IP Library Patent Application 17824751
Patent Application
App. No. 17/824,751

MANAGING USER IDENTITIES IN A MANAGED MULTI-TENANT SERVICE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/824,751
Filed
May 25, 2022
Art Unit
2457
USPC
726/7
Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for processing data in a multi-tenant system. One of the methods includes receiving a data processing job associated with a user account of a user; determining to launch the data processing job on one or more cloud clusters of a cloud services provider; identifying a mirror account corresponding to the user, wherein the mirror account defines which cloud resources of the cloud services provider the user is permitted to access; obtaining a key for the mirror account; sending a request to launch the data processing job on the one or more cloud clusters, comprising sending data characterizing the data processing job, the mirror account of the user, and the obtained key to the one or more cloud clusters; and receiving output data associated with the data processing job from the one or more cloud clusters.

Claims (64)

1 . (canceled)

2 . A method comprising:

generating data representing a user account for a user, wherein the user account is used to authenticate requests for accessing resources of an enterprise environment, and wherein a cloud services account of the user is used to authenticate requests for accessing a first set of resources of a cloud services provider;

associating the user account of the user with one or more permissions to perform data processing on one or more cloud clusters of the cloud services provider;

generating a mirror account corresponding to the user account of the user, wherein:

the mirror account is used to authenticate requests for accessing a second set of resources of the cloud services provider, and

the mirror account is distinct from the user account and the cloud services account of the user; and

establishing credentials for the mirror account, comprising:

defining access permissions to the second set of resources of the cloud services provider according to the one or more permissions associated with the user account, and

generating one or more credentials for the mirror account.

3 . The method of claim 2 , wherein associating the user account of the user with one or more permissions to perform data processing on the one or more cloud clusters of the cloud services provider comprises:

associating the user account of the user with one or more groups of users of the enterprise environment, wherein different groups of users have access to respective different portions of the second set of resources of the cloud services provider.

4 . The method of claim 2 , wherein the access permissions corresponding to the mirror account do not provide access to the first set of resources of the cloud services provider.

5 . The method of claim 2 , further comprising:

storing the one or more credentials for the mirror account in a secure data store; and

periodically updating the one or more credentials for the mirror account.

6 . The method of claim 2 , wherein the one or more cloud clusters use the mirror account to authorize one or more requests submitted by respective data processing jobs launched on the cloud clusters and associated with the mirror account, the one or more requests being associated with at least a subset of the second set of resources of the cloud services provider, the authorizing comprising determining whether the user is permitted to access the subset.

7 . The method of claim 2 , wherein the one or more cloud clusters use the mirror account to audit one or more requests submitted by respective data processing jobs launched on the cloud clusters and associated with the mirror account, the auditing comprising generating one or more logs associated with the requests and with the user.

8 . The method of claim 2 , further comprising:

receiving a data processing job associated with the user account of the user;

sending a request to launch the data processing job on at least one of the cloud clusters of the cloud services provider, the request being associated with one or more of the mirror account or the credentials for the mirror account; and

receiving output data associated with the data processing job from the at least one cloud cluster.

9 . A system comprising one or more computers and one or more storage devices storing instructions that when executed by the one or more computers cause the one or more computers to perform operations comprising:

generating data representing a user account for a user, wherein the user account is used to authenticate requests for accessing resources of an enterprise environment, and wherein a cloud services account of the user is used to authenticate requests for accessing a first set of resources of a cloud services provider;

associating the user account of the user with one or more permissions to perform data processing on one or more cloud clusters of the cloud services provider;

generating a mirror account corresponding to the user account of the user, wherein:

the mirror account is used to authenticate requests for accessing a second set of resources of the cloud services provider, and

the mirror account is distinct from the user account and the cloud services account of the user; and

establishing credentials for the mirror account, comprising:

defining access permissions to the second set of resources of the cloud services provider according to the one or more permissions associated with the user account, and

generating one or more credentials for the mirror account.

10 . The system of claim 9 , wherein associating the user account of the user with one or more permissions to perform data processing on the one or more cloud clusters of the cloud services provider comprises:

associating the user account of the user with one or more groups of users of the enterprise environment, wherein different groups of users have access to respective different portions of the second set of resources of the cloud services provider.

11 . The system of claim 9 , wherein the access permissions corresponding to the mirror account do not provide access to the first set of resources of the cloud services provider.

