Delegated and restricted asset-based permissions management for co-location facilities

US9595013B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9595013-B2
Application numberUS-96465810-A
CountryUS
Kind codeB2
Filing dateDec 9, 2010
Priority dateDec 10, 2009
Publication dateMar 14, 2017
Grant dateMar 14, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

At least one user is designated to manage assets including management delegations, access restrictions, and access permissions. Management responsibilities are applied based on business rules and based on a hierarchical model. The hierarchical model enables a well-defined logical flow of delegations and restrictions with pruning capability. User groups, asset groups, asset trees and asset permissions may be defined. The designated user can manage a single asset or all assets or a subset of assets. An asset may belong to one or more asset groups.

First claim

Opening claim text (preview).

We claim: 1. A system for managing assets in a data center co-location facilities environment, the system comprising: a central relational database containing information associated with assets of a service provider, wherein the assets are associated with one or more geographically distinct co-location facilities, wherein the assets are provided by the service provider for use by a customer, and wherein the service provider is associated with the customer based on one or more agreements to enable the customer to access the assets, wherein a permissions model is configured to enable at least one user from the customer to be designated as having authority to grant permissions to access the assets, the permissions granted to other users of the same customer, wherein an asset hierarchical model is configured to enable grouping of the assets in one or more asset groups, and a user group model is configured to enable grouping of the users of the customer in one or more user groups and according to the geographically distinct co-location facilities, the user groups and the asset groups managed independently of one another, wherein many-to-many relationships are established among the users in the user groups, the assets in the asset groups, and the permissions granted to the users to use the assets, and wherein components of the system are implemented in hardware, software, or a combination of both, and where components of the system that are implemented in software are stored in an executable format on one or more non-transitory machine-readable mediums. 2. The system of claim 1 , wherein the at least one user from the customer to be designated as having the authority to grant permissions to the assets is an administrator responsible for managing the assets at an asset level, and wherein that designated user is authorized to administer over one of (1) a single asset group, (2) all of the asset groups, and (3) some subsets of all of the asset groups. 3. The system of claim 1 , wherein the one or more asset groups are associated with one or more co-location facilities, and wherein permissions granted to an asset at a first level of the hierarchy model includes permissions granted to other assets at levels lower than the first level in the hierarchy model. 4. The system of claim 3 , wherein the other assets at the levels lower than the first level in the hierarchy model is limitable to less than a total number of assets included in the levels lower than the first level. 5. The system of claim 1 , wherein the agreements are grouped into two or more agreement groups, wherein a first agreement group is associated with a first logical customer organization and a second agreement group is associated with a second logical customer organization, and wherein each logical customer organization is associated with at least one asset group and at least one user group. 6. The system of claim 5 , wherein a first user is a member of at least one user group, and wherein an asset is a member of at least one asset group. 7. The system of claim 1 , wherein the assets include logical and physical assets, and wherein a user interface is configured to display information related to logical assets granted to a first user according to permissions granted to the first user, the user interface associated with a portal of the service provider. 8. The system of claim 7 , wherein the user interface is presented to the first user based on the first user logging into the portal of the service provider using a browser installed in a client computer system connected to a network in a client-server environment. 9. The system of claim 1 , wherein the assets are associated with one or more data centers of the one or more geographically distinct co-location facilities, and wherein the designated user is further authorized to revoke permissions to access the assets. 10. A method for managing assets in a data center co-location facilities environment, the method comprising: applying a permissions model to enable at least one user from a customer to be designated as an asset administrator having authority to grant or restrict permissions to access assets of a service provider in one or more geographically distinct co-location facilities, the permissions applied to other users of the same customer; applying a logical customer organization model to enable grouping of one or more agreements between the customer and the service provider, the agreements enabling the users of the customer to access the assets of the service provider; applying an asset hierarchical model to enable grouping of the assets in one or more asset groups and according to the logical customer organization model; establishing relationships among the users in the user groups, the assets in the asset groups, and the permissions granted by the asset administrator to the users; and presenting information related to the relationships to the users via a user interface associated with a portal of the service provider. 11. The method of claim 10 , wherein information related to the assets, the users and the permissions is stored in a central relational database associated with the service provider, and wherein the presentation of the information related to the relationships to the users is based on the users logging on to the portal of the service provider. 12. The method of claim 10 , wherein the administrator is responsible for managing the assets at an asset level and authorized to administer over a single asset group, all of the asset groups, or some subsets of all of the asset groups. 13. The method of claim 10 , wherein the one or more asset groups are associated with one or more co-location facilities, and wherein permissions granted to an asset at a first level of the hierarchy model includes permissions granted to other assets at levels lower than the first level in the hierarchy model. 14. The method of claim 13 , wherein the other assets at the levels lower than the first level in the hierarchy model is limitable to less than a total number of assets included in the levels lower than the first level. 15. The method of claim 10 , wherein a first user is a member of at least one user group, and wherein an asset is a member of at least one asset group, wherein the agreements are grouped into one or more agreement groups, wherein each agreement group is associated with a logical customer organization, and wherein each logical customer organization is associated with at least one asset group and at least one user group. 16. The method of claim 15 , wherein the first user is to use a first login identification (ID) to access a first asset and a second asset in a first asset group of a first co-location facility and a third asset in a third asset group of a second co-location facility geographically distinct from the first co-location facility, wherein the first asset group and the third asset group are associated with a similar logical customer organization, and wherein the first user is to use a second login ID to access an asset in a second asset group, wherein the second asset group is associated with a logical customer organization different than the logical customer organization associated with the first and third asset groups. 17. The method of claim 10 , wherein the assets include physical and logical assets associated with one or more data centers of the one or more geographically distinct co-location facilities, and wherein the user interface is presented to a first user based on the first user logging into the portal of the service provider using a browser

Assignees

Inventors

Classifications

  • Monitoring arrangements determined by the means or processing involved in sensing the monitored data, e.g. interfaces, connectors, sensors, probes, agents (software debugging using additional hardware using a specific debug interface G06F11/3656; performance evaluation by tracing or monitoring G06F11/3466) · CPC title

  • monitoring of user actions (tracking the activity of the user H04L67/535) · CPC title

  • Creating or negotiating SLA contracts, guarantees or penalties · CPC title

  • Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration · CPC title

  • Tools and structures for managing or administering access control systems · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9595013B2 cover?
At least one user is designated to manage assets including management delegations, access restrictions, and access permissions. Management responsibilities are applied based on business rules and based on a hierarchical model. The hierarchical model enables a well-defined logical flow of delegations and restrictions with pruning capability. User groups, asset groups, asset trees and asset permi…
Who is the assignee on this patent?
Doraiswamy Vijaay, Jeyapaul Jaganathan, Weng Tsunyen, and 4 more
What technology area does this patent fall under?
Primary CPC classification G06Q10/06. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Mar 14 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).