IP Library › Granted Patent US 10,505,941
Granted Patent B2
US 10,505,941 · App. 15/665,157 · Granted Dec 10, 2019

Virtual directory system for LDAP to SCIM proxy service

Inventors: Kanika Vats (Bangalore, IN); Vinoth Janakiraman (Bangalore, IN); Manohari Neelakanteshwar (Bangalore, IN); Rajesh Purushothaman (Bangalore, IN); Loganathan Ramasamy (Bangalore, IN); Anand Murugesan (Fremont, CA); Hari Sastry (San Jose, CA)
Assignee: Oracle International Corporation
H04L63/102G06F16/188G06F21/629H04L63/0281H04L63/104H04L67/1095H04L67/2838H04L67/306H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,941
App. No.
15/665,157
Granted
Dec 10, 2019
Kind
B2
Abstract

A method for providing an on-premises virtual directory system for an LDAP (Lightweight Directory Access Protocol) to SCIM (System for Cross-domain Identity Management) proxy service is provided. The method includes providing an LDAP Directory Information Tree (DIT) including LDAP DIT entries, providing a SCIM directory including SCIM resource entries, migrating the LDAP DIT entries to the SCIM directory, creating a virtual LDAP hierarchy based on LDAP DIT hierarchical information stored in the SCIM directory, and displaying a graphical user interface (GUI) for a directory services application that includes a data tree pane that depicts the virtual LDAP hierarchy. Creating the virtual LDAP hierarchy includes storing the LDAP DIT hierarchical information in the SCIM directory by mapping LDAP containers to SCIM user or SCIM group attributes, mapping LDAP containers to special marker SCIM groups, mapping LDAP user DNs to SCIM user externalIDs, or mapping LDAP group DNs to SCIM group externalIDs.

Claims (56)

1. A non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor, cause the processor to provide an on-premises virtual directory system for an LDAP (Lightweight Directory Access Protocol) to SCIM (System for Cross-domain Identity Management) proxy service, the providing comprising:

providing an LDAP Directory Information Tree (DIT) including a plurality of LDAP DIT entries that describe LDAP containers, LDAP users and LDAP groups, each LDAP DIT entry including a Distinguished Name (DN) and a plurality of LDAP attribute-value pairs, the DN providing LDAP DIT hierarchical information that uniquely identifies the LDAP DIT entry and describes a hierarchical position of the LDAP DIT entry in the LDAP DIT, each LDAP attribute-value pair including an attribute name and one or more attribute values;

providing a SCIM directory including a plurality of SCIM resource entries that describe SCIM users and SCIM groups, each SCIM resource entry including a plurality of SCIM attributes including an externalID and a resource type identifying the SCIM resource entry as belonging to a user or a group, each SCIM attribute including a name and one or more values;

migrating the plurality of LDAP DIT entries to the SCIM directory, including storing the LDAP DIT hierarchical information in the SCIM directory by:

mapping LDAP containers to SCIM user or SCIM group attributes,

mapping LDAP containers to special marker SCIM groups,

mapping LDAP user DNs to SCIM user externalIDs, or

mapping LDAP group DNs to SCIM group externalIDs;

creating a virtual LDAP hierarchy based on the LDAP DIT hierarchical information stored in the SCIM directory; and

displaying a graphical user interface (GUI) for a directory services application that includes a data tree pane that depicts the virtual LDAP hierarchy.

2. The computer-readable medium of claim 1 , wherein the mapping LDAP containers to SCIM user or SCIM group attributes includes, for each LDAP user or LDAP group present in an LDAP container having a DN including a Relative Distinguished Name (RDN) having an attribute name and an attribute value, adding a SCIM attribute to the corresponding SCIM user or SCIM group based on the attribute name and the attribute value of the RDN.

3. The computer-readable medium of claim 2 , wherein the attribute name of the RDN is organizational unit (OU), common name (CN), domain component (DC), organization (O) or location (L).

