Determing a permission of a first tenant with respect to a second tenant

US2016337365A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016337365-A1
Application numberUS-201415112394-A
CountryUS
Kind codeA1
Filing dateJan 20, 2014
Priority dateJan 20, 2014
Publication dateNov 17, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A first representation is provided of privileges among a plurality of tenants of a system. The tenants have relationships according to a hierarchy that includes multiple hierarchical levels of the tenants, where at least one of the privileges specifies a permission of a first tenant to perform a task with respect to a second tenant. The first representation is independent of a representation of the relationships among the plurality of tenants. In response to a request from the first tenant to perform a task with respect to the second tenant, a system determines, based on the first representation, whether the first tenant is permitted to perform the task with respect to the second tenant.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: storing, by a system including a processor, a first representation of privileges among a plurality of tenants of the system, the plurality of tenants having relationships according to a hierarchy that includes a plurality of hierarchical levels of the tenants, wherein at least one of the privileges specifies an access permission of a first of the tenants at a first of the hierarchical levels to a resource of a second of the tenants at one of the hierarchical levels, and wherein the first representation is independent of a representation of the relationships among the plurality of tenants; and in response to a request from the first tenant for the resource of the second tenant, determining, by the system based on the first representation, whether the first tenant is permitted to access the resource of the second tenant. 2 . The method of claim 1 , wherein the at least one privilege specifies the access permission of the first tenant to the resource of the second tenant at a second, different one of the hierarchical levels. 3 . The method of claim 1 , wherein the at least one privilege specifies the access permission of the first tenant to user identity data of the second tenant, the user identity data for authorizing access of a cloud service or cloud resource provided by the system. 4 . The method of claim 1 , wherein a second of the privileges specifies a permission of the first tenant to modify the second tenant, the method further comprising: in response to a request by the first tenant to modify the second tenant, determining, by the system based first representation, whether the first tenant is permitted to modify the second tenant. 5 . The method of claim 4 , wherein the second privilege specifies a permission of the first tenant to modify the second tenant by adding or removing a sub-tenant of the second tenant. 6 . The method of claim 1 , further comprising: dynamically modifying the first representation to change the privileges among the plurality of tenants, without changing the representation of the relationships among the plurality of tenants. 7 . The method of claim 1 , wherein storing the first representation comprises storing access control information in at least one access control list. 8 . The method of claim 1 , wherein storing the first representation comprises using a cryptographic mechanism to control the privileges. 9 . The method of claim 1 , wherein the storing and the determining is performed by an identity management system that performs authorization of access of a cloud service or cloud resource of the system. 10 . A system comprising: at least one processor to: receive a request from a first tenant of a system to perform a task with respect to a second tenant of the system; in response to the request, access a first representation of privileges among a plurality of tenants, the plurality of tenants having relationships according to a hierarchy that includes a plurality of hierarchical levels of the tenants, wherein the privileges specify permissions of the tenants at the respective hierarchical levels to perform tasks with respect to other tenants at the respective hierarchical levels, and wherein the first representation is independent of a representation of the relationships among the plurality of tenants; and determine, based on the first representation, whether the first tenant is permitted to perform the task with respect to the second tenant. 11 . The system of claim 10 , wherein determining whether the first tenant is permitted to perform the task with respect to the second tenant comprises determining whether the first tenant is permitted to access a resource of the second tenant. 12 . The system of claim 10 , wherein determining whether the first tenant is permitted to perform the task with respect to the second tenant comprises determining whether the first tenant is permitted to add or remove a sub-tenant of the second tenant. 13 . The system of claim 10 , wherein the system is a cloud system, and the cloud system further comprising an identity management engine including the at least one processor, the identity management system to authorize access of a cloud service or cloud resource of the cloud system by a user of one of the plurality of tenants. 14 . The system of claim 10 , wherein the first representation includes a tenant privilege hierarchy that specifies privilege relationships among the plurality of tenants, the tenant privilege hierarchy including a plurality of hierarchical levels at which the respective tenants are provided. 15 . An article comprising at least one non-transitory machine-readable storage medium storing instructions that upon execution cause a cloud system to: receive a request from a first tenant of the cloud system to perform a task with respect to a second tenant of the cloud system, the cloud system including at least one cloud resource or at least one cloud service shareable by a plurality of tenants, and the cloud system further including an identity management system to authorize access of the at least one cloud resource or at least one cloud service; in response to the request, access a first representation of privileges among the plurality of tenants, the plurality of tenants having relationships according to a hierarchy that includes a plurality of hierarchical levels of the tenants, wherein the privileges specify permissions of the tenants at the respective hierarchical levels to perform tasks with respect to other tenants at the respective hierarchical levels, and wherein the first representation is independent of a representation of the relationships among the plurality of tenants; and determine, based on the first representation, whether the first tenant is permitted to perform the task with respect to the second tenant.

Assignees

Inventors

Classifications

  • G06F9/468Primary

    Specific access rights for resources, e.g. using capability register · CPC title

  • Entity profiles · CPC title

  • H04L63/101Primary

    Access control lists [ACL] · CPC title

  • Electricity · mapped topic

  • Discovery or management thereof, e.g. service location protocol [SLP] or web services · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016337365A1 cover?
A first representation is provided of privileges among a plurality of tenants of a system. The tenants have relationships according to a hierarchy that includes multiple hierarchical levels of the tenants, where at least one of the privileges specifies a permission of a first tenant to perform a task with respect to a second tenant. The first representation is independent of a representation of…
Who is the assignee on this patent?
Hewlett Packard Development Co Lp, Hewlett Packard Development Co Lp
What technology area does this patent fall under?
Primary CPC classification G06F9/468. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Nov 17 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).