FEDERATED LOGIN MECHANISMS FOR MULTI TENANT ROLE BASED ACCESS CONTROL

    公开(公告)号:US20240259389A1

    公开(公告)日:2024-08-01

    申请号:US18187191

    申请日:2023-03-21

    Applicant: Rubrik, Inc.

    CPC classification number: H04L63/105

    Abstract: Methods, systems, and devices for data management are described. A data management system (DMS) may receive a federated login request from a user associated with one or more tenants of the DMS. The DMS may direct the federated login request to a centralized management service. The DMS may receive a security assertion markup language (SAML) assertion that indicates an identity of the user, a set of object-level permissions assigned to the user, and an identifier of a first tenant associated with the user. The DMS may identify one or more computing objects in a cluster of storage nodes that correspond to the first tenant based on the identifier from the SAML assertion. The DMS may determine that the user is authorized to perform a set of actions on the one or more computing objects based on the set of object-level permissions indicated by the SAML assertion.

    ROLE-BASED ACCESS CONTROL FOR HIERARCHICAL RESOURCES OF A DATA MANAGEMENT SYSTEM

    公开(公告)号:US20240259386A1

    公开(公告)日:2024-08-01

    申请号:US18124553

    申请日:2023-03-21

    Applicant: Rubrik, Inc

    CPC classification number: H04L63/105

    Abstract: Methods, systems, and devices for data management are described. A data management system (DMS) may implement multi-tenancy role based access control (RBAC). In accordance with the multi-tenancy based RBAC, tenant organizations of a DMS may be assigned permissions (i.e., privileges) for a given data management cluster and/or computing objects within a data management cluster. Customized user roles (RBAC roles) may also be created for a given tenant. For example, a role may be defined based on a corresponding set of permissions (e.g., permissions associated with computing objects, data management clusters, or data sources associated with the tenant). A user within a tenant may be assigned a user role, which may be a customized role, and the effective permissions for the user may be based on which permissions of the user's assigned role are also within the scope of the tenant's permissions.

Patent Agency Ranking