Dynamic Access Control to Network Resources Using Federated Full Domain Logon
US-2018007059-A1 · Jan 4, 2018 · US
US11522845B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11522845-B2 |
| Application number | US-201916699548-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 29, 2019 |
| Priority date | Nov 29, 2019 |
| Publication date | Dec 6, 2022 |
| Grant date | Dec 6, 2022 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method for joining an association that includes receiving, by a first cluster, an association access credential and a unique address of an association manager, generating, based on the association access credential, an association access request, sending, to the unique address, the association access request, receiving, in response to the sending, association information, and initiating, based on the association information, a connection to a second cluster in the association.
Opening claim text (preview).
What is claimed is: 1. A method for joining an association, comprising: receiving, by a first cluster, an association access credential and a unique address of an association manager; generating, based on the association access credential, an association access request; sending, to the unique address, the association access request; receiving, in response to the sending, association information comprising: a first authenticated credential and a first association cluster list that indicates the second cluster; and initiating, based on the association information, a connection to a second cluster in the association, wherein initiating the connection comprises: performing a first lookup in the first association cluster list; identifying, based on the first lookup, the second cluster and a second cluster address; and sending, to the second cluster address, a first inquiry request that comprises the first authenticated credential; after initiating the connection: receiving, from the second cluster, a second association cluster list that indicates a third cluster in the association; and generating, based on the first association cluster list and the second association cluster list, an updated association cluster list; after generating the updated association cluster list: performing a second lookup in the updated association cluster list; identifying, based on the second lookup, the third cluster and a third cluster address; and sending, to the third cluster address, a second inquiry request. 2. The method of claim 1 , wherein the method further comprises: after initiating the connection: receiving, from the second cluster, an inquiry request; making a determination that the inquiry request comprises a second authenticated credential; and sending, based on the determination, the first association cluster list to the second cluster. 3. The method of claim 1 , wherein the association information is generated by the association manager. 4. The method of claim 3 , wherein generating the association information, by the association manager, comprises: receiving, from the first cluster, the association access request; making a determination that the association access request is valid; generating, based on the determination, the first authenticated credential; and sending, to the first cluster, the association information. 5. The method of claim 1 , wherein generating the updated association cluster list comprises: making a determination that the third cluster is not indicated in the first association cluster list; and adding, based on the determination, an indication of the third cluster and a third cluster address to the first association cluster list. 6. A non-transitory computer readable medium comprising instructions which, when executed by a computer processor, configuring the computer processor to perform a method for joining an association, the method comprising: receiving, by a first cluster, an association access credential and a unique address of an association manager; generating, based on the association access credential, an association access request; sending, to the unique address, the association access request; receiving, in response to the sending, association information comprising: a first authenticated credential and a first association cluster list that indicates the second cluster; and initiating, based on the association information, a connection to a second cluster in the association, wherein initiating the connection comprises: performing a first lookup in the first association cluster list; identifying, based on the first lookup, the second cluster and a second cluster address; and sending, to the second cluster address, a first inquiry request that comprises the first authenticated credential; after initiating the connection: receiving, from the second cluster, a second association cluster list that indicates a third cluster in the association; and generating, based on the first association cluster list and the second association cluster list, an updated association cluster list; after generating the updated association cluster list: performing a second lookup in the updated association cluster list; identifying, based on the second lookup, the third cluster and a third cluster address; and sending, to the third cluster address, a second inquiry request. 7. The non-transitory computer readable medium of claim 6 , wherein the method further comprises: after initiating the connection: receiving, from the second cluster, an inquiry request; making a determination that the inquiry request comprises a second authenticated credential; and sending, based on the determination, the first association cluster list to the second cluster. 8. The non-transitory computer readable medium of claim 6 , wherein the association information is generated by the association manager. 9. The non-transitory computer readable medium of claim 8 , wherein generating the association information, by the association manager, comprises: receiving, from the first cluster, the association access request; making a determination that the association access request is valid; generating, based on the determination, the first authenticated credential; and sending, to the first cluster, the association information. 10. A first cluster, comprising: memory; persistent storage; and a processor, wherein the processor is configured to: receive, by the first cluster, an association access credential and a unique address of an association manager; generate, based on the association access credential, an association access request; send, to the unique address, the association access request; receive, in response to the sending, association information comprising: a first authenticated credential and a first association cluster list that indicates the second cluster; and initiate, based on the association information, a connection to a second cluster in the association, wherein initiating the connection comprises: performing a first lookup in the first association cluster list; identifying, based on the first lookup, the second cluster and a second cluster address; and sending, to the second cluster address, a first inquiry request that comprises the first authenticated credential; after initiating the connection: receive, from the second cluster, a second association cluster list that indicates a third cluster in the association; and generate, based on the first association cluster list and the second association cluster list, an updated association cluster list; after generating the updated association cluster list: perform a second lookup in the updated association cluster list; identify, based on the second lookup, the third cluster and a third cluster address; and send, to the third cluster address, a second inquiry request. 11. The first cluster of claim 10 , wherein the processor is further configured to: after initiating the connection: receive, from the second cluster, an inquiry request; make a determination that the inquiry request comprises a second authenticated credential; and send, based on the determination, the first association cluster list to the second cluster. 12. The first cluster of claim 10 , wherein the association information is generated by the association manager. 13. The first cluster of claim 12 , wherein generating the association information, by the association manager, comprises: receiving, from the first cluster, the association access request; making a determination that the association access request is valid; generating, b
in response to processing delays, e.g. caused by jitter or round trip time [RTT] · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Cluster building · CPC title
Access control lists [ACL] · CPC title
Grouping of entities · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.