IP Library › Granted Patent US 12,101,320
Granted Patent B2
US 12,101,320 · App. 17/582,810 · Granted Sep 24, 2024

Managing on-premises and off-premises access control

Inventors: Muzhar S. Khokhar (Shrewsbury, MA); Michael G. Varteresian (Lexington, MA); Wenfeng Li (Shanghai, CN); Haijun Zhong (Shanghai, CN); Chen Liang (Shanghai, CN); Donald Mace (Hopkinton, MA); Stéphane Meng (Shanghai, CN)
Assignee: Dell Products L.P.
H04L63/10H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,101,320
App. No.
17/582,810
Granted
Sep 24, 2024
Kind
B2
Abstract

A disclosed method for managing access control in cloud based environment with on-premises and off-premises access portals includes storing account mapping information, indicative of an association between on-premises accounts off-premises accounts, to a lockbox in each of the plurality of clusters and deploying an off-premises agent in each of the clusters. One or more of the clusters may exist within a hyper-converged infrastructure system. Each off-premises agent may be configured to retrieve cluster access information indicative of access permissions for the on-premises node cluster and upload the cluster access information to an off-premises access control service. The access permissions for the on-premises cluster and the off-premises access permissions may comprise role based access permissions. The off-premises access control service is coupled to an off-premises portal and enables the off-premises portal to switch its access control permissions between on-premises access permissions and off-premises permissions in accordance with the targeted resource.

Claims (35)

1. A method, comprising:

deploying, in each of a plurality of on-premises node clusters, an off-premises agent, wherein each off-premises agent deployed within an on-premises node cluster is configured to:

retrieve cluster access information indicative of access permissions for the on-premises node cluster; and

upload the cluster access information to an off-premises access control service coupled to an off-premises portal, wherein the off-premises access control service enables the off-premises portal to switch its access control permissions between off-premises access permissions and the access permissions for the on-premises node cluster based on which resource is targeted by an access request; and

responsive to an off-premises request to access an on-premises node cluster, determining whether to grant the off-premises request based on access permissions associated with the on-premises node cluster.

2. The method of claim 1 , further comprising:

responsive to an off-premises request to access an off-premises resource, determining whether to grant the off-premises request based on off-premises configuration information indicative of access permissions associated with an off-premises portal for processing requests to access off-premises resources.

3. The method of claim 2 , wherein the access permissions for the on-premises cluster comprise role based access permissions.

4. The method of claim 1 , further comprising:

storing account mapping information, indicative of an association between an on-premises account and an off-premises account, to a lockbox in each of the plurality of on-premises clusters.

5. The method of claim 1 , wherein at least one of the plurality of clusters executes within a hyper-converged infrastructure (HCI) appliance.

6. An information handling system, comprising:

a central processing unit (CPU); and

a computer readable memory including processor executable instructions that, when executed by the CPU, cause the system to perform operations, wherein the operations include:

deploying, in each of a plurality of on-premises node clusters, an off-premises agent, wherein each off-premises agent deployed within an on-premises node cluster is configured to:

retrieve cluster access information indicative of access permissions for the on-premises node cluster; and

upload the cluster access information to an off-premises access control service coupled to an off-premises portal, wherein the off-premises access control service enables the off-premises portal to switch its access control permissions between off-premises access permissions and the access permissions for the on-premises node cluster based on which resource is targeted by an access request; and

responsive to an off-premises request to access an on-premises node cluster, determining whether to grant the off-premises request based on access permissions associated with the on-premises node cluster.

7. The information handling system of claim 6 , wherein the operations include:

responsive to an off-premises request to access an off-premises resource, determining whether to grant the off-premises request based on off-premises configuration information indicative of access permissions associated with an off-premises portal for processing requests to access off-premises resources.

8. The information handling system of claim 7 , wherein the access permissions for the on-premises cluster comprise role based access permissions.

9. The information handling system of claim 6 , wherein the operations include:

storing account mapping information, indicative of an association between an on-premises account and an off-premises account, to a lockbox in each of the plurality of on-premises clusters.

10. The information handling system of claim 6 , wherein at least one of the plurality of clusters executes within a hyper-converged infrastructure (HCI) appliance.

11. A non-transitory computer readable medium, including processor executable instructions that, when executed by a processor, cause the processor to perform operations including:

deploying, in each of a plurality of on-premises node clusters, an off-premises agent, wherein each off-premises agent deployed within an on-premises node cluster is configured to:

retrieve cluster access information indicative of access permissions for the on-premises node cluster; and

upload the cluster access information to an off-premises access control service coupled to an off-premises portal, wherein the off-premises access control service enables the off-premises portal to switch its access control permissions between off-premises access permissions and the access permissions for the on-premises node cluster based on which resource is targeted by an access request; and

responsive to an off-premises request to access an on-premises node cluster, determining whether to grant the off-premises request based on access permissions associated with the on-premises node cluster.

12. The non-transitory computer readable medium of claim 11 , wherein the operations include:

responsive to an off-premises request to access an off-premises resource, determining whether to grant the off-premises request based on off-premises configuration information indicative of access permissions associated with an off-premises portal for processing requests to access off-premises resources.

13. The non-transitory computer readable medium of claim 12 , wherein the access permissions for the on-premises cluster comprise role based access permissions.

14. The non-transitory computer readable medium of claim 11 , wherein the operations include:

storing account mapping information, indicative of an association between an on-premises account and an off-premises account, to a lockbox in each of the plurality of on-premises clusters.

15. The non-transitory computer readable medium of claim 11 , wherein at least one of the plurality of clusters executes within a hyper-converged infrastructure (HCI) appliance.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2022
From: KHOKHAR, MUZHAR S.; .VARTERESIAN, MICHAEL G; LI, WENFENG; ZHONG, HAIJUN; LIANG, CHEN; MACE, DONALD; MENG, STÉPHANE
To: DELL PRODUCTS L.P.
Reel/Frame 061550/0426 →
Continuity (1)
Related Publication 20230239298A1 · Jul 27, 2023
Cited By (1)
US 12,204,669