IP Library Granted Patent US 10,198,210
Granted Patent B2
US 10,198,210 · App. 15/195,513 · Granted Feb 5, 2019

Access control in a decentralized control plane of a computing system

Inventors: Georgios Chrysanthakopoulos (Seattle, WA); Pieter Noordhuis (Menlo Park, CA)
Assignee: VMware, Inc.
G06F3/0647G06F3/064G06F3/0608G06F3/0652G06F3/0659G06F3/0673G06F8/315G06F9/5027G06F9/541G06F9/542G06F17/30321G06F17/30345G06F17/30424H04L41/0893H04L41/20H04L67/02H04L67/10H04L67/104H04L67/1095H04L67/16H04L67/32H04L67/327H04L67/42G06F2209/5011
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,198,210
App. No.
15/195,513
Filed
Jun 28, 2016
Granted
Feb 5, 2019
Kind
B2
Art Unit
2446
USPC
709/225
Abstract

A method of controlling access to a target resource of a plurality of resources managed by a control plane executing on a computing system includes: receiving, at the control plane, a request for the target resource by a client, the request including a user indicator; identifying a user group in which the user indicator is a member; identifying a role that includes an access policy, applicable to the user group, for accessing a group of the plurality of resources, the group of resources defined by a query executable against an index of states of the plurality of resources; obtaining a state of the target resource in response to the request; and applying the access policy of the role to the request for the target resource based on a determination of whether the state of the target resource satisfies a query filter corresponding to the query of the role.

Claims (38)

1. A method of controlling access to a target resource of a plurality of resources managed by a control plane executing on a computing system, the method comprising:

receiving, at the control plane, a request for the target resource by a client, the request including a user indicator;

identifying a user group in which the user indicator is a member, the user group defined by a first query executable against an index of states of the plurality of resources;

identifying a role that includes an access policy, applicable to the user group, for accessing a group of the plurality of resources, the role including a uniform resource indicator (URI) of a user group service of the control plane and a URI of a resource group service of the control plane, the group of resources defined by a second query executable against the index of states of the plurality of resources;

obtaining a state of the target resource in response to the request, a state of the user group service, which includes the first query, and a state of the resource group service, which includes the second query; and

applying the access policy of the role to the request for the target resource based on a determination of whether the state of the target resource satisfies a query filter corresponding to the query of the role.

2. The method of claim 1 , wherein the request includes a token, the token encoding the user indicator, an expiration time, and a signature, and wherein the method further comprises parsing the token to verify the signature of the token, verify the expiration time against a current time, and extract the user indicator.

3. The method of claim 1 , wherein the user indicator comprises a uniform resource indicator (URI) of a user service of the control plane, a state of the user service including a user identity.

4. The method of claim 1 , wherein the URI of the user group service, the URI of the resource group service, and the access policy comprises state of a role service of the control plane.

5. The method of claim 1 , wherein the access policy of the role includes permission to invoke one or more actions of a representation state transfer (REST) application programming interface (API) of the control plane.

6. The method of claim 1 , wherein the step of applying the access policy comprises:

determining that the state of the resource satisfies the second query and that an action of the request satisfies the access policy; and

forwarding the request to the resource for handling the action of the request.

7. The method of claim 1 , wherein the step of applying the access policy comprises:

determining that the state of the resource does not satisfy the second query; and

generating a response to the request that indicates the request is forbidden.

8. The method of claim 1 , wherein the plurality of resources comprise a plurality of services managed by the control plane.

9. A computer system, comprising:

a hardware platform having a processor and memory;

a software platform executing on the hardware platform;

a service host process executing within the software platform, the service host process including a framework that controls access to a target resource of a plurality of resources, the service host process configured to:

receive a request for the target resource by a client, the request including a user indicator;

identify a user group in which the user indicator is a member, the user group defined by a first query executable against an index of states of the plurality of resources;

identify a role that includes an access policy, applicable to the user group, for accessing a group of the plurality of resources, the role including a uniform resource indicator (URI) of a user group service of the control plane and a URI of a resource group service of the control plane, the group of resources defined by a second query executable against the index of states of the plurality of resources;

obtain a state of the target resource in response to the request, a state of the user group service, which includes the first query, and a state of the resource group service, which includes the second query; and

apply the access policy of the role to the request for the target resource based on a determination of whether the state of the target resource satisfies a query filter corresponding to the query of the role.

10. The computer system of claim 9 , wherein the request includes a token, the token encoding the user indicator, an expiration time, and a signature, and wherein the method further comprises parsing the token to verify the signature of the token, verify the expiration time against a current time, and extract the user indicator.

11. The computer system of claim 9 , wherein the user indicator comprises a uniform resource indicator (URI) of a user service of the framework, a state of the user service including a user identity.

12. The computer system of claim 9 , wherein the URI of the user group service, the URI of the resource group service, and the access policy comprises state of a role service of the framework.

13. The computer system of claim 9 , wherein the access policy of the role includes permission to invoke one or more actions of a representation state transfer (REST) application programming interface (API) of the framework.

14. The computer system of claim 9 , wherein the plurality of resources comprise a plurality of services managed by the framework.

15. A non-transitory computer readable medium comprising instructions, which when executed in a computer system, causes the computer system to carry out a method of controlling access to a target resource of a plurality of resources managed by a control plane executing on a computing system, the method comprising:

receiving, at the control plane, a request for the target resource by a client, the request including a user indicator;

identifying a user group in which the user indicator is a member, the user group defined by a first query executable against an index of states of the plurality of resources;

identifying a role that includes an access policy, applicable to the user group, for accessing a group of the plurality of resources, the role including a uniform resource indicator (URI) of a user group service of the control plane and a URI of a resource group service of the control plane, the group of resources defined by a second query executable against the index of states of the plurality of resources;

obtaining a state of the target resource in response to the request, a state of the user group service, which includes the first query, and a state of the resource group service, which includes the second query; and

applying the access policy of the role to the request for the target resource based on a determination of whether the state of the target resource satisfies a query filter corresponding to the query of the role.

16. The non-transitory computer readable medium of claim 15 , wherein the plurality of resources comprise a plurality of services managed by the control plane.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2017
From: CHRYSANTHAKOPOULOS, GEORGIOS; NOORDHUIS, PIETER
To: VMWARE, INC.
Reel/Frame 041107/0001 →
Continuity (2)
Provisional Application 62355541 · Jun 28, 2016
Related Publication 20170373945A1 · Dec 28, 2017