020

Hybrid cloud-based authentication for flash storage array access

Inventors: Benjamin P. Borowiec (Santa Clara, CA); Jimmy T. Hu (Foster City, CA); Ethan L. Miller (Santa Cruz, CA); Terence W. Noonan (Vadnais Heights, MN); Constantine P. Sapuntzakis (Mountain View, CA); Neil A. Vachharajani (San Francisco, CA); Daquan Zuo (Sunnyvale, CA)
Assignee: Pure Storage, Inc.
H04L63/102H04L9/30H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,834,086
App. No.
15/235,770
Granted
Nov 10, 2020
Kind
B1
Abstract

Providing authorization and authentication in a cloud for a user of a storage array includes: receiving, by a storage array access module from a client-side array services module, a token representing authentication of user credentials and authorized access privileges defining one or more storage array services accessible by the user, where the token is generated by a cloud-based security module upon authentication of the user credentials and identification of authorized access privileges for the user; receiving, by the storage array access module from the user, a user access request to one or more storage array services; and determining, by the storage array access module, whether to grant the user access request in dependence upon the authorized access privileges represented by the token.

Claims (38)

1. A method comprising:

sending, by a storage array access module to the client-side array services module, a redirect to a cloud-based security module distinct from the storage array access module;

receiving, by the storage array access module from the client-side array services module, a token generated by the cloud-based security module and provided by the cloud-based security module to the client-side array services module, wherein the token indicates an authentication of the user input credentials from the client-side array services module by the cloud-based security module and authorized access privileges defined by the cloud-based security module for the user for one or more storage array services; and

granting, by the storage array access module utilizing the access privileges for the user indicated by the token generated by the cloud-based security module, access to the user to the one or more storage array services.

2. The method of claim 1 , wherein the cloud-based security module comprises a cloud identity provider (‘IDP’).

3. The method of claim 1 , wherein the cloud-based security module comprises a component of a cloud-based storage array services provider.

4. The method of claim 1 , wherein the cloud-based security module comprises a lightweight directory access protocol directory service.

5. The method of claim 1 , wherein:

access privileges are further defined in the storage array access module for a plurality of users; and

determining whether to grant the user access request in dependence upon the access privileges defined in the storage array access module as well as the token.

6. The method of claim 1 , wherein access privileges are defined in the cloud-based security module for a plurality of users with an association of each user with one of a plurality of profiles, each profile specifying access privileges for users associated with the profile.

7. The method of claim 6 , wherein the plurality of profiles comprise:

a read-only profile specifying, for users associated with the read only profile, read-only access privileges;

a modify profile specifying, for users associated with the modify profile, read and modify access privileges; and

an administrator profile specifying, for users associated with the administrator profile, all available access privileges.

8. The method of claim 6 , wherein the plurality of profiles comprise at least one storage-array specific profile specifying access privileges for a single storage array and multi-array profiles specifying access privileges for a plurality of storage arrays.

9. The method of claim 1 , wherein the token further comprises data representing a digital signature and the method further comprises:

decrypting the digital signature using a public key of the cloud-based security module.

10. An apparatus for comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

sending, by a storage array access module to the client-side array services module, a redirect to a cloud-based security module distinct from the storage array access module;

receiving, by the storage array access module from the client-side array services module, a token generated by the cloud-based security module and provided by the cloud-based security module to the client-side array services module, wherein the token indicates an authentication of the user input credentials from the client-side array services module by the cloud-based security module and authorized access privileges defined by the cloud-based security module for the user for one or more storage array services; and

granting, by the storage array access module utilizing the access privileges for the user indicated by the token generated by the cloud-based security module, access to the user to the one or more storage array services.

11. The apparatus of claim 10 , wherein the cloud-based security module comprises a cloud identity provider (‘IDP’).

12. The apparatus of claim 10 , wherein the cloud-based security module comprises a component of a cloud-based storage array services provider.

13. The apparatus of claim 10 , wherein:

access privileges are further defined in the storage array access module for a plurality of users; and

determining whether to grant the user access request in dependence upon the access privileges defined in the storage array access module as well as the token.

14. The apparatus of claim 10 , wherein access privileges are defined in the cloud-based security module for a plurality of users with an association of each user with one of a plurality of profiles, each profile specifying access privileges for users associated with the profile.

15. The apparatus of claim 13 , wherein the plurality of profiles comprise at least one storage-array specific profile specifying access privileges for a single storage array and multi-array profiles specifying access privileges for a plurality of storage arrays.

16. A computer program product disposed upon a non-transitory computer readable medium, wherein the non-transitory computer readable medium is not a signal, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out the steps of:

sending, by a storage array access module to the client-side array services module, a redirect to a cloud-based security module distinct from the storage array access module;

receiving, by the storage array access module from the client-side array services module, a token generated by the cloud-based security module and provided by the cloud-based security module to the client-side array services module, wherein the token indicates an authentication of the user input credentials from the client-side array services module by the cloud-based security module and authorized access privileges defined by the cloud-based security module for the user for one or more storage array services; and

granting, by the storage array access module utilizing the access privileges for the user indicated by the token generated by the cloud-based security module, access to the user to the one or more storage array services.

17. The computer program product of claim 16 , wherein the cloud-based security module comprises a cloud identity provider (‘IDP’).

18. The computer program product of claim 16 , wherein the cloud-based security module comprises a component of a cloud-based storage array services provider.

19. The computer program product of claim 16 , wherein: access privileges are further defined in the storage array access module for a plurality of users; and

determining whether to grant the user access request in dependence upon the access privileges defined in the storage array access module as well as the token.

20. The computer program product of claim 16 , wherein access privileges are defined in the cloud-based security module for a plurality of users with an association of each user with one of a plurality of profiles, each profile specifying access privileges for users associated with the profile.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2016
From: BOROWIEC, BENJAMIN P.; HU, JIMMY T.; MILLER, ETHAN L.; NOONAN, TERENCE W.; SAPUNTZAKIS, CONSTANTINE P.; VACHHARAJANI, NEIL A.; ZUO, DAQUAN
To: PURE STORAGE, INC.
Reel/Frame 039421/0380 →
Continuity (1)
Continuation 14726449 · May 29, 2015
Cited By (1)
US 12,719,876