IP Library Granted Patent US 8,683,578
Granted Patent B2
US 8,683,578 · App. 13/565,483 · Granted Mar 25, 2014

Methods and systems for using derived user accounts

Inventor: Ulfar Erlingsson (San Francisco, CA)
Assignee: Google Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,683,578
App. No.
13/565,483
Granted
Mar 25, 2014
Kind
B2
Abstract

Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.

Claims (44)

1. A computer-implemented method for accessing a resource in a computer system comprising an operating system, comprising:

receiving a request to access the resource from an application;

determining if the application is running in a derived user account (DUA) context, wherein the DUA context represents a security context of a DUA that is derived from an original user account (OUA) of a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not running in the DUA context, creating the DUA and directing the application to run in the DUA context, wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA; and

granting the application access to the resource.

2. The computer-implemented method of claim 1 , wherein creating the DUA further comprises creating a copy of the resource, and wherein granting the application access to the resource comprises granting the application access to the copy of the resource.

3. The computer-implemented method of claim 1 , wherein applying the derivation transformation comprises copying the OUA state to generate the DUA state.

4. The computer-implemented method of claim 1 , wherein applying the derivation transformation comprises modifying the OUA state to generate the DUA state.

5. The computer-implemented method of claim 1 , wherein applying the derivation transformation comprises setting a value of the DUA state irrespective of a value of the OUA state.

6. The computer-implemented method of claim 1 , wherein creating the DUA comprises generating the DUA using a user account creation mechanism of the operating system.

7. The computer-implemented method of claim 1 , wherein the DUA comprises different access rights than the OUA.

8. The computer-implemented method of claim 1 , wherein applying the derivation transformation comprises:

comparing a value of the OUA state against a range; and

setting a value of the DUA state based on the comparison.

9. The computer-implemented method of claim 8 , wherein setting the value of the DUA state based on the comparison comprises:

setting the value of the DUA state as the closer of two end values of the range to the value of the OUA state, if the OUA state is outside the range; and

setting the value of the DUA state as the value of the OUA state, if the value of the OUA state is within the range.

10. An apparatus, comprising:

at least one memory having program instructions to execute an operating system; and

at least one processor configured to execute the program instructions to perform the operations of:

receiving a request to access a resource from an application;

determining if the application is running in a derived user account (DUA) context, the DUA context represents a security context of a DUA that is derived from an original user account (OUA) of a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not running in the DUA context, creating the DUA and directing the application to run in the DUA context, wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA; and

granting the application access to the resource.

11. The apparatus of claim 10 , wherein applying the derivation transformation comprises copying the OUA state to generate the DUA state.

12. The apparatus of claim 10 , wherein applying the derivation transformation comprises modifying the OUA state to generate the DUA state.

13. The apparatus of claim 10 , wherein applying the derivation transformation comprises:

comparing a value of the OUA state against a range; and

setting a value of the DUA state based on the comparison.

14. The apparatus of claim 10 , wherein the DUA comprises different access rights than the OUA.

15. A non-transitory computer-readable medium containing computer-readable instructions enabling a computer to perform a method, the method comprising:

receiving a request to access a resource from an application;

determining if the application is running in a derived user account (DUA) context, wherein the DUA context represents a security context of a DUA that is derived from an original user account (OUA) of a user, and wherein the determining comprises examining an access token associated with the request to determine if the request is associated with the DUA;

if the application is not running in the DUA context, creating the DUA and directing the application to run in the DUA context, wherein creating the DUA comprises applying a derivation transformation to an OUA state of the OUA to generate a corresponding DUA state of the DUA; and

granting the application access to the resource.

16. The non-transitory computer-readable medium of claim 15 , wherein applying the derivation transformation comprises copying the OUA state to generate the DUA state.

17. The non-transitory computer-readable medium of claim 15 , wherein applying the derivation transformation comprises modifying the OUA state to generate the DUA state.

18. The non-transitory computer-readable medium of claim 15 , wherein applying the derivation transformation comprises:

comparing a value of the OUA state against a range; and

setting a value of the DUA state based on the comparison.

19. The non-transitory computer-readable medium of claim 18 , wherein setting the value of the DUA state based on the comparison comprises:

setting the value of the DUA state as the closer of two end values of the range to the value of the OUA state, if the OUA state is outside the range; and

setting the value of the DUA state as the value of the OUA state, if the value of the OUA state is within the range.

20. The non-transitory computer-readable medium of claim 18 , wherein the DUA comprises different access rights than the OUA.

Assignments (3)
CHANGE OF NAME Recorded Oct 6, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044141/0827 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2012
From: ERLINGSSON, ULFAR
To: GREEN BORDER TECHNOLOGIES
Reel/Frame 028712/0758 →
MERGER Recorded Aug 2, 2012
From: GREEN BORDER TECHNOLOGIES
To: GOOGLE INC.
Reel/Frame 028712/0834 →
Continuity (3)
Continuation 10144048 · May 10, 2002
Provisional Application 60335894 · Nov 1, 2001
Related Publication 20120311698A1 · Dec 6, 2012