Mapping tenat groups to identity management classes

US10372483B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10372483-B2
Application numberUS-201415112371-A
CountryUS
Kind codeB2
Filing dateJan 20, 2014
Priority dateJan 20, 2014
Publication dateAug 6, 2019
Grant dateAug 6, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Groups of a plurality of tenants are mapped to identity management classes corresponding to respective roles that grant respective permissions. The identity management classes are associated with hierarchical delegation information that specify delegation rights among the identity management classes, the delegation rights specifying rights of members of the respective identity management classes to perform delegation with respect to further members of the identity management classes. In response to a request by a first member of a first of the identity management classes to perform delegation with respect to a second member of one of the identity management classes, it is determined, based on the hierarchical delegation information, whether the first member is allowed to perform the delegation with respect to the second member.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: mapping, by a system including a processor, groups of a plurality of tenants to identity management classes corresponding to respective roles that grant respective permissions for performing tasks with respect to at least one application, the at least one application accessible by the plurality of tenants, wherein the identity management classes are associated with hierarchical delegation information that specifies delegation rights among members of the identity management classes; and in response to a request by a first member of a first of the identity management classes to perform delegation with respect to a second member of one of the identity management classes, determining, by the system based on the delegation rights specified in the hierarchical delegation information for the first identity management class, whether the first member is allowed to perform the delegation with respect to the second member, wherein to perform the delegation with respect to the second member includes at least one of enrolling the second member in a particular identity management class, modifying information of the second member in the particular identity management class, and removing the second member from the particular identity management class, and wherein a first group and a second group of the groups of the plurality of tenants have a same role, but are mapped to different identity management classes having different delegation rights, wherein the delegation rights of each of the members of the identity management classes specify rights of each of the members of the identity management class to perform delegation with respect to further members of the identity management class. 2. The method of claim 1 , wherein the request is a request by the first member of the first identity management class to enroll the second member in a second identity management class, and wherein the determining comprises determining, based on the hierarchical delegation information, whether the first member is allowed to enroll the second member in the second identity management class. 3. The method of claim 1 , wherein the request is a request by the first member of the first identity management class to remove the second member from a second identity management class, and wherein the determining comprises determining, based on the hierarchical delegation information, whether the first member is allowed to remove the second member from the second identity management class. 4. The method of claim 1 , wherein the request is a request by the first member of the first identity management class to modify information of the second member of a second identity management class, and wherein the determining comprises determining, based on the hierarchical delegation information, whether the first member is allowed to modify the information of the second member of the second identity management class. 5. The method of claim 1 , wherein mapping the groups of the plurality of tenants to the identity management classes comprises mapping the groups of the plurality of tenants to system groups, the method further comprising: mapping, by the system, the system groups to the respective roles. 6. The method of claim 5 , wherein mapping the groups of the plurality of tenants to the system groups is performed by an identity management engine, and wherein mapping the system groups to the roles is performed by the at least one application. 7. The method of claim 5 , wherein the system groups are common to a plurality of applications that have different sets of roles. 8. The method of claim 1 , wherein mapping the groups of the plurality of tenants to the identity management classes comprises mapping the groups of the plurality of tenants to the roles. 9. The method of claim 1 , wherein the at least one application is a cloud-based application for providing one or a combination of cloud resources and cloud services to members of the plurality of tenants. 10. A cloud system comprising: at least one of a cloud resource and a cloud service accessible by a plurality of tenants of the cloud system; and at least one storage medium to store a mapping between groups of the plurality of tenants and identity management classes corresponding to respective roles that grant respective permissions to access the cloud resource or cloud service, wherein the identity management classes are associated with hierarchical delegation information that specifies delegation rights among members of the identity management classes; and at least one processor to: receive a request by a first member of a first of the identity management classes to perform delegation with respect to a second member of a particular one of the identity management classes, wherein to perform the delegation with respect to the second member includes at least one of enrolling the second member in a particular identity management class, modifying information of the second member in the particular identity management class, or removing the second member from the identity management class; and in response to the request, determine, based on the hierarchical delegation information, whether the first member is allowed to perform the delegation with respect to the second member of the particular identity management class, wherein a first group and a second group of the groups of the plurality of tenants have a same role, but are mapped to different identity management classes having different delegation rights, wherein the delegation rights of each of the members of the identity management classes specify rights of each of the members of the identity management class to perform delegation with respect to further members of the identity management class. 11. The cloud system of claim 10 , wherein the particular identity management class is the same as the first identity management class. 12. The cloud system of claim 10 , wherein the particular identity management class is different from the first identity management class. 13. The cloud system of claim 10 , wherein the mapping includes a first mapping between the groups of the plurality of tenants and system groups that correspond to the identity management classes, and a second mapping between the system groups and the roles. 14. An article comprising at least one non-transitory machine-readable storage medium storing instructions that upon execution by a cloud system cause the cloud system to: store a mapping between groups of a plurality of tenants and identity management classes corresponding to respective roles that grant respective permissions for performing tasks with respect to at least one application, the at least one application accessible by the plurality of tenants and managing access of one or a combination of a cloud resource and a cloud service, wherein the identity management classes are associated with hierarchical delegation information that specifies delegation rights among members of the identity management classes; and in response to a request by a first member of a first of the identity management classes to perform delegation with respect to a second member of one of the identity management classes, determine, based on the hierarchical delegation information, whether the first member is allowed to perform the delegation with respect to the second member, wherein to perform the delegation with respect to the second member includes at least one of enrolling the second member in a particular identity management class, modifying information of the second member in the particular identity management class, and removing the second membe

Assignees

Inventors

Classifications

  • G06F9/468Primary

    Specific access rights for resources, e.g. using capability register · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10372483B2 cover?
Groups of a plurality of tenants are mapped to identity management classes corresponding to respective roles that grant respective permissions. The identity management classes are associated with hierarchical delegation information that specify delegation rights among the identity management classes, the delegation rights specifying rights of members of the respective identity management classe…
Who is the assignee on this patent?
Hewlett Packard Development Co
What technology area does this patent fall under?
Primary CPC classification G06F9/468. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 06 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).