4. The computer-readable medium of claim 1 , wherein the mapping LDAP containers to special marker SCIM groups includes, for each LDAP user or LDAP group present in an LDAP container having DN including a Relative Distinguished Name (RDN) having an attribute name and an attribute value, creating a new SCIM group based on the attribute name and attribute value of the RDN, and adding the corresponding SCIM user or SCIM group to the new SCIM group.

5. The computer-readable medium of claim 4 , wherein the attribute name of the RDN is OU, CN, DC, O or L.

6. The computer-readable medium of claim 1 ,

wherein the mapping LDAP user DNs to SCIM user externalIDs includes, for each LDAP user, setting the corresponding SCIM user externalID to the DN of the LDAP user, and

wherein the mapping LDAP group DNs to SCIM group externalIDs includes, for each LDAP group, setting the corresponding SCIM group externalID to the DN of the LDAP group.

7. The computer-readable medium of claim 6 , wherein the DN includes a plurality of attribute-value pairs arranged in a hierarchical sequence.

8. A method for providing an on-premises virtual directory system for an LDAP (Lightweight Directory Access Protocol) to SCIM (System for Cross-domain Identity Management) proxy service, the method comprising:

providing an LDAP Directory Information Tree (DIT) including a plurality of LDAP DIT entries that describe LDAP containers, LDAP users and LDAP groups, each LDAP DIT entry including a Distinguished Name (DN) and a plurality of LDAP attribute-value pairs, the DN providing LDAP DIT hierarchical information that uniquely identifies the LDAP DIT entry and describes a hierarchical position of the LDAP DIT entry in the LDAP DIT, each LDAP attribute-value pair including an attribute name and one or more attribute values;

providing a SCIM directory including a plurality of SCIM resource entries that describe SCIM users and SCIM groups, each SCIM resource entry including a plurality of SCIM attributes including an externalID and a resource type identifying the SCIM resource entry as belonging to a User or a Group, each SCIM attribute including a name and one or more values;

migrating the plurality of LDAP DIT entries to the SCIM directory, including storing the LDAP DIT hierarchical information in the SCIM directory by:

mapping LDAP containers to SCIM user or SCIM group attributes,

mapping LDAP containers to special marker SCIM groups,

mapping LDAP user DNs to SCIM user externalIDs, or

mapping LDAP group DNs to SCIM group externalIDs;

creating a virtual LDAP hierarchy based on the LDAP DIT hierarchical information stored in the SCIM directory; and

displaying a graphical user interface (GUI) for a directory services application that includes a data tree pane that depicts the virtual LDAP hierarchy.

9. The method of claim 8 , wherein the mapping LDAP containers to SCIM user or SCIM group attributes includes, for each LDAP user or LDAP group present in an LDAP container having a DN including a Relative Distinguished Name (RDN) an RDN having an attribute name and an attribute value, adding a SCIM attribute to the corresponding SCIM user or SCIM group based on the attribute name and the attribute value of the RDN.

10. The method of claim 9 , wherein the attribute name of the RDN is organizational unit (OU), common name (CN), domain component (DC), organization (O) or location (L).

11. The method of claim 8 , wherein the mapping LDAP containers to special marker SCIM groups includes, for each LDAP user or LDAP group present in an LDAP container having DN including a Relative Distinguished Name (RDN) having an attribute name and an attribute value, creating a new SCIM group based on the attribute name and attribute value of the RDN, and adding the corresponding SCIM user or SCIM group to the new SCIM group.

12. The method of claim 11 , wherein the attribute name of the RDN is OU, CN, DC, O or L.

13. The method of claim 8 ,

wherein the mapping LDAP user DNs to SCIM user externalIDs includes, for each LDAP user, setting the corresponding SCIM user externalID to the DN of the LDAP user, and

wherein the mapping LDAP group DNs to SCIM group externalIDs includes, for each LDAP group, setting the corresponding SCIM group externalID to the DN of the LDAP group.

