Single sign-on proxy
By introducing an SSO proxy to bridge the identity authentication and authorization services between the private cloud platform and third-party applications, the SSO access control problem when users access multiple services and third-party applications in the private cloud environment is solved, realizing cross-platform single sign-on and consistent access management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HEWLETT PACKARD ENTERPRISE DEV LP
- Filing Date
- 2025-07-18
- Publication Date
- 2026-06-05
AI Technical Summary
In a private cloud environment, when users need to access multiple services and third-party applications simultaneously, existing technologies struggle to achieve effective single sign-on (SSO) access control, resulting in complex and inconsistent authentication and authorization processes.
By introducing a Single Sign-On (SSO) agent, identity authentication and authorization services between the private cloud platform and third-party applications are bridged. The IAM tools of the platform identity provider and the SSO agent are used to achieve cross-platform SSO access management, including event-driven access permission updates.
It enables cross-platform single sign-on, simplifies the user authentication and authorization process, improves access efficiency and security, and ensures consistency and flexibility of user access to resources within the private cloud.
Smart Images

Figure CN122160080A_ABST
Abstract
Description
Background Technology
[0001] Computing resources (such as hardware and software resources) can be deployed as part of a cloud environment. Access to resources in a cloud environment is typically subject to at least some form of access control, which authenticates users and authorizes them to access at least some portion of the computing resources in the cloud environment. Attached Figure Description
[0002] Some examples discussed herein will be described with reference to the accompanying drawings listed below. However, the drawings illustrate only certain aspects or implementations of the examples described herein by way of example and are not intended to limit the scope of the claims. Figure 1 When reading this document, various aspects of the present disclosure will be best understood through the following detailed description. For a more complete understanding of the present disclosure and its advantages, reference is now made to the following description taken in conjunction with the accompanying drawings, wherein:
[0003] Figure 1 A block diagram of a private cloud based on one or more examples disclosed herein is shown;
[0004] Figure 2 This is a block diagram of a single sign-on (SSO) agent based on one or more examples disclosed herein;
[0005] Figure 3 An overview of example methods for managing identity events via an SSO agent in a private cloud environment, based on one or more examples disclosed herein, is shown.
[0006] Figure 4 A block diagram of a computing device according to one or more examples disclosed herein is shown; and
[0007] Figure 5 A block diagram of a computing device according to one or more examples disclosed herein is shown.
[0008] The accompanying drawings are provided to illustrate various aspects of this disclosure and are not necessarily drawn to scale. Detailed Implementation
[0009] The following disclosure provides many different examples for implementing various features. Specific examples of components and arrangements are described below to simplify this disclosure. Of course, these are merely examples and are not intended to be limiting.
[0010] An entity may seek an environment in which computing resources can be operated and / or provided for performing various tasks, operations, activities, etc., and / or for providing various applications, services, etc. Such an environment may be referred to as a cloud environment. For example, resources in a cloud environment may be obtained from a cloud service provider that can provide hardware resources, software resources, management services, and / or any other related components and / or services to be deployed as a cloud environment. In some cases, such an entity may seek to retain at least a degree of control over such an environment by having at least some control over the physical computing resources (e.g., computing devices, network devices, storage devices, management devices, etc.) and / or logical resources (e.g., software, applications, services, container platforms, management technologies, etc.) of the cloud environment. The environment in which such an entity maintains such control may be referred to as a private cloud. In one or more examples, a private cloud is an environment in which all or any part of the physical and / or logical computing resources of a cloud environment is managed, used, or otherwise maintained by a particular entity (e.g., a company) or set of entities, and is intended for use by the entity or set of entities maintaining the private cloud.
[0011] As an example, a specific entity may seek and obtain physical components (such as computing devices, network devices, storage devices, infrastructure components) and other components, such as management software, applications, services, and other software, from a provider of such resources, and deploy these resources at one or more physical sites as a private cloud, where other applications and / or services (such as applications and / or services from third-party providers) may also be deployed. A private cloud may include an external network connection (such as a connection to the Internet) through which a connection to an external entity (referred to herein as a cloud service provider or private cloud provider) may exist, and the private cloud provider may use this network connection to provide private cloud services, such as management services, software updates, software lifecycle management services, device lifecycle management services, health monitoring, etc. In other scenarios, a private cloud may be a disconnected private cloud, where the computing resources maintained by the entity reside at one or more physical locations and are not connected to an external network, such as the Internet.
