IMPLICITLY LINKING ACCESS POLICIES USING GROUP NAMES
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for implicitly linking access policies using group names. One of the methods includes receiving first information corresponding to a directory service of network users, the directory service configured to organize the network users into a plurality of user roles, receiving second information corresponding to a resource available to the network users, the resource having a plurality of policy groups, identifying at least one first user role name that matches at least one first policy group name, and linking the user role corresponding to the matched first user role name with the policy group corresponding to the matched first policy group name such that the one or more network users in the linked user role are subject to the usage policies associated with the linked policy group.
1 . A system comprising a data processing apparatus and one or more non-transitory storage devices storing instructions that are operable, when executed by the data processing apparatus, to cause the data processing apparatus to perform operations comprising:
receiving, from a first device connected to the data processing apparatus through a network, a request to allow a second device access to a network connected resource, wherein the second device is associated with a user role name for the second device, and the user role name comprises a first human-readable string;
in response to receiving the request, comparing the first human-readable string for the user role name with each second human-readable string in a plurality of second human-readable strings, wherein each of the second human-readable strings in the plurality of second human-readable strings comprises a network policy group name for a network policy group in a plurality of network policy groups;
based on comparing the first human-readable string for the user role name with each second human-readable string in the plurality of second human-readable strings, selecting, from the plurality of network policy groups, a network policy group that has, as a network policy group name, a second human-readable string that is the same as the first human-readable string, wherein the second human-readable string for the selected network policy group is from the plurality of second human-readable strings; and
determining whether to allow or block the second device's access to the network connected resource based on the selected network policy group.
2 . The system of claim 1 , wherein determining whether to allow or block the second device's access to the network connected resource using the network policy group comprises determining to allow the second device access to the network connected resource based on the network policy group.
3 . The system of claim 1 , wherein determining whether to allow or block the second device's access to the network connected resource using the network policy group comprises determining to deny the second device access to the network connected resource based on the network policy group.
4 . The system of claim 1 , wherein:
the system comprises the network connected resource; and
the network connected resource comprises the data processing apparatus and the one or more storage devices.
5 . The system of claim 4 , wherein the network connected device comprises, stored in a non-transitory memory, data for the plurality of network policy groups including the network policy group.
6 . The system of claim 1 , wherein:
the system comprises a content management device; and
the content management device comprises the data processing apparatus and the one or more storage devices.
7 . The system of claim 1 , wherein:
the system comprises an access control server; and
the access control server comprises:
the data processing apparatus and the one or more storage devices; and
a non-transitory memory that includes data for the plurality of network policy groups including the network policy group.
8 . The system of claim 1 , wherein the first device is the same device as the second device.
9 . The system of claim 1 , wherein:
the first device is a different device from the second device; and
the first device receives a network access request for the second device and, in response, provides the request to the data processing apparatus.
10 . The system of claim 1 , wherein a device that includes the data processing apparatus is manufactured by a first hardware manufacturer and the first device is manufactured by a second hardware manufacturer that is different from the first hardware manufacturer.
11 . The system of claim 10 , wherein:
the first hardware manufacturer uses a first network service that is a different network service from a second network service used by the second hardware manufacturer; and
the device that includes the data processing apparatus and the first device both access a directory service hosted by a directory server.
12 . The system of claim 1 , the operations comprising:
requesting, from an access control server that includes data for a second plurality of network policy groups, data for the plurality of network policy groups, wherein the plurality of network policy groups comprise a subset of network policy groups from the second plurality of network policy groups; and
receiving, from the access control server, the data for the plurality of network policy groups.
13 . The system of claim 1 , the operations comprising:
in response to receiving the request, requesting, from a directory server hosting a directory service, the user role name for the second device by providing the directory server an identifier for the second device; and
receiving, from the directory server, the user role name for the second device in response to requesting the user role name for the second device, wherein comparing the first human-readable string for the user role name with each second human-readable string in a plurality of second human-readable strings is responsive to receiving the user role name for the second device.
14 . The system of claim 1 , wherein the request identifies the user role name for the second device.
15 . A method comprising:
receiving, from a first device connected to a data processing apparatus through a network, a request to allow a second device access to a network connected resource, wherein the second device is associated with a user role name for the second device, and the user role name comprises a first human-readable string;
in response to receiving the request, comparing the first human-readable string for the user role name with each second human-readable string in a plurality of second human-readable strings, wherein each of the second human-readable strings in the plurality of second human-readable strings comprises a network policy group name for a network policy group in a plurality of network policy groups;
based on comparing the first human-readable string for the user role name with each second human-readable string in the plurality of second human-readable strings, selecting, from the plurality of network policy groups, a network policy group that has, as a network policy group name, a second human-readable string that is the same as the first human-readable string, wherein the second human-readable string for the selected network policy group is from the plurality of second human-readable strings; and
determining whether to allow or block the second device's access to the network connected resource based on the selected network policy group.