12 . The system of claim 9 , the operations further comprising:

storing the one or more credentials for the mirror account in a secure data store; and

periodically updating the one or more credentials for the mirror account.

13 . The system of claim 9 , wherein the one or more cloud clusters use the mirror account to authorize one or more requests submitted by respective data processing jobs launched on the cloud clusters and associated with the mirror account, the one or more requests being associated with at least a subset of the second set of resources of the cloud services provider, the authorizing comprising determining whether the user is permitted to access the subset.

14 . The system of claim 9 , wherein the one or more cloud clusters use the mirror account to audit one or more requests submitted by respective data processing jobs launched on the cloud clusters and associated with the mirror account, the auditing comprising generating one or more logs associated with the requests and with the user.

15 . The system of claim 9 , the operations further comprising:

receiving a data processing job associated with the user account of the user;

sending a request to launch the data processing job on at least one of the cloud clusters of the cloud services provider, the request being associated with one or more of the mirror account or the credentials for the mirror account; and

receiving output data associated with the data processing job from the at least one cloud cluster.

16 . One or more non-transitory computer storage media encoded with computer program instructions that when executed by one or more computers cause the one or more computers to perform operations comprising:

generating data representing a user account for a user, wherein the user account is used to authenticate requests for accessing resources of an enterprise environment, and wherein a cloud services account of the user is used to authenticate requests for accessing a first set of resources of a cloud services provider;

associating the user account of the user with one or more permissions to perform data processing on one or more cloud clusters of the cloud services provider;

generating a mirror account corresponding to the user account of the user, wherein:

the mirror account is used to authenticate requests for accessing a second set of resources of the cloud services provider, and

the mirror account is distinct from the user account and the cloud services account of the user; and

establishing credentials for the mirror account, comprising:

defining access permissions to the second set of resources of the cloud services provider according to the one or more permissions associated with the user account, and

generating one or more credentials for the mirror account.

17 . The non-transitory computer storage media of claim 16 , wherein associating the user account of the user with one or more permissions to perform data processing on the one or more cloud clusters of the cloud services provider comprises:

associating the user account of the user with one or more groups of users of the enterprise environment, wherein different groups of users have access to respective different portions of the second set of resources of the cloud services provider.

18 . The non-transitory computer storage media of claim 16 , wherein the access permissions corresponding to the mirror account do not provide access to the first set of resources of the cloud services provider.

19 . The non-transitory computer storage media of claim 16 , the operations further comprising:

storing the one or more credentials for the mirror account in a secure data store; and

periodically updating the one or more credentials for the mirror account.

20 . The non-transitory computer storage media of claim 16 , wherein the one or more cloud clusters use the mirror account to authorize one or more requests submitted by respective data processing jobs launched on the cloud clusters and associated with the mirror account, the one or more requests being associated with at least a subset of the second set of resources of the cloud services provider, the authorizing comprising determining whether the user is permitted to access the subset.

21 . The non-transitory computer storage media of claim 16 , wherein the one or more cloud clusters use the mirror account to audit one or more requests submitted by respective data processing jobs launched on the cloud clusters and associated with the mirror account, the auditing comprising generating one or more logs associated with the requests and with the user.

22 . The non-transitory computer storage media of claim 16 , the operations further comprising:

receiving a data processing job associated with the user account of the user;

sending a request to launch the data processing job on at least one of the cloud clusters of the cloud services provider, the request being associated with one or more of the mirror account or the credentials for the mirror account; and

receiving output data associated with the data processing job from the at least one cloud cluster.

Assignments (6)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS (REEL 062079, FRAME 0677) Recorded Mar 3, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: X CORP. (F/K/A TWITTER, INC.)
Reel/Frame 075015/0574 →
RELEASE OF SECURITY INTEREST Recorded Apr 30, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: X CORP. (F/K/A TWITTER, INC.)
Reel/Frame 071127/0240 →
RELEASE OF SECURITY INTEREST Recorded Mar 27, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: X CORP. (F/K/A TWITTER, INC.)
Reel/Frame 070670/0857 →
SECURITY INTEREST Recorded Oct 28, 2022
From: TWITTER, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 061804/0001 →
SECURITY INTEREST Recorded Oct 28, 2022
From: TWITTER, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 061804/0086 →
SECURITY INTEREST Recorded Oct 28, 2022
From: TWITTER, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 062079/0677 →