Systems and/or methods for resource use limitation in a cloud environment
US-9967196-B2 · May 8, 2018 · US
US11570259B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11570259-B2 |
| Application number | US-202217661096-A |
| Country | US |
| Kind code | B2 |
| Filing date | Apr 28, 2022 |
| Priority date | Jul 17, 2020 |
| Publication date | Jan 31, 2023 |
| Grant date | Jan 31, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Embodiments of the present disclosure may provide a streamlined process for performing operations, such as data sharing and data replication, using multiple accounts. A global identity (also referred to as an organization user) may be employed, where the global identity may have access to multiple accounts across the same or different deployments. The global identity may switch between accounts from its login session and perform various tasks in the context of different accounts without undergoing further authentication.
Opening claim text (preview).
What is claimed is: 1. A method comprising: establishing a login session for a global identity providing access to a plurality of accounts associated with an organization; from the login session: transmitting a first request to establish a first remote session with a first deployment, the first deployment being associated with a first account from the plurality of accounts; receiving a first confirmation message from the first deployment regarding establishing the first remote session including a first remote session identification; transmitting a first execution request to the first deployment to execute a first task, the first execution request including the first remote session identification; receiving a first result in response to the first execution request, the first result being generated in the first deployment using a first proxy user associated with the global identity; transmitting a second request to establish a second remote session with a second deployment, the second deployment being associated with a second account from the plurality of accounts; receiving a second confirmation message from the second deployment regarding establishing the second remote session including a second remote session identification; transmitting a second execution request to the second deployment to execute a second task, the second execution request including the second remote session identification; and receiving a second result in response to the second execution request, the second result being generated in the second deployment using a second proxy user associated with the global identity. 2. The method of claim 1 , further comprising: combining the first and second results to generate a final result. 3. The method of claim 1 , further comprising: authenticating a one-way trust relationship associated with the global identity, wherein the single login session provides access to the plurality of accounts without further authentication. 4. The method of claim 3 , wherein the authenticating is performed using a single sign-on token. 5. The method of claim 1 , further comprising: providing a session pool of active remote sessions in parallel allowing switching by the global identity between the active remote sessions. 6. The method of claim 1 , wherein at least one property value of the first proxy user indicates that that the first proxy user is standing in for the global identity. 7. The method of claim 1 , wherein receiving the first result includes retrieving the first result from a cloud storage location. 8. A system comprising: one or more processors of a machine; and at least one memory storing instructions that, when executed by the one or more processors, cause the machine to perform operations comprising: establishing a login session for a global identity providing access to a plurality of accounts associated with an organization; from the login session: transmitting a first request to establish a first remote session with a first deployment, the first deployment being associated with a first account from the plurality of accounts; receiving a first confirmation message from the first deployment regarding establishing the first remote session including a first remote session identification; transmitting a first execution request to the first deployment to execute a first task, the first execution request including the first remote session identification; receiving a first result in response to the first execution request, the first result being generated in the first deployment using a first proxy user associated with the global identity; transmitting a second request to establish a second remote session with a second deployment, the second deployment being associated with a second account from the plurality of accounts; receiving a second confirmation message from the second deployment regarding establishing the second remote session including a second remote session identification; transmitting a second execution request to the second deployment to execute a second task, the second execution request including the second remote session identification; and receiving a second result in response to the second execution request, the second result being generated in the second deployment using a second proxy user associated with the global identity. 9. The system of claim 8 , the operations further comprising: combining the first and second results to generate a final result. 10. The system of claim 8 , the operations further comprising: authenticating a one-way trust relationship associated with the global identity, wherein the single login session provides access to the plurality of accounts without further authentication. 11. The system of claim 10 , wherein the authenticating is performed using a single sign-on token. 12. The system of claim 8 , the operations further comprising: providing a session pool of active remote sessions in parallel allowing switching by the global identity between the active remote sessions. 13. The system of claim 8 , wherein at least one property value of the first proxy user indicates that that the first proxy user is standing in for the global identity. 14. The system of claim 8 , wherein receiving the first result includes retrieving the first result from a cloud storage location. 15. A non-transitory computer readable storage media storing instructions that, when executed by one or more processors, cause the one or more processors to: establishing a login session for a global identity providing access to a plurality of accounts associated with an organization; from the login session: transmitting a first request to establish a first remote session with a first deployment, the first deployment being associated with a first account from the plurality of accounts; receiving a first confirmation message from the first deployment regarding establishing the first remote session including a first remote session identification; transmitting a first execution request to the first deployment to execute a first task, the first execution request including the first remote session identification; receiving a first result in response to the first execution request, the first result being generated in the first deployment using a first proxy user associated with the global identity; transmitting a second request to establish a second remote session with a second deployment, the second deployment being associated with a second account from the plurality of accounts; receiving a second confirmation message from the second deployment regarding establishing the second remote session including a second remote session identification; transmitting a second execution request to the second deployment to execute a second task, the second execution request including the second remote session identification; and receiving a second result in response to the second execution request, the second result being generated in the second deployment using a second proxy user associated with the global identity. 16. The non-transitory computer readable storage media of claim 15 , further comprising: combining the first and second results to generate a final result. 17. The non-transitory computer readable storage media of claim 15 , further comprising: authenticating a one-way trust relationship associated with the global identity, wherein the single login session provides access to the plurality of accounts without further authentication. 18. The non-transitory computer readable storage media
providing single-sign-on or federations · CPC title
for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS] · CPC title
based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title
Network service management, e.g. ensuring proper service fulfilment according to agreements · CPC title
User authentication · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.