16 . The method of claim 15 , wherein determining whether to allow or block the second device's access to the network connected resource using the network policy group comprises determining to allow the second device access to the network connected resource based on the network policy group.
17 . The method of claim 15 , wherein determining whether to allow or block the second device's access to the network connected resource using the network policy group comprises determining to deny the second device access to the network connected resource based on the network policy group.
18 . The method of claim 15 , wherein the network connected resource comprises the data processing apparatus.
19 . The method of claim 18 , wherein the network connected device comprises, stored in a non-transitory memory, data for the plurality of network policy groups including the network policy group.
20 . The method of claim 15 , wherein:
the first device is a different device from the second device; and
the first device receives a network access request for the second device and, in response, provides the request to the data processing apparatus.
21 . The method of claim 15 , wherein a device that includes the data processing apparatus is manufactured by a first hardware manufacturer and the first device is manufactured by a second hardware manufacturer that is different from the first hardware manufacturer.
22 . The method of claim 21 , wherein:
the first hardware manufacturer uses a first network service that is a different network service from a second network service used by the second hardware manufacturer; and
the device that includes the data processing apparatus and the first device both access a directory service hosted by a directory server.
23 . The method of claim 15 , further comprising:
requesting, from an access control server that includes data for a second plurality of network policy groups, data for the plurality of network policy groups, wherein the plurality of network policy groups comprise a subset of network policy groups from the second plurality of network policy groups; and
receiving, from the access control server, the data for the plurality of network policy groups.
24 . The method of claim 15 , further comprising:
in response to receiving the request, requesting, from a directory server hosting a directory service, the user role name for the second device by providing the directory server an identifier for the second device; and
receiving, from the directory server, the user role name for the second device in response to requesting the user role name for the second device, wherein comparing the first human-readable string for the user role name with each second human-readable string in a plurality of second human-readable strings is responsive to receiving the user role name for the second device.
25 . The method of claim 15 , wherein the request identifies the user role name for the second device.
26 . A non-transitory computer storage medium encoded with instructions that, when executed by one or more computers, cause the one or more computers to perform operations comprising:
receiving, from a first device connected to a data processing apparatus through a network, a request to allow a second device access to a network connected resource, wherein the second device is associated with a user role name for the second device, and the user role name comprises a first human-readable string;
in response to receiving the request, comparing the first human-readable string for the user role name with each second human-readable string in a plurality of second human-readable strings, wherein each of the second human-readable strings in the plurality of second human-readable strings comprises a network policy group name for a network policy group in a plurality of network policy groups;
based on comparing the first human-readable string for the user role name with each second human-readable string in the plurality of second human-readable strings, selecting, from the plurality of network policy groups, a network policy group that has, as a network policy group name, a second human-readable string that is the same as the first human-readable string, wherein the second human-readable string for the selected network policy group is from the plurality of second human-readable strings; and
determining whether to allow or block the second device's access to the network connected resource based on the selected network policy group.
27 . The computer storage medium of claim 26 , wherein a device that includes the data processing apparatus is manufactured by a first hardware manufacturer and the first device is manufactured by a second hardware manufacturer that is different from the first hardware manufacturer.
28 . The computer storage medium of claim 27 , wherein:
the first hardware manufacturer uses a first network service that is a different network service from a second network service used by the second hardware manufacturer; and
the device that includes the data processing apparatus and the first device both access a directory service hosted by a directory server.
29 . The computer storage medium of claim 28 , the operations further comprising:
requesting, from an access control server that includes data for a second plurality of network policy groups, data for the plurality of network policy groups, wherein the plurality of network policy groups comprise a subset of network policy groups from the second plurality of network policy groups; and
receiving, from the access control server, the data for the plurality of network policy groups.
30 . The computer storage medium of claim 28 , the operations further comprising:
in response to receiving the request, requesting, from a directory server hosting a directory service, the user role name for the second device by providing the directory server an identifier for the second device; and
receiving, from the directory server, the user role name for the second device in response to requesting the user role name for the second device, wherein comparing the first human-readable string for the user role name with each second human-readable string in a plurality of second human-readable strings is responsive to receiving the user role name for the second device.