×

Access control policies associated with freeform metadata

  • US 10,341,281 B2
  • Filed: 01/22/2013
  • Issued: 07/02/2019
  • Est. Priority Date: 01/22/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer implemented method for using tags to control access to resources, comprising:

  • associating both a first access control policy and a second access control policy with a single metadata tag, the metadata tag including a freeform character string specifying a key and a key value,wherein the first access control policy identifies principals that are allowed to assign the metadata tag to the at least one computing resource andwherein the second access control policy identifies operations that are allowed or not allowed to be performed on resources associated with the key and the key value of the metadata tag;

    receiving, from a user using an application programming interface (API), a request to assign the metadata tag to the at least one computing resource;

    evaluating the first access control policy based at least in part on a combination of the key and the key value of the metadata tag;

    assigning the metadata tag to the at least one computing resource in response to determining that the first access control policy allows the user to assign the metadata tag;

    receiving a request to perform an operation on the at least one computing resource;

    evaluating, based at least in part on both of the key and the key value of the metadata tag, the second access control policy associated with the metadata tag via an identity management service that retrieves the second access control policy in addition to one or more other access control policies that are related to the request to perform the operation on the computing resource; and

    authorizing the request to perform the operation on the at least one computing resource based at least in part on the evaluation of the second access control policy.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×