IP Library › Granted Patent US 9,111,118
Granted Patent B2
US 9,111,118 · App. 12/201,832 · Granted Aug 18, 2015

Managing access in a software provisioning environment

Inventor: Michael Paul DeHaan (Morrisville, NC)
Assignee: Red Hat, Inc.
G06F21/629H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,111,118
App. No.
12/201,832
Granted
Aug 18, 2015
Kind
B2
Abstract

A provisioning server can be configured to associate user actions with users that have access to perform the associated user actions. The user actions can include any user action performed within or by the provisioning server, such as configuring the provisioning server, modifying provisioning objects in the provisioning server, accessing provisioning processes by the provisioning server, and the like. The association can be based on the identity of the users or a type of user (administrator, client, guest, etc.). Once a request is received for a particular user action, the provisioning server can be configured to enable the requested action if the requested action is associated with the requesting user.

Claims (37)

1. A method comprising:

assigning, by a processor, each user of a set of users to a set of user actions available to be performed by the user, wherein the set of user actions comprises at least one of configuring a provisioning server, modifying a provisioning object in the provisioning server, creating a provisioning object in the provisioning server, or accessing a provisioning process by the provisioning server, and wherein each user of the set of users is granted access limited to the assigned set of user actions available to be performed by the user;

maintaining a plurality of user-specific records each comprising information identifying a user, a target machine associated with the user, and the set of user actions assigned to the user, wherein the information identifying the user comprises a user name and authentication key associated with the user;

receiving, by the processor, a request from a first user to perform a selected user action related to a software provisioning environment;

verifying that the selected user action is available to be performed by the first user in view of a user-specific record associated with the first user; and

enabling, by the processor, the selected user action when the first user is assigned the selected user action.

2. The method of claim 1 , further comprising:

providing a network user interface to receive the request.

3. The method of claim 1 , wherein assigning each user to the set of user actions available to be performed by the user, comprises:

assigning, by the processor, each user with the set of user actions available to be performed by the user in view of at least one of the identity of each user or a type of each user.

4. The method of claim 1 , further comprising:

authenticating, by the processor, an identity received from the first user.

5. A system comprising:

a memory to store instructions: and

a processor operatively coupled to the memory, the processor to execute the instructions to:

assign each user of the set of users with a set of user actions available to be performed by the user, wherein the set of user actions comprises at least one of configuring a provisioning server, modifying a provisioning object in the provisioning server, creating a provisioning object in the provisioning server, or accessing a provisioning process by the provisioning server, and wherein each user of the set of users is granted access limited to the associated set of user actions available to be performed by the user;

maintain a plurality of user-specific records each comprising information identifying a user, a target machine associated with the user, and the set of user actions assigned to the user, wherein the information identifying the user comprises a user name and authentication key associated with the user;

receive a request from a first user to perform a selected user action related to a software provisioning environment;

verify that the selected user action is available to be performed by the first user in view of a user-specific record associated with the first user; and

enable the selected user action when the user is assigned the selected user action.

6. The system of claim 5 , the processor to:

provide a network user interface to receive the request.

7. The system of claim 5 , wherein to associate each user with the set of user actions, the processor is to:

associate each user with the set of user actions available to be performed by the user in view of at least one of the identity of each user or a type of each user.

8. The system of claim 5 , the processor to:

authenticate an identity received from the first user.

9. A non-transitory computer readable medium comprising instructions that, when executed by a processor, cause the processor to:

assign, by the processor, each user of the set of users with a set of user actions available to be performed by the user, wherein the set of user actions comprises at least one of configuring a provisioning server, modifying a provisioning object in the provisioning server, creating a provisioning object in the provisioning server, or accessing a provisioning process by the provisioning server, and wherein each user of the set of users is granted access limited to the associated set of user actions available to be performed by the user;

maintain a plurality of user-specific records each comprising information identifying a user, a target machine associated with the user, and the set of user actions assigned to the user, wherein the information identifying the user comprises a user name and authentication key associated with the user;

receive a request from a first user to perform a selected user action related to a software provisioning environment;

verify that the selected user action is available to be performed by the first user in view of a user-specific record associated with the first user; and

enable the selected user action when the user is assigned the selected user action.

10. The non-transitory computer readable medium of claim 9 , the processor to provide a network user interface to receive the request.

11. The non-transitory computer readable medium of claim 9 , the processor to:

assign each user to the set of user actions available to be performed by the user in view of at least one of the identity of each user or a type of each user.

12. The non-transitory computer readable medium of claim 9 , the processor to:

authenticate an identity received from the first user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2008
From: DEHAAN, MICHAEL PAUL
To: RED HAT, INC.
Reel/Frame 021464/0391 →
Continuity (1)
Related Publication 20100058444A1 · Mar 4, 2010