IP Library Granted Patent US 12,143,387
Granted Patent B2
US 12,143,387 · App. 16/743,567 · Granted Nov 12, 2024

Dynamic authorization in a multi-tenancy environment via tenant policy profiles

Inventors: Michael G. Roche (Hamilton, CA); Michal J. Drozd (Cracow, PL)
Assignee: EMC IP Holding Company LLC
H04L63/102H04L63/08H04L63/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,143,387
App. No.
16/743,567
Granted
Nov 12, 2024
Kind
B2
Abstract

In one example, a method for managing user access to data contained in a computing system, includes receiving a token from an authentication service, wherein the token includes an application role and associated privilege mask; receiving an authentication request from an entity seeking access to an application; comparing information in the authentication request with the token; approving the authentication request when the information in the authentication request matches the token, and granting access to the application when the authentication request has been approved, and denying access to the application when the information in the authentication request does not match the token. The receiving, comparing, approving, granting, and denying processes are performed by the application to which the entity is seeking access, and wherein when the entity, or a different entity, seeks access to another application, user access to the another application is controlled by the another application.

Claims (40)

1. A method, comprising:

managing user access to an application hosted by a computing system, by performing operations comprising:

receiving at the application, a token from an authentication component of an authorization/authentication service, which includes the authentication component and an authorization component,

wherein the token includes an application role and a privilege mask associated with the application role,

wherein the application role corresponds to a role of an entity with respect to the application, and the privilege mask defines one or more privileges, which can be granted to the entity with respect to the application upon authentication of the entity based on the role of the entity, and

wherein the token is generated by the authentication component based on the application role and the privilege mask, which has been generated by the authorization component in response to a set of characteristics sent by the authentication component to the authorization component;

receiving at the application, by way of the authorization/authentication service with which the application is in communication, an authentication request from the entity seeking access to the application;

identifying a change in the computing system;

based on the change, receiving an updated token at the application from the authorization/authentication service;

evaluating the authentication request based on the updated token;

approving the authentication request when information in the authentication request matches the updated token;

granting, to the entity, access to the application when the authentication request has been approved, wherein granting the entity access to the application comprises enabling the entity to access and run one or more functions of the application based on the privilege mask; and

denying access to the application when the information in the authentication request does not match the updated token and notifying the user the authentication request has been denied,

wherein the approving, granting, and denying processes are performed by the application to which the entity is seeking access, and

wherein, when the entity or a different entity seeks access to another application, user access to the another application is controlled by the another application.

2. The method as recited in claim 1 , wherein approval of the authentication request is based on authorization information in the token indicating that tenant characteristics match a tenant authorization profile associated with the application.

3. The method as recited in claim 1 , wherein one of the tokens is a Security Assertion Markup Language (SAML) token.

4. The method as recited in claim 1 , wherein the method is performed in a tenant environment that provides intra-application tenancy in which a user in the tenant environment does not have access to all aspects of the application.

5. The method as recited in claim 1 , wherein the method enables single sign-on (SSO) functionality that permits an authorized user to gain access to multiple independent hardware and/or software.

6. The method as recited in claim 1 , wherein one of the application and the another application is a backup application.

7. A non-transitory storage medium having stored therein instructions which are executable by one or more hardware processors, to perform:

managing user access to an application hosted by a computing system, by performing operations comprising:

receiving at the application, a token from an authentication component of an authorization/authentication service which includes the authentication component and an authorization component,

wherein the token includes an application role and an associated a privilege mask associated with the application role,

wherein the application role corresponds to a role of an entity with respect to the application, and the privilege mask defines one or more privileges, which can be granted to the entity with respect to the application upon authentication of the entity based on the role of the entity, and

wherein the token is generated by the authentication component based on the application role and the privilege mask, which has been generated by the authorization component in response to a set of characteristics sent by the authentication component to the authorization component;

receiving at the application, by way of the authorization/authentication service with which the application is in communication, an authentication request from the entity seeking access to the application;

identifying a change in the computing system;

based on the change, receiving an updated token at the application from the authorization/authentication service;

evaluating the authentication request based on the updated token;

approving the authentication request when information in the authentication request matches the updated token;

granting, to the entity, access to the application when the authentication request has been approved, wherein granting the entity access to the application comprises enabling the entity to access and run one or more functions of the application based on the privilege mask; and

denying access to the application when the information in the authentication request does not match the updated token and notifying the user the authentication request has been denied,

wherein the approving, granting, and denying processes are performed by the application to which the entity is seeking access, and

wherein, when the entity or a different entity seeks access to another application, user access to the another application is controlled by the another application.

8. The non-transitory storage medium as recited in claim 7 , wherein approval of the authentication request is based on authorization information in the token indicating that tenant characteristics match a tenant authorization profile associated with the application.

9. The non-transitory storage medium as recited in claim 7 , wherein one of the tokens is a Security Assertion Markup Language (SAML) token.

10. The non-transitory storage medium as recited in claim 7 , wherein the operations are performed in a tenant environment that provides intra-application tenancy in which a user in the tenant environment does not have access to all aspects of the application.

11. The non-transitory storage medium as recited in claim 7 , wherein performance of the operations enables single sign-on (SSO) functionality that permits an authorized user to gain access to multiple independent hardware and/or software.

12. The non-transitory storage medium as recited in claim 7 , wherein one of the application and the another application is a backup application.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2020
From: ROCHE, MICHAEL G.; DROZD, MICHAL J.
To: EMC CORPORATION
Reel/Frame 051524/0617 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2020
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 051614/0001 →