IP Library Granted Patent US 9,626,524
Granted Patent B2
US 9,626,524 · App. 14/461,017 · Granted Apr 18, 2017

Managing network identities

Inventor: Sunil Puri (Burnaby, CA)
Assignee: SAP SE
G06F21/62H04L12/44H04L63/0407H04L63/10G06F2221/2117G06F2221/2145G06F2221/2153
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,626,524
App. No.
14/461,017
Granted
Apr 18, 2017
Kind
B2
Abstract

Techniques for managing network identities include generating, with a local computing system, a tree structure representing a network comprising a plurality of entities, the tree structure comprising a plurality of nodes, each node of the plurality of nodes representing an entity of the plurality of entities, at least one entity of the plurality of entities is represented by more than one node of the plurality of nodes; assigning a unique identifier to each node; identifying each node of the plurality of nodes as being a protected node or an unprotected node; and transmitting, to a remote computing system, the tree structure, the unique identifiers for the protected nodes, and identity information of the entities for the unprotected nodes.

Claims (82)

1. A method for managing network identities, the method comprising:

generating, with a local computing system, a tree structure representing a network comprising a plurality of entities, the tree structure comprising a plurality of nodes, each node of the plurality of nodes representing an entity of the plurality of entities;

identifying a first node and a second node of the tree structure each associated with a respective identification number;

identifying a first order of expansion of the tree structure, including:

i) expanding the tree structure at a first node to include a first expanded branch at the first node, the first expanded branch including a third node,

ii) assigning a first identification number to the third node based on the first order of expansion;

identifying a second order of expansion of the tree structure, including:

i) expanding the tree structure at the second node to include a second expanded branch at the second node, the second expanded branch including a fourth node,

ii) subsequent to expanding the tree structure at the second node, expanding the tree structure at the first node to include the first expanded branch at the first node, the first expanded branch including the third node;

iii) assigning a second identification number to the third node based on the second order of expansion, the second identification number different than the first identification number;

assigning a unique identifier to each of a fifth and a sixth node, the fifth and the sixth node representing the same entity, the fifth node distinct from the sixth node, the assigning including:

encoding a first unique identifier for the fifth node by combining i) an identification number of the entity that is represented by the fifth and the sixth nodes and ii) identification numbers of entities associated with other nodes along a first path from a root node of the tree structure to the first node, wherein the first unique identifier is based on an order of the other nodes along the first path, the first path including the first node and third node, the identification number of the third node based on one of the first and the second identification numbers,

encoding a second unique identifier for the sixth node by combining i) the identification number of the entity that is represented by the fifth and the sixth nodes and ii) the identification numbers of entities associated with the other nodes along a second path from a root node of the tree structure to the second node, wherein the second unique identifier is based on an order of the other nodes along the second path, the order of the other nodes along the first path is distinct from the order of the other nodes along the second path, the second path including the second node and the fourth node;

decoding the first unique identifier to determine that the fifth node is an unprotected node, the unprotected node including identifying information associated with the entity;

decoding the second unique identifier to determine that the sixth node is a protected node, the protected node concealing the identifying information associated with the entity; and

transmitting, to a remote computing system, the unique identifier for the sixth node, and the identifying information for the fifth node.

2. The method of claim 1 , further comprising:

encrypting the first unique identifier and the second unique identifier.

3. The method of claim 1 , further comprising:

maintaining a mapping of each unique identifier to information about the entity associated with the node associated with the unique identifier.

4. The method of claim 1 , further comprising:

determining that a user of the remote computing system has permission to view identity information of the entity associated with the fifth node; and

identifying the fifth node as being an unprotected node.

5. The method of claim 1 , further comprising:

determining that a user of the remote computing system does not have permission to view identity information of the entity associated with the sixth node; and

identifying the sixth node as being a protected node.

6. The method of claim 1 , wherein the at least one entity represented by more than one node of the plurality of nodes is associated with at least one protected node.

7. A non-transitory computer storage medium encoded with a computer program, the program comprising instructions that when executed by one or more computers cause the one or more computers to perform operations comprising:

generating, with a local computing system, a tree structure representing a network comprising a plurality of entities, the tree structure comprising a plurality of nodes, each node of the plurality of nodes representing an entity of the plurality of entities;

identifying a first node and a second node of the tree structure each associated with a respective identification number;

identifying a first order of expansion of the tree structure, including:

i) expanding the tree structure at a first node to include a first expanded branch at the first node, the first expanded branch including a third node,

ii) assigning a first identification number to the third node based on the first order of expansion;

identifying a second order of expansion of the tree structure, including:

i) expanding the tree structure at the second node to include a second expanded branch at the second node, the second expanded branch including a fourth node,

ii) subsequent to expanding the tree structure at the second node, expanding the tree structure at the first node to include the first expanded branch at the first node, the first expanded branch including the third node;

iii) assigning a second identification number to the third node based on the second order of expansion, the second identification number different than the first identification number;

assigning a unique identifier to each of a fifth and a sixth node, the fifth and the sixth node representing the same entity, the fifth node distinct from the sixth node, the assigning including:

encoding a first unique identifier for the fifth node by combining i) an identification number of the entity that is represented by the fifth and the sixth nodes and ii) identification numbers of entities associated with other nodes along a first path from a root node of the tree structure to the first node, wherein the first unique identifier is based on an order of the other nodes along the first path, the first path including the first node and third node, the identification number of the third node based on one of the first and the second identification numbers,

encoding a second unique identifier for the sixth node by combining i) the identification number of the entity that is represented by the fifth and the sixth nodes and ii) the identification numbers of entities associated with the other nodes along a second path from a root node of the tree structure to the second node, wherein the second unique identifier is based on an order of the other nodes along the second path, the order of the other nodes along the first path is distinct from the order of the other nodes along the second path, the second path including the second node and the fourth node;

decoding the first unique identifier to determine that the fifth node is an unprotected node, the unprotected node including identifying information associated with the entity;

decoding the second unique identifier to determine that the sixth node is a protected node, the protected node concealing the identifying information associated with the entity; and

transmitting, to a remote computing system, the unique identifier for the sixth node, and the identifying information for the fifth node.

8. The non-transitory computer storage medium of claim 7 , further comprising:

generating a number by combining an identification number of the entity associated with the node and identification numbers of entities associated with nodes along a path from a root node of the tree structure to the node; and

encrypting the first unique identifier and the second unique identifier.

9. The non-transitory computer storage medium of claim 7 , further comprising:

maintaining a mapping of each unique identifier to information about the entity associated with the node associated with the unique identifier.

10. The non-transitory computer storage medium of claim 7 , further comprising:

determining that a user of the remote computing system has permission to view identity information of the entity associated with the fifth node; and

identifying the fifth node as being an unprotected node.

11. The non-transitory computer storage medium of claim 7 , further comprising:

determining that a user of the remote computing system does not have permission to view identity information of the entity associated with the sixth node; and

identifying the sixth node as being a protected node.

12. The non-transitory computer storage medium of claim 7 , wherein the at least one entity represented by more than one node of the plurality of nodes is associated with at least one protected node.

13. A system of one or more computers configured to perform operations comprising:

generating, with a local computing system, a tree structure representing a network comprising a plurality of entities, the tree structure comprising a plurality of nodes, each node of the plurality of nodes representing an entity of the plurality of entities;

identifying a first node and a second node of the tree structure each associated with a respective identification number;

identifying a first order of expansion of the tree structure, including:

i) expanding the tree structure at a first node to include a first expanded branch at the first node, the first expanded branch including a third node,

ii) assigning a first identification number to the third node based on the first order of expansion;

identifying a second order of expansion of the tree structure, including:

i) expanding the tree structure at the second node to include a second expanded branch at the second node, the second expanded branch including a fourth node,

ii) subsequent to expanding the tree structure at the second node, expanding the tree structure at the first node to include the first expanded branch at the first node, the first expanded branch including the third node;

iii) assigning a second identification number to the third node based on the second order of expansion, the second identification number different than the first identification number;

assigning a unique identifier to each of a fifth and a sixth node, the fifth and the sixth node representing the same entity, the fifth node distinct from the sixth node, the assigning including:

encoding a first unique identifier for the fifth node by combining i) an identification number of the entity that is represented by the fifth and the sixth nodes and ii) identification numbers of entities associated with other nodes along a first path from a root node of the tree structure to the first node, wherein the first unique identifier is based on an order of the other nodes along the first path, the first path including the first node and third node, the identification number of the third node based on one of the first and the second identification numbers,

encoding a second unique identifier for the sixth node by combining i) the identification number of the entity that is represented by the fifth and the sixth nodes and ii) the identification numbers of entities associated with the other nodes along a second path from a root node of the tree structure to the second node, wherein the second unique identifier is based on an order of the other nodes along the second path, the order of the other nodes along the first path is distinct from the order of the other nodes along the second path, the second path including the second node and the fourth node;

decoding the first unique identifier to determine that the fifth node is an unprotected node, the unprotected node including identifying information associated with the entity;

decoding the second unique identifier to determine that the sixth node is a protected node, the protected node concealing the identifying information associated with the entity; and

transmitting, to a remote computing system, the unique identifier for the sixth node, and the identifying information for the fifth node.

14. The system of claim 13 , further comprising:

encrypting the first unique identifier and the second unique identifier.

15. The system of claim 13 , further comprising:

maintaining a mapping of each unique identifier to information about the entity associated with the node associated with the unique identifier.

16. The system of claim 13 , further comprising:

determining that a user of the remote computing system has permission to view identity information of the entity associated with the fifth node; and

identifying the fifth node as being an unprotected node.

17. The system of claim 13 , further comprising:

determining that a user of the remote computing system does not have permission to view identity information of the entity associated with the sixth node; and

identifying the sixth node as being a protected node.

18. The system of claim 13 , wherein the at least one entity represented by more than one node of the plurality of nodes is associated with at least one protected node.

Assignments (2)
CHANGE OF NAME Recorded Oct 2, 2015
From: SAP AG
To: SAP SE
Reel/Frame 036745/0597 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2014
From: PURI, SUNIL
To: SAP AG
Reel/Frame 033548/0167 →
Continuity (2)
Continuation 13463772 · May 3, 2012
Related Publication 20140359791A1 · Dec 4, 2014