System and method for cross-authoritative configuration management
Abstract
A system and method for cross-authoritative, user-based network configuration management is provided. Users log-in to a network using any device coupled to the network, and an identity manager may provide the user with a custom computing environment by verifying the user's identity and identifying content, assignments, and other configuration information associated with the user. For instance, the identity manager may retrieve a unique identifier assigned to the user, query one or more authoritative source domains based on the unique identifier, and deliver a computing environment assigned to the user. By seamlessly integrating multiple authoritative sources, administrators can make assignments to users across multiple authoritative source domains, and queries to the sources will always be up-to-date without having to perform synchronization processes.
Claims
exact text as granted — not AI-modified1 . A method for cross-authoritative configuration management, comprising:
integrating a plurality of authoritative sources with an identity manager that natively supports schemas used in the plurality of authoritative sources, wherein the identity manager integrated with the plurality of authoritative sources operates on a processor and provides a single point of control for managing access rights across the plurality of authoritative sources; receiving, at the identity manager operating on the processor, a request to access a resource on a network from a device in communication with the identity manager, wherein the request to access the resource on the network includes one or more credentials provided by at least one user managed across the plurality of authoritative sources; determining the access rights for the at least one user across the plurality of authoritative sources, wherein determining the access rights for the at least one user includes capturing identifiers for any directory objects assigned to the at least one user in the plurality of authoritative sources and retrieving the access rights for the at least one user from the directory objects assigned to the at least one user in the plurality of authoritative sources; and providing the at least one user with access to the requested resource in response to determining that the access rights retrieved from the directory objects assigned to the at least one user in the plurality of authoritative sources indicate that the at least one user has permission to access the requested resource.
2 . The method of claim 1 , wherein integrating the plurality of authoritative sources with the identity manager further includes associating the identifiers for the directory objects assigned to the at least one user in the plurality of authoritative sources with a globally unique identifier assigned to the at least one user.
3 . The method of claim 1 , wherein the directory objects assigned to the at least one user in the plurality of authoritative sources define the access rights for the at least one user across the plurality of authoritative sources.
4 . The method of claim 3 , wherein the directory objects assigned to the at least one user in the plurality of authoritative sources further define the access rights for one or more groups that include the at least one user or one or more containers that include the at least one user.
5 . The method of claim 1 , further comprising:
detecting, by the identity manager operating on the processor, a change to one or more of the directory objects assigned to the at least one user in the plurality of authoritative sources; and updating, by the identity manager operating on the processor, the identifiers for the one or more changed directory objects.
6 . A system for cross-authoritative configuration management, comprising:
a plurality of authoritative sources integrated with an identity manager that natively supports schemas used in the plurality of authoritative sources, wherein the identity manager integrated with the plurality of authoritative sources provides a single point of control for managing access rights across the plurality of authoritative sources; and one or more processors that execute the identity manager, wherein the one or more processors that execute the identity manager are configured to:
receive a request to access a resource on a network from a device in communication with the identity manager, wherein the request to access the resource on the network includes one or more credentials provided by at least one user managed across the plurality of authoritative sources;
determine the access rights for the at least one user across the plurality of authoritative sources, wherein determining the access rights for the at least one user includes capturing identifiers for any directory objects assigned to the at least one user in the plurality of authoritative sources and retrieving the access rights for the at least one user from the directory objects assigned to the at least one user in the plurality of authoritative sources; and
provide the at least one user with access to the requested resource in response to determining that the access rights retrieved from the directory objects assigned to the at least one user in the plurality of authoritative sources indicate that the at least one user has permission to access the requested resource.
7 . The system of claim 6 , wherein the one or more processors that execute the identity manager are further configured to associate the identifiers for the directory objects assigned to the at least one user in the plurality of authoritative sources with a globally unique identifier assigned to the at least one user.
8 . The system of claim 6 , wherein the directory objects assigned to the at least one user in the plurality of authoritative sources define the access rights for the at least one user across the plurality of authoritative sources.
9 . The system of claim 8 , wherein the directory objects assigned to the at least one user in the plurality of authoritative sources further define the access rights for one or more groups that include the at least one user or one or more containers that include the at least one user.
10 . The system of claim 6 , wherein the one or more processors that execute the identity manager are further configured to:
detect a change to one or more of the directory objects assigned to the at least one user in the plurality of authoritative sources; and update the identifiers for the one or more changed directory objects.Join the waitlist — get patent alerts
Track US2010268824A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.