×

Distributed data structures for authorization and access control for computing resources

  • US 7,331,058 B1
  • Filed: 12/16/1999
  • Issued: 02/12/2008
  • Est. Priority Date: 12/16/1999
  • Status: Expired due to Fees
First Claim
Patent Images

1. An information storage management system in a first administrative domain administered by a first organization, comprising:

  • a collection of stored objects in the first administrative domain administered by the first organization;

    an access control unit in the first administrative domain administered by the first organization for determining if a requester is authorized to access a protected object stored in the collection in the first administrative domain administered by the first organization;

    a resource manager connected to the access control unit and to a communications channel;

    wherein the resource manager receives a user'"'"'s request for access to the protected object in the first administrative domain administered by the first organization, the request including a globally unique identifier for the user requesting the access, and in response to the user'"'"'s request, the resource manager sends over the communications channel to an external storage management system in a second administrative domain administered by a second organization that is different from the first organization, a resource manager request for information about the user, the resource manager request including the globally unique identifier; and

    wherein the resource manager upon receiving a response to the resource manager request from the external storage management system passes the user information to the access control unit in the first administrative domain administered by the first organization; and

    wherein responsive to the user information the access control unit determines whether to authorize the user for access to the protected object.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×