[0012] In one or more examples, to facilitate the use of a private cloud, a private cloud provider may offer a private cloud platform through which administrators and users of the private cloud can manage, use, and / or otherwise interact with various resources of the private cloud. In one or more examples, the private cloud platform may use technologies for authentication and authorization of users and other entities for the use of its resources. As an example, users of resources in the private cloud may need access to and / or authorization to use services provided by the private cloud provider as part of the private cloud platform (e.g., access to and / or use of Virtual Machine as a Service (VMaaS), Bare Metal as a Service (BMaaS), etc.), and may also need access to and / or authorization to use other applications, services, etc., deployed within the private cloud (e.g., which may be provided via a third party).
[0013] In this scenario, entities can establish services and processes to control access to resources in a private cloud, such as deploying an entity identity management provider that can authenticate users and authorize them to use various resources within one or more domains. As an example, an entity can maintain any number of Active Directory (AD) domains that can be used to authenticate users and authorize them to use resources in one or more domains. In this scenario, entities can also use federated identity services, such as AD Federation Service (ADFS), to provide users with a single sign-on service. Users log in once through this service (e.g., using a username and password or other login criteria) and are issued a token containing various informational items that allow users to use additional computing resources without requiring additional login when shared with other devices, services, etc.
[0014] In some scenarios, users may be offered access to any portion of an entity's private cloud computing resources, such as various services, applications, files, and other information. Authenticated users may be granted individual access to such resources. Alternatively, authenticated users may be offered access to a subset of the private cloud's computing resources. As an example, the private cloud's computing resources may be divided into different workspaces, which may also be referred to as tenants (e.g., a bounded context in which an authenticated user is authorized to operate on computing resources), and users may be offered access to these workspaces (e.g., as a portion of a tenant) to have access to the computing resources within them.
[0015] Additionally, a specific user can be assigned one or more roles. In one or more examples, assigning roles to users can at least partially control the portion of the private cloud's computing resources that the user has access to. A given user can be provided with access to any number of workspaces, and / or can be assigned to any number of roles for accessing computing resources within an ecosystem of such resources (e.g., a private cloud). Additionally, any number of services and / or applications can be deployed in the private cloud, and a given workspace / tenant and / or specific role can be associated with certain services and / or applications so that users provided with access to the workspace / tenant or assigned to that role can access the corresponding set of services and applications.
[0016] However, challenges exist in facilitating single sign-on (SSO) access for users in private cloud environments. As an example, a cloud provider may offer a platform (referred to herein as a private cloud platform) through which users access and / or use various services of the private cloud, such as VMaaS and BMaaS services. Simultaneously, the private cloud can be configured with any number of applications from the private cloud provider and / or any number of third-party providers, through which users may also require access. Such services from the private cloud provider and other entities may not use authentication and authorization services configured to function correctly with each other. The examples disclosed herein address this problem by implementing a single sign-on (SSO) proxy that at least partially manages user authentication and authorization for using resources within the private cloud (including provider services such as VMaaS and BMaaS) and third-party services (such as various other applications deployed within the private cloud). In one or more examples, such an SSO agent can bridge SSO functionality between proprietary SSO functionality implemented by a private cloud provider and SSO functionality based on standard protocols (such as Security Assertion Markup Language (SAML), OpenID Connectivity (OIDC)) implemented by entities that maintain the private cloud and / or third-party applications deployed within the private cloud.
[0017] In one or more examples, the private cloud platform is configured to include a platform identity provider (e.g., PingFederate) for the private cloud platform, which may include a user interface (UI) and / or be associated with it for providing and managing SSO access for users, configuring roles for users (e.g., role modification), configuring workspaces / tenants, etc.
[0018] A platform identity provider can be initially configured to trust an existing identity provider (such as Active Directory and / or ADFS) maintained by the entity providing the private cloud for it, and therefore can be configured to match users, roles, and tenants set up by that entity using such an entity identity provider. For example, the platform identity provider can be configured to interact with the entity identity provider using industry-standard standards and protocols (such as SAML or OIDC). As an example, the platform identity provider can be configured to create workspaces and / or roles within the private cloud platform to mirror tenants and / or roles configured in the entity identity provider, and to accept (e.g., trust) user authentication from the entity identity provider (e.g., PingFederate within the private cloud platform can be configured to trust AD and / or ADFS maintained by the entity associated with the private cloud).
