×

Multi-tenancy identity management system

  • US 10,581,867 B2
  • Filed: 02/11/2016
  • Issued: 03/03/2020
  • Est. Priority Date: 09/07/2012
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method comprising:

  • creating, in a multi-tenant computing environment including a plurality of computing devices providing services to a plurality of customers, a first identity domain using an identity management (IDM) system configured to authenticate identities of users and authorize access to system resources, wherein the multi-tenant computing environment is a cloud computing environment, and wherein the identity management system is partitioned into a plurality of identity domains;

    binding the first identity domain, that is created for a first customer of the plurality of customers, to identification information comprising a first uniform resource locator (URL) that is associated with the first identity domain, and wherein the first URL provides the first customer access to the first identity domain and services of the first identity domain;

    associating, using the identity management system, a first plurality of services and one or more policies associated with a host machine for accessing the first plurality of services with the first identity domain, wherein associating the first plurality of services with the first identity domain comprises provisioning an instance of a service from among the first plurality of services to the first identity domain, and wherein access to the first plurality of services associated with the first identity domain is provided via the first URL when the customer satisfies the one or more policies associated with the host machine;

    storing, in a first partition of a centralized identity store of the identity management system, identities and identity definitions of a first set of users using the identity management system;

    associating, using the identity management system, the identities of the first set of users with the first plurality of services;

    creating, in the multi-tenant computing environment using the identity management system, a second identity domain for the first customer that is isolated from the first identity domain, wherein the second identity domain comprises a second uniform resource locator (URL) that is associated with the second identity domain, and wherein the second URL provides the first customer access to the second identity domain;

    associating, using the identity management system, a second plurality of services and one or more policies for accessing the second plurality of services with the second identity domain, wherein associating the second plurality of services with the second identity domain comprises provisioning an instance of a service from among the second plurality of services to the second identity domain;

    storing, in a second partition of the centralized identity store, identities and identity definitions of a second set of users using the identity management system, wherein the second set of users is different from the first set of users; and

    associating, using the identity management system, the identities of the second set of users with the second plurality of services.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×