IP Library › Granted Patent US 11,503,031
Granted Patent B1
US 11,503,031 · App. 17/064,419 · Granted Nov 15, 2022

Storage array access control from cloud-based user authorization and authentication

Inventors: Jimmy T. Hu (Menlo Park, CA); Benjamin Borowiec (San Jose, CA); Ethan Miller (Santa Cruz, CA); Terence Noonan (Vadnais Heights, MN); Constantine Sapuntzakis (Mountain View, CA); Neil Vachharajani (Menlo Park, CA); Daquan Zuo (Mountain View, CA)
Assignee: PURE STORAGE, INC.
H04L63/101G06F9/45533H04L9/3242H04L9/3247H04L63/0815H04L67/1097H04L2209/24H04L2209/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,503,031
App. No.
17/064,419
Granted
Nov 15, 2022
Kind
B1
Abstract

Providing authorization and authentication in a cloud for a user of a storage array includes: receiving, by a storage array access module from a client-side array services module, a token representing authentication of user credentials and authorized access privileges defining one or more storage array services accessible by the user, where the token is generated by a cloud-based security module upon authentication of the user credentials and identification of authorized access privileges for the user; receiving, by the storage array access module from the user, a user access request to one or more storage array services; and determining, by the storage array access module, whether to grant the user access request in dependence upon the authorized access privileges represented by the token.

Claims (37)

1. A method comprising:

receiving, from a client-side array services module, a token representing authentication of user credentials and authorized access privileges defining one or more storage array services accessible by the user, wherein the token is generated by a cloud-based security module upon authentication of the user credentials and identification of authorized access privileges for the user;

receiving, from the user, a user access request to one or more storage array services; and

determining whether to grant the user access request based on determining whether a hash of data representing the authorized access privileges represented by the token matches a decrypted digital signature within the token, the decrypted digital signature being decrypted using a public key of the cloud-based security module.

2. The method of claim 1 , wherein the cloud-based security module comprises a cloud identity provider (‘IDP’).

3. The method of claim 1 , wherein the cloud-based security module comprises a component of a cloud-based storage array services provider.

4. The method of claim 1 , wherein the cloud-based security module comprises a lightweight directory access protocol directory service.

5. The method of claim 1 , wherein:

access privileges are further defined in a storage array access module for a plurality of users; and

determining whether to grant the user access request in dependence upon the authorized access privileges represented by the token includes determining whether to grant the user access request in dependence upon the access privileges defined in the storage array access module as well as the token.

6. The method of claim 1 , wherein access privileges are defined in the cloud-based security module for a plurality of users with an association of each user with one of a plurality of profiles, each profile specifying access privileges for users associated with the profile.

7. The method of claim 6 , wherein the plurality of profiles comprise:

a read-only profile specifying, for users associated with the read only profile, read-only access privileges;

a modify profile specifying, for users associated with the modify profile, read and modify access privileges; and

an administrator profile specifying, for users associated with the administrator profile, all available access privileges.

8. The method of claim 6 , wherein the plurality of profiles comprise at least one storage-array specific profile specifying access privileges for a single storage array and multi-array profiles specifying access privileges for a plurality of storage arrays.

9. An apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

receiving, from a client-side array services module, a token representing authentication of user credentials and authorized access privileges defining one or more storage array services accessible by the user, wherein the token is generated by a cloud-based security module upon authentication of the user credentials and identification of authorized access privileges for the user;

receiving, from the user, a user access request to one or more storage array services; and

determining whether to grant the user access request based on determining whether a hash of data representing the authorized access privileges represented by the token matches a decrypted digital signature within the token, the decrypted digital signature being decrypted using a public key of the cloud-based security module.

10. The apparatus of claim 9 , wherein the cloud-based security module comprises a cloud identity provider (‘IDP’).

11. The apparatus of claim 9 , wherein the cloud-based security module comprises a component of a cloud-based storage array services provider.

12. The apparatus of claim 9 , wherein:

access privileges are further defined in a storage array access module for a plurality of users; and

determining whether to grant the user access request in dependence upon the authorized access privileges represented by the token includes determining whether to grant the user access request in dependence upon the access privileges defined in the storage array access module as well as the token.

13. The apparatus of claim 9 , wherein access privileges are defined in the cloud-based security module for a plurality of users with an association of each user with one of a plurality of profiles, each profile specifying access privileges for users associated with the profile.

14. The apparatus of claim 12 , wherein the plurality of profiles comprise at least one storage-array specific profile specifying access privileges for a single storage array and multi-array profiles specifying access privileges for a plurality of storage arrays.

15. A computer program product disposed upon a computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out the steps of:

receiving, from a client-side array services module, a token representing authentication of user credentials and authorized access privileges defining one or more storage array services accessible by the user, wherein the token is generated by a cloud-based security module upon authentication of the user credentials and identification of authorized access privileges for the user;

receiving, from the user, a user access request to one or more storage array services; and

determining whether to grant the user access request based on determining whether a hash of data representing the authorized access privileges represented by the token matches a decrypted digital signature within the token, the decrypted digital signature being decrypted using a public key of the cloud-based security module.

16. The computer program product of claim 15 , wherein the cloud-based security module comprises a cloud identity provider (‘IDP’).

17. The computer program product of claim 15 , wherein the cloud-based security module comprises a component of a cloud-based storage array services provider.

18. The computer program product of claim 15 , wherein:

access privileges are further defined in a storage array access module for a plurality of users; and

determining whether to grant the user access request in dependence upon the authorized access privileges represented by the token includes determining whether to grant the user access request in dependence upon the access privileges defined in the storage array access module as well as the token.

19. The computer program product of claim 15 , wherein access privileges are defined in the cloud-based security module for a plurality of users with an association of each user with one of a plurality of profiles, each profile specifying access privileges for users associated with the profile.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2020
From: HU, JIMMY T.; BOROWIEC, BENJAMIN; MILLER, ETHAN; NOONAN, TERENCE; SAPUNTZAKIS, CONSTANTINE; VACHHARAJANI, NEIL; ZUO, DAQUAN
To: PURE STORAGE, INC.
Reel/Frame 053991/0001 →
Continuity (2)
Continuation In Part 15235770 · Aug 12, 2016
Continuation 14726449 · May 29, 2015
Cited By (6)
US 12,192,351 US 12,238,101 US 12,282,588 US 12,321,426 US 12,367,320 US 12,429,348