Performing a security action with regard to an access token based on clustering of access requests
US-2024406160-A1 · Dec 5, 2024 · US
US2016337337A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016337337-A1 |
| Application number | US-201415112389-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jan 20, 2014 |
| Priority date | Jan 20, 2014 |
| Publication date | Nov 17, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
In response to a request of a first user, identity information for users is searched to retrieve a portion of the identity information corresponding to the first user. The identity information including fields, where a first subset of the fields is schemaless, and a second subset of the fields is interpreted according to a specified schema. Searching the identity information includes searching the first subset and the second subset of fields. An action for the request is authorized by using information included in at least one field of the first subset included in the retrieved portion of the identity information.
Opening claim text (preview).
What is claimed is: 1 . A method comprising: receive, by a system including a processor, a request of a first user; in response to the request, searching, by the system, identity information for users to retrieve a portion of the identity information corresponding to the first user, the identity information including fields, wherein a first subset of the fields is schemaless, and a second subset of the fields is interpreted according to a specified schema, and wherein searching the identity information comprises searching the first subset and the second subset of fields; and authorizing, by the system, an action for the request by using information included in at least one field of the first subset included in the retrieved portion of the identity information. 2 . The method of claim 1 , further comprising a further action using identity information from the first and second subsets of the fields. 3 . The method of claim 1 , wherein the identity information is stored in a schemaless database, and wherein interpreting the second subset of fields according to the specified schema uses logic that enforces presence of the second subset of the fields according to the specified schema in the schemaless database. 4 . The method of claim 1 , wherein the identity information is stored in a schemaful database, and wherein at least one data structure in the schemaful database is used to store the first subset of the fields. 5 . The method of claim 4 , wherein the at least one data structure is in at least one field of the schemaful database. 6 . The method of claim 1 , further comprising: storing the first subset of the fields in at least one schemaless database; and staring the second subset of the fields in at least one schemaful database. 7 . The method of claim 1 , further comprising: generating an index using at least one field from the first and second subsets of fields, wherein searching the identity information uses the index. 8 . The method of claim further comprising: dynamically adding new field to the first subset of the fields in the identity information. 9 . The method of claim 1 , further comprising: dynamically removing an existing field of the first subset of the fields in the identity information. 10 . The method of claim 1 , further comprising: dynamically modifying an existing field of the first subset of the fields in the identity information. 11 . A system comprising: at least one storage medium to store a semi-schemaless identity information repository that stores identity information for users, the identity information including fields, wherein a first subset of the fields is schemaless, and a second subset of the fields is interpreted according to a specified schema; and at least one processor to: in response to a request of a first user, search the semi-schemaless identity information repository to retrieve a portion of the identity information corresponding to the first user, wherein searching the semi-schemaless identity information repository comprises searching the first subset and the second subset of fields; and provide information included in at least one field of the first subset included in the retrieved portion of the identity information for use in authorizing an action for the request. 12 . The system of claim 11 , wherein the at least one processor is to further provide information included in at least one field of the second subset included in the retrieved portion of the identity information for use in authorizing the action for the request. 13 . The system of claim 11 , wherein the semi-schemaless identity information repository includes a schemaless database containing the second subset of the fields, and wherein the at least one processor is to further: emulate storage of the second subset of the fields according to the specified schema. 14 . The system of claim 11 , wherein the semi-schemaless identity information repository includes a schemaful database containing the first subset of the fields, and wherein the at least one processor is to further: emulate storage of the first subset of the fields in a schemaless manner. 15 . An article comprising at least one non-transitory machine-readable storage medium storing instructions that upon execution cause a system to: receive a request of a first user to access a cloud resource or cloud service of a cloud system; in response to the request, search identity information for users to retrieve a portion of the identity information corresponding to the first user, the identity information including fields, wherein a first subset of the fields is schemaless, and a second subset of the fields is interpreted according to a specified schema, and wherein searching the identity information comprises searching the first subset and the second subset of fields; and provide information in at least one field of the first subset included in the retrieved portion of the identity information for authorizing access of the cloud resource or cloud service for the request.
providing single-sign-on or federations · CPC title
where a single sign-on provides access to a plurality of computers · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.