14. The method of claim 13 , wherein the DN includes a plurality of attribute-value pairs arranged in a hierarchical sequence.

15. A system, comprising:

a memory; and

a processor, coupled to the memory and a network, to provide an on-premises virtual directory system for an LDAP (Lightweight Directory Access Protocol) to SCIM (System for Cross-domain Identity Management) proxy service, the processor configured to:

provide an LDAP Directory Information Tree (DIT) including a plurality of LDAP DIT entries that describe LDAP containers, LDAP users and LDAP groups, each LDAP DIT entry including a Distinguished Name (DN) and a plurality of LDAP attribute-value pairs, the DN providing LDAP DIT hierarchical information that uniquely identifies the LDAP DIT entry and describes a hierarchical position of the LDAP DIT entry in the LDAP DIT, each LDAP attribute-value pair including an attribute name and one or more attribute values;

provide a SCIM directory including a plurality of SCIM resource entries that describe SCIM users and SCIM groups, each SCIM resource entry including a plurality of SCIM attributes including an externalID and a resource type identifying the SCIM resource entry as belonging to a User or a Group, each SCIM attribute including a name and one or more values;

migrate the plurality of LDAP DIT entries to the SCIM directory, including storing the LDAP DIT hierarchical information in the SCIM directory by:

mapping LDAP containers to SCIM user or SCIM group attributes,

mapping LDAP containers to special marker SCIM groups,

mapping LDAP user DNs to SCIM user externalIDs, or

mapping LDAP group DNs to SCIM group externalIDs;

create a virtual LDAP hierarchy based on the LDAP DIT hierarchical information stored in the SCIM directory; and

display a graphical user interface (GUI) for a directory services application that includes a data tree pane that depicts the virtual LDAP hierarchy.

16. The system of claim 15 , wherein the mapping LDAP containers to SCIM user or SCIM group attributes includes, for each LDAP user or LDAP group present in an LDAP container having a DN including a Relative Distinguished Name (RDN) having an attribute name and an attribute value, adding a SCIM attribute to the corresponding SCIM user or SCIM group based on the attribute name and the attribute value of the RDN.

17. The system of claim 16 , wherein the attribute name of the RDN is organizational unit (OU), common name (CN), domain component (DC), organization (O) or location (L).

18. The system of claim 15 , wherein the mapping LDAP containers to special marker SCIM groups includes, for each LDAP user or LDAP group present in an LDAP container having DN including a Relative Distinguished Name (RDN) having an attribute name and an attribute value, creating a new SCIM group based on the attribute name and attribute value of the RDN, and adding the corresponding SCIM user or SCIM group to the new SCIM group.

19. The system of claim 18 , wherein the attribute name of the RDN is OU, CN, DC, O or L.

20. The system of claim 15 ,

wherein the DN includes a plurality of attribute-value pairs arranged in a hierarchical sequence,

wherein the mapping LDAP user DNs to SCIM user externalIDs includes, for each LDAP user, setting the corresponding SCIM user externalID to the DN of the LDAP user, and

wherein the mapping LDAP group DNs to SCIM group externalIDs includes, for each LDAP group, setting the corresponding SCIM group externalID to the DN of the LDAP group.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: VATS, KANIKA; JANAKIRAMAN, VINOTH; NEELAKANTESHWAR, MANOHARI; PURUSHOTHAMAN, RAJESH; RAMASAMY, LOGANATHAN; MURUGESAN, ANAND; SASTRY, HARI
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 043153/0792 →
Priority Claims (1)
IN 201641031586 · Sep 16, 2016 · national
Continuity (4)
Provisional Application 62395405 · Sep 16, 2016
Provisional Application 62376069 · Aug 17, 2016
Provisional Application 62371336 · Aug 5, 2016
Related Publication 20180041516A1 · Feb 8, 2018
Cited By (3)
US 12,267,368 US 12,273,343 US 12,455,854