[0019] In one or more examples, the private cloud platform may include and / or be operatively connected to an SSO agent configured for the private cloud. In one or more examples, the SSO agent facilitates single sign-on access to various resources within the private cloud. As an example, the private cloud provider may configure the SSO agent to provide and manage SSO functionality so that users can access various resources, services, and / or third-party applications within the private cloud. In one or more examples, the SSO agent is configured to interact with the private cloud platform and various third-party applications to facilitate user SSO access to resources within the private cloud (e.g., services provided by the private cloud provider, third-party applications, etc.). To this end, the SSO agent may be configured with Identity and Access Management (IAM) tools (e.g., Keycloak) that act as a bridge between the workspace / tenant configured for the private cloud (e.g., sets of hardware and / or software resources), the services provided by the private cloud provider (e.g., VMaaS, BMaaS, private cloud monitoring services, etc.), and the corresponding constructs of the third-party applications.
[0020] Therefore, the IAM tool of the SSO agent can be configured with any number of domains, which are logical constructs corresponding to workspaces on a private cloud platform. For example, the platform identity provider of the private cloud platform can be configured with three workspaces corresponding to three tenants configured in the entity identity provider, and the IAM tool of the SSO agent can have three domains configured to correspond to the three workspaces. These domains can be configured to allow users to access the computing resources of the workspace / tenant associated with a given domain, and to be configured with the services and applications associated with that domain. Specific domains can have constructs called groups, which directly correspond to roles configured for users. Therefore, users assigned to a specific role can be correspondingly added to a specific group associated with that role within the domain of the SSO agent's IAM tool.
[0021] In one or more examples, access management provided by the SSO agent is at least partially driven by identity events. In one or more examples, an identity event is any change to access permissions for users within the private cloud. Examples of such identity events include, but are not limited to, adding a user, assigning a user to a workspace / tenant, removing a user, assigning a user to one or more roles, removing a user from one or more roles, granting or removing access to one or more applications for a user or role, creating a new workspace, deleting a workspace, creating a new role, deleting a role, etc. For example, such events can be triggered by an administrator via the private cloud platform's user interface (UI), or by an identity provider (such as Active Directory and / or ADFS) that uses entities to maintain an identity for the entity providing the private cloud.
[0022] In one or more examples, when any identity event occurs, a notification of the event is provided from the private cloud platform to the SSO agent. The notification may include any amount of information about the event. In one or more examples, the notification contains a limited amount of information, such as the user's identification, the identification of one or more workspaces associated with the event, and the fact that some unspecified event related to the user has occurred. For example, the event identification notification may be received at the SSO agent (e.g., via an event handler subscribed to receive such event notifications). The SSO agent can then extract relevant information from the event (e.g., user identity, one or more workspaces) and send a request to the private cloud platform to obtain user-related information, including, for example, the user's associated roles, permissions, accessible workspaces, etc. (e.g., user access permissions). In one or more examples, after obtaining this information from the private cloud platform, the information is provided to the SSO agent's IAM tool, and the SSO agent then updates one or more fields of the IAM tool to reflect any changes that triggered the identity event (e.g., the user being granted access to a third-party application, the user being added to a workspace, the user being removed from a workspace, etc.).
[0023] In one or more examples, the domains created within the SSO agent's IAM tool (e.g., Keycloak) directly correspond to the tenants created within the entity identity provider (e.g., AD and / or ADFS) and the corresponding workspaces created within the private cloud platform identity provider (e.g., PingFederate). In one or more examples, the SSO agent's IAM tool is configured to trust the private cloud platform identity provider (which in turn can be configured to trust the entity identity provider), and the domains of the IAM tool are configured to allow SSO access to the user's resources.
[0024] In one or more examples, these domains are also configured to bridge SSO access from the private cloud platform identity provider to third-party applications by maintaining an application identity management instance (e.g., a SAML application instance) within the domain for the corresponding application to allow access to other applications using industry-standard technologies (e.g., SAML). This is because the application identity management instance can be configured to trust the IAM tool to allow SSO access to the corresponding application. In one or more examples, using the IAM tool domain within the SSO broker can allow SSO access for users to access two services provided by the platform cloud provider (e.g., VMaaS, BMaaS, etc.) and other applications (e.g., third-party applications) deployed within the private cloud environment.
[0025] Figure 1 A block diagram of a private cloud 100 based on one or more examples disclosed herein is shown. Figure 1 As shown, the private cloud 100 includes an entity identity provider 102, a private cloud platform 104, a platform identity provider 106, platform workspaces 108 (including workspaces A 110 and B 112), a platform event transmitter 114, a platform authorization information repository 116, a single sign-on (SSO) agent 118, an event manager 120, identity and access management (IAM) tools (including domains A 124 and B 126), other applications 128 (including application A 130, application B 132, and application N 134), and private cloud resources 136. Each of these components is described below.
[0026] In one or more examples, a private cloud 100 is a cloud environment deployed and used by an entity or a specific set of entities. In one or more examples, a cloud environment is a collection of computing resources (e.g., computing devices, network devices, storage devices, various types of software, etc.). As an example, a specific entity (such as a company) may seek to have a cloud environment that its employees use for various purposes and / or that the company uses to provide various services to users.
[0027] A private cloud (e.g., private cloud 100) can be configured to provide computing resources to users of the private cloud on demand. To this end, an entity that has deployed private cloud 100 can obtain a private cloud platform (e.g., private cloud platform 104, which will be discussed further below), which may include a user interface (e.g., a web-based graphical user interface (UI)) that users of the entity can interact with to gain access to the computing resources of the private cloud.
[0028] In one or more examples, an entity deploying private cloud 100 may wish to secure private cloud 100 by implementing systems and technologies for authentication (e.g., for user identity) and authorization (e.g., for user access to or otherwise use of resources within private cloud 100). In some scenarios, the entity may configure an entity identity provider (e.g., entity identity provider 102). In one or more examples, entity identity provider 102 is a system maintained by the entity for authenticating users of private cloud 100 and / or authorizing such users to access or use resources within the private cloud.
[0029] In one or more examples, entity identity provider 102 is implemented using one or more computing devices. In one or more examples, as used herein, the computing device can be any single computing device, a set of computing devices, a portion of one or more computing devices, or any other physical, virtual, and / or logical grouping of computing resources. Non-limiting examples of computing devices are described below. Figure 4 and Figure 5 The computing device is shown in the image. In one or more examples, the computing device can be any type of device configured to host all or any part of one or more applications, microservices, cluster environment services, storage services, network services, and / or any other computing functionality, which may include executing instructions, performing operations, performing functions, performing computations, etc.
[0030] In one or more examples, a computing device is any device, part of a device, or any set of devices capable of processing instructions electronically, and may include, but is not limited to, any one of the following: one or more processors (e.g., components including circuitry), memory (e.g., random access memory (RAM)), input and output devices (multiple) of non-volatile storage hardware (e.g., solid-state drives (SSDs), persistent memory (Pmem) devices, hard disk drives (HDDs)), one or more physical interfaces (e.g., network ports, storage ports), any number of other hardware components, and / or any combination thereof.
[0031] Examples of computing devices include, but are not limited to, servers (e.g., blade servers in blade server chassis, rack servers in racks, desktop servers, any other type of server equipment), desktop computers, mobile devices (e.g., laptops, smartphones, personal digital assistants, tablets, automotive computing systems, and / or any other mobile computing devices), storage devices (e.g., disk drive arrays, Fibre Channel storage devices, Internet Small Computer System Interface (iSCSI) storage devices, tape storage devices, flash memory arrays, network-attached storage devices, any other type of storage devices), network devices, virtual machines, virtualized computing environments, logical containers (e.g., for one or more applications), container pods, Internet of Things (IoT) devices, node arrays of computing resources, supercomputing devices, data centers or any part thereof, any combination of the foregoing, and / or any other type of computing device. As will be appreciated by those skilled in the art, any of the above examples of computing devices necessarily requires at least some hardware components. By way of example, when virtual machines, containers, and / or container pods are considered computing devices herein, it includes the underlying hardware on which the virtual machines, containers, and / or container pods execute.
[0032] In one or more examples, the storage devices and / or memory of a computing device or computing device system may be and / or include one or more data repositories for storing any number of data structures that store any amount of data (e.g., information). In one or more examples, a data repository is any type of storage unit and / or device used for storing data (e.g., file system, database, collection of tables, RAM, hard disk drive, solid-state drive, and / or any other storage mechanism or medium). Further, a data repository may include multiple different storage units and / or devices. These multiple different storage units and / or devices may or may not be of the same type, or may or may not be located in the same physical location.
[0033] In one or more examples, any storage device and / or memory of a computing device or computing device system may be regarded, in whole or in part, as a non-transient computer-readable medium storing software and / or firmware that, when executed by one or more processors, causes one or more processors to perform operations (e.g., the execution of one or more computer programs) in accordance with one or more examples disclosed herein.
[0034] As an example, entity identity provider 102 may be an instance of Active Directory (AD) and / or AD Federation Services (ADFS) configured with one or more domains, capable of authenticating users (e.g., via username / password combinations