IP Library › Granted Patent US 11,539,707
Granted Patent B2
US 11,539,707 · App. 17/020,075 · Granted Dec 27, 2022

Dynamic security policy consolidation

Inventors: Robert W. Kissell (Bealeton, VA); Eric Andrew Scholz (Ashburn, VA)
Assignee: Amazon Technologies, Inc.
H04L63/104G06F16/337G06F21/604G06F21/6218H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,539,707
App. No.
17/020,075
Granted
Dec 27, 2022
Kind
B2
Abstract

Various embodiments provide for the consolidation of policies across multiple identities that are respectively associated with multiple active directory (AD) groups to which a user belongs. Present embodiments provide for dynamically generating a new identity in the resource provider environment that includes permissions to all of the resources that may otherwise be distributed across multiple identities. Specifically, in accordance with various embodiments, when a user login is detected, the active directory is queried to determine the AD groups to which the user belongs. As mentioned, the user's AD groups are mapped to respective identities in the resource provider environment, in which each identity includes policy defining access to one or more resources. The policies of all the respective identities are consolidated and assigned to a new identity. The user may assume the new identity and access all the resources in tandem.

Claims (65)

1. A computer-implemented method, comprising:

receiving login credentials used to access an on-premise system, the login credentials associated with a particular user;

permitting single sign-on across the on-premise system and a cloud-based system, the cloud-based system having a synchronized directory integrated with an on-premise directory;

determining one or more groups in the on-premise directory to which the user belongs;

determining one or more groups in the cloud-based environment corresponding to the one or more groups in the on-premise directory, wherein the one or more groups in the cloud-based environment are mapped to the one or more groups in the on-premise directory on a one-to-one basis, the one or more groups in the cloud-based environment providing respective access to one or more resources in the cloud-based environment;

generating a dynamic group in the cloud-based environment, the dynamic group having access to all of the resources associated with the one or more groups in the cloud-based environment;

assigning the user to the dynamic group; and

allowing the user to access all of the one or more resources.

2. The method of claim 1 , further comprising:

creating a record of the dynamic group in a database, the record including a user identifier, a group identifier, an expiration parameter, and one or more policies defining access to the one or more resources.

3. The method of claim 1 , further comprising:

querying a database using a user identifier, the database having records of previously generated dynamic groups; and

determining, from the database, that a valid dynamic group does not already exist for the user identifier.

4. The method of claim 3 further comprising:

determining, from the database, a record of an existing dynamic group associated with the user identifier;

determining that the existing dynamic group is no longer valid; and

deleting the existing dynamic group and maintaining the record in the database.

5. The method of claim 3 , further comprising:

determining, from the database, a record of an existing dynamic group for the user identifier, the record indicating that the existing dynamic group has expired; and

determining that the existing dynamic group is no longer valid.

6. The method of claim 3 , further comprising:

determining, from the database, a record of an existing dynamic group for the user identifier, the record including one or more groups previously associated with the existing dynamic group, wherein the one or more groups in the record are not the same set of groups as the one or more groups currently associated with the user; and

determining that the existing dynamic group is no longer valid.

7. The method of claim 1 , wherein the on-premise directory includes an active directory hosted in a client environment and wherein the one or more groups in the on-premise direction include one or more active directory groups.

8. The method of claim 1 , further comprising:

enabling a request using the user identifier to access any of the one or more resources.

9. The method of claim 1 , wherein the one or more resources include data or services hosted by cloud-based system.

10. A system, comprising:

at least one computing device processor; and

a memory device including instructions that, when executed by the at least one computing device processor, cause the system to:

receive login credentials used to access an on-premise system, the login credentials associated with a particular user;

permit single sign-on across the on-premise system and a cloud-based system, the cloud-based system having a synchronized directory integrated with an on-premise directory;

determine one or more groups in the on-premise directory to which the user belongs;

determine one or more groups in the cloud-based environment corresponding to the one or more groups in the on-premise directory, wherein the one or more groups in the cloud-based environment are mapped to the one or more groups in the on-premise directory on a one-to-one basis, the one or more groups in the cloud-based environment providing respective access to one or more resources in the cloud-based environment;

generate a dynamic group in the cloud-based environment, the dynamic group having access to all of the resources associated with the one or more groups in the cloud-based environment;

assign the user to the dynamic group; and

allow the user to access all of the one or more resources.

11. The system of claim 10 , wherein the instructions when executed further cause the system to:

create a record of the dynamic group in a database, the record including a user identifier, a group identifier, an expiration parameter, and one or more policies defining access to the one or more resources.

12. The system of claim 10 , wherein the on-premise directory includes an active directory hosted in a client environment and wherein the one or more groups in the on-premise direction include one or more active directory groups.

13. The system of claim 10 , wherein the instructions when executed further cause the system to:

query a database using a user identifier, the database having records of previously generated dynamic groups; and

determine, from the database, that a valid dynamic group does not already exist for the user identifier.

14. The system of claim 10 , wherein the instructions when executed further cause the system to:

determine, from the database, a record of an existing dynamic group associated with the user identifier;

determine that the existing dynamic group is no longer valid; and

delete the existing dynamic group and maintaining the record in the database.

15. A non-transitory computer-readable storage medium storing instructions, the instructions when executed by a processor causing the processor to:

receive login credentials used to access an on-premise system, the login credentials associated with a particular user;

permit single sign-on across the on-premise system and a cloud-based system, the cloud-based system having a synchronized directory integrated with an on-premise directory;

determine one or more groups in the on-premise directory to which the user belongs;

determine one or more groups in the cloud-based environment corresponding to the one or more groups in the on-premise directory, wherein the one or more groups in the cloud-based environment are mapped to the one or more groups in the on-premise directory on a one-to-one basis, the one or more groups in the cloud-based environment providing respective access to one or more resources in the cloud-based environment;

generate a dynamic group in the cloud-based environment, the dynamic group having access to all of the resources associated with the one or more groups in the cloud-based environment;

assign the user to the dynamic group; and

allow the user to access all of the one or more resources.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions when executed further cause the processor to:

query a database using a user identifier, the database having records of previously generated dynamic groups; and

determine, from the database, that a valid dynamic group does not already exist for the user identifier.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions when executed further cause the processor to:

determine, from the database, a record of an existing dynamic group for the user identifier, the record indicating that the existing dynamic group has expired; and

determine that the existing dynamic group is no longer valid.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions when executed further cause the processor to:

determine, from the database, a record of an existing dynamic group for the user identifier, the record including one or more groups previously associated with the existing dynamic group, wherein the one or more groups in the record are not the same set of groups as the one or more groups currently associated with the user; and

determine that the existing dynamic group is no longer valid.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the on-premise directory includes an active directory hosted in a client environment and wherein the one or more groups in the on-premise direction include one or more active directory groups.

Continuity (2)
Continuation 15835172 · Dec 7, 2017
Related Publication 20200412736A1 · Dec 31, 2020