IP Library Granted Patent US 12,306,978
Granted Patent B2
US 12,306,978 · App. 17/992,030 · Granted May 20, 2025

Tenant access protection via an intermediary computer system

Inventors: Liangyi Huang (Taoyuan, TW); Yao Wen Chang (Taipei, TW)
Assignee: RUCKUS IP HOLDINGS LLC
G06F21/6218G06F21/45
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,306,978
App. No.
17/992,030
Granted
May 20, 2025
Kind
B2
Abstract

During operation, a computer system may receive, from an electronic device, an access request to access a shared network in a multi-tenant system, where the electronic device associated with a tenant in the multi-tenant system. Then, the computer system may identify a second computer system, which may be associated with an MSP of the shared network and that provides authentication and/or authorization to the shared network for users associated with the tenant. Moreover, the computer system may provide, to the second computer system, an authorization request for the electronic device. Next, the computer system may receive, from the second computer system, an authorization response, where the authorization response approves access by the electronic device to the shared network. Furthermore, the computer system may provide, to the electronic device, an access response, where the access response includes information specifying access privileges of the electronic device in the shared network.

Claims (37)

1. A computer system, comprising:

an interface circuit configured to communicate with an electronic device associated with a tenant in a multi-tenant system, and with a second computer system associated with a managed service provider (MSP) of a shared network in the multi-tenant system, wherein the MSP is different from the tenant, and wherein the computer system is configured to:

receive, associated with the electronic device, an access request to access the shared network;

identify the second computer system, which provides authentication and authorization to the shared network for users associated with the tenant;

provide, addressed to the second computer system, an authorization request for the electronic device;

receive, associated with the second computer system, an authorization response, wherein the authorization response approves access by the electronic device to the shared network;

determine a mapping to a partner domain administrator of the electronic device based at least in part on a lightweight directory access protocol (LDAP) group or a vendor specific attribute (VSA) specified in the authorization response; and

provide, addressed to the electronic device, an access response, wherein the access response comprises information specifying access privileges of the electronic device in the shared network and the partner domain administrator.

2. The computer system of claim 1 , wherein the access request and the authorization request comprise login credentials of the electronic device or a user of the electronic device.

3. The computer system of claim 1 , wherein the second computer system comprises: an active-directory server, an authentication, authorization and accounting (AAA) server, a LDAP server, a remote authentication dial-in user service (RADIUS) server, or a terminal access controller access control system plus (TACACS+) server.

4. The computer system of claim 1 , wherein communication between the electronic device and the computer system, the computer system and the second computer system, or both uses transport layer security (TLS).

5. The computer system of claim 1 , wherein the computer system is configured to notify a single-sign-on (SSO) manager about the mapping to the partner domain administrator.

6. The computer system of claim 1 , wherein the MSP and the tenant are associated with different entities.

7. A non-transitory computer-readable storage medium for use in conjunction with a computer system, the computer-readable storage medium storing program instructions that, when executed by the computer system, cause the computer system to perform operations comprising:

receiving, from an electronic device, an access request to access a shared network in a multi-tenant system, wherein the electronic device associated with a tenant in the multi-tenant system;

identifying a second computer system, which is associated with a managed service provider (MSP) of a shared network in the multi-tenant system, wherein the MSP is different from the tenant, and the MSP provides authentication and authorization to the shared network for users associated with the tenant;

providing, to the second computer system, an authorization request for the electronic device;

receiving, from the second computer system, an authorization response, wherein the authorization response approves access by the electronic device to the shared network; and

determining a mapping to a partner domain administrator of the electronic device based at least in part on a lightweight directory access protocol (LDAP) group or a vendor specific attribute (VSA) specified in the authorization response;

providing, to the electronic device, an access response, wherein the access response comprises information specifying access privileges of the electronic device in the shared network and the partner domain administrator.

8. The non-transitory computer-readable storage medium of claim 7 , wherein the access request and the authorization request comprise login credentials of the electronic device or a user of the electronic device.

9. The non-transitory computer-readable storage medium of claim 7 , wherein the second computer system comprises: an active-directory server, an authentication, authorization and accounting (AAA) server, a LDAP server, a remote authentication dial-in user service (RADIUS) server, or a terminal access controller access control system plus (TACACS+) server.

10. The non-transitory computer-readable storage medium of claim 7 , wherein communication between the electronic device and the computer system, the computer system and the second computer system, or both uses transport layer security (TLS).

11. The non-transitory computer-readable storage medium of claim 7 , wherein the operations notifying a single-sign-on (SSO) manager about the mapping to the partner domain administrator.

12. A method for providing an authorization request, comprising:

by a computer system:

receiving, from an electronic device, an access request to access a shared network in a multi-tenant system, wherein the electronic device associated with a tenant in the multi-tenant system;

identifying a second computer system, which is associated with a managed service provider (MSP) of a shared network in the multi-tenant system, wherein the MSP is different from the tenant, and the MSP provides authentication and authorization to the shared network for users associated with the tenant;

providing, to the second computer system, the authorization request for the electronic device;

receiving, from the second computer system, an authorization response, wherein the authorization response approves access by the electronic device to the shared network; and

determining a mapping to a partner domain administrator of the electronic device based at least in part on a lightweight directory access protocol (LDAP) group or a vendor specific attribute (VSA) specified in the authorization response;

providing, to the electronic device, an access response, wherein the access response comprises information specifying access privileges of the electronic device in the shared network and the partner domain administrator.

13. The method of claim 12 , wherein the access request and the authorization request comprise login credentials of the electronic device or a user of the electronic device.

14. The method of claim 12 , wherein the second computer system comprises: an active-directory server, an authentication, authorization and accounting (AAA) server, a LDAP server, a remote authentication dial-in user service (RADIUS) server, or a terminal access controller access control system plus (TACACS+) server.

15. The method of claim 12 , wherein communication between the electronic device and the computer system, the computer system and the second computer system, or both uses transport layer security (TLS).

16. The method of claim 12 , wherein the method comprises notifying a single-sign-on (SSO) manager about the mapping to the partner domain administrator.

17. The method of claim 12 , wherein the MSP and the tenant are associated with different entities.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067620/0675 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 074593/0001 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067620/0717 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 069743/0220 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2024
From: HUANG, LIANGYI; CHANG, YAO WEN
To: ARRIS ENTERPRISES LLC
Reel/Frame 068437/0060 →
PATENT SECURITY AGREEMENT (TERM) Recorded Jun 4, 2024
From: RUCKUS IP HOLDINGS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067620/0717 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jun 4, 2024
From: RUCKUS IP HOLDINGS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067620/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2024
From: ARRIS ENTERPRISES LLC
To: RUCKUS IP HOLDINGS LLC
Reel/Frame 066399/0561 →
Continuity (2)
Provisional Application 63283610 · Nov 29, 2021
Related Publication 20230169196A1 · Jun 1, 2023
References Cited (4)
US 9992186B1 · Drozd · 2018 [cited by examiner]
US 10057246B1 · Drozd · 2018 [cited by examiner]
US 20150381623A1 · Mattson · 2015 [cited by examiner]
Wankhede et al. “Secure and Multi-tenant Hadoop Cluster—An Experience”, 2016 2nd International Conference on Green High Performance Computing (ICGHPC), Date of Conference: Feb. 26-27 (Year: 2016). [cited by examiner]