IP Library › Granted Patent US 9,390,255
Granted Patent B2
US 9,390,255 · App. 13/485,408 · Granted Jul 12, 2016

Privileged account manager, dynamic policy engine

Inventors: Himanshu Sharma (Berkeley, CA); Buddhika Kottahachchi (San Mateo, CA); Arun Theebaprakasam (Burlingame, CA); Kuang-Yu Shih (Fremont, CA)
Assignee: Oracle International Corporation
G06F21/45G06F21/31G06F21/316G06F21/46G06F21/55G06F21/554G06F21/604H04L63/083H04L63/10G06F2221/2111
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,390,255
App. No.
13/485,408
Granted
Jul 12, 2016
Kind
B2
Abstract

Techniques for managing accounts are provided. An access management system may check out credentials for accessing target systems. For example a user may receive a password for a period of time or until checked back in. Access to the target system may be logged during this time. Upon the password being checked in, a security account may modify the password so that the user may not log back in without checking out a new password. Additionally, in some examples, password policies for the security account may be managed. As such, when a password policy changes, the security account password may be dynamically updated. Additionally, in some examples, hierarchical viewing perspectives may be determined and/or selected for visualizing one or more managed accounts. Further, accounts may be organized into groups based on roles, and grants for the accounts may be dynamically updated as changes occur or new accounts are managed.

Claims (40)

1. A system, comprising:

a memory storing a plurality of instructions; and

one or more processors configured to access the memory, wherein the one or more processors are further configured to execute the plurality of instructions to:

receive a perspective selection for viewing multiple accounts based at least in part on tags assigned to registered accounts to display on a user device in a user-defined hierarchical view;

receive information that identifies a plurality of different types of accounts associated with a different type of target system external to the system that is managed by an account management service of the system, the plurality of accounts for accessing resources used by the associated target system;

receive a role of at least one of the plurality of accounts;

organize one or more of the plurality of accounts together in a group based at least in part on the role for each of the one or more of the plurality of accounts, the group being formed by the perspective selection and a policy manager;

assign a first grant to the group based at least in part on received grant information for the group, the grant information identifying access rights and privileges of users, accounts, groups of the users, or groups of the accounts;

identify a new account of the plurality of accounts that corresponds to the role, the new account being associated with at least a second grant that is different from the first grant;

add the new account to the group based at least in part on a request from an administrative account of the account management service; and

update privileges of the group to include the second grant based at least in part on adding the new account to the group.

2. The system of claim 1 , wherein a first account and a second account of the plurality of accounts each comprise a different type of account.

3. The system of claim 2 , wherein the type comprises a user account, a root account, the administrative account, or a user-defined account.

4. The system of claim 1 , wherein a first account and a second account of the plurality of accounts are associated with a first target system and a second target system, respectively.

5. The system of claim 4 , wherein the first target system and the second target system each comprise a different type of target system.

6. The system of claim 1 , wherein the information associated with the plurality of accounts indicates a particular target system associated with the account, a type of the account, or a role associated with the account.

7. The system of claim 1 , wherein the one or more processors are further configured to execute the plurality of instructions to receive grant information for the group, wherein the assignment of the first grant to the group is based at least in part on the received grant information.

8. The system of claim 1 , wherein the second grant is not previously associated with the group.

9. A computer-implemented method, comprising:

receiving, by a computer system, a perspective selection for viewing multiple accounts based at least in part on tags assigned to registered accounts to display on a user device in a user-defined hierarchical view;

receiving, by the computer system, information that identifies a plurality of different types of accounts associated with a plurality of different types of target systems, at least a first target system of the plurality of target systems being different from at least a second target system of the plurality of target systems;

receiving, by the computer system, role information for at least one of the plurality of accounts;

forming, by the computer system, a group of the plurality of accounts based at least in part on the role information, the group being formed by the perspective selection and a policy manager;

assigning, by the computer system, a first grant policy to the group of the plurality of accounts based at least in part on received grant information for the group, the grant information identifying access rights and privileges of users, accounts, groups of the users, or groups of the accounts;

identify a new account of the plurality of accounts that corresponds to the role information, the new account being associated with at least a second grant policy that is different from the first grant policy;

add the new account to the group based at least in part on a request from an administrator of the account management service; and

update privileges of the group to include the second grant policy based at least in part on adding the new account to the group.

10. The computer-implemented method of claim 9 , wherein the role information comprises identification of a role for the at least one of the plurality of accounts, the role comprising administrative, root, user, security, or user-defined.

11. The computer-implemented method of claim 9 , wherein the role information is received from an administrative account of an account management service configured to manage the plurality of accounts associated with the plurality of target systems.

12. The computer-implemented method of claim 9 , further comprising receiving grant information for the group, wherein the assigning of the first grant policy to the group is based at least in part on the received grant information.

13. A computer-readable memory storing a plurality of instructions executable by one or more processors, the plurality of instructions comprising:

instructions that cause the one or more processors to receive a perspective selection for viewing multiple accounts based at least in part on tags assigned to registered accounts to display on a user device in a user-defined hierarchical view;

instructions that cause the one or more processors to receive information that identifies a plurality of different types of accounts associated with a plurality of different types of target systems external to a system that is managed by an account management service of the system, at least a first target system of the plurality of target systems being different from at least a second target system of the plurality of target systems;

instructions that cause the one or more processors to receive, from an administrative account of the account management service configured to manage the plurality of accounts associated with the plurality of target systems, role information for at least one of the plurality of accounts;

instructions that cause the one or more processors to form a group of the plurality of accounts based at least in part on the role information, the group being formed by the perspective selection and a policy manager;

instructions that cause the one or more processors to assign a first grant policy to the group of the plurality of accounts based at least in part on received grant information for the group, the grant information identifying access rights and privileges of users, accounts, groups of the users, or groups of the accounts;

instructions that cause the one or more processors to identify a new account of the plurality of accounts that corresponds to the role information, the new account being associated with at least a second grant policy that is different from the first grant policy;

instructions that cause the one or more processors to add the new account to the group based at least in part on a request from an administrator of the account management service; and

instructions that cause the one or more processors to update the first grant policy of each of the plurality of accounts in the group to the second grant policy based at least in part on adding the new account to the group.

14. The computer-readable memory of claim 13 , wherein the plurality of accounts managed by the administrative account includes at least a first account that is a different type of account from at least a second account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2013
From: SHARMA, HIMANSHU; KOTTAHACHCHI, BUDDHIKA; THEEBAPRAKASAM, ARUN; SHIH, KUANG-YU
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 029652/0906 →
Continuity (2)
Provisional Application 61540984 · Sep 29, 2011
Related Publication 20130086065A1 · Apr 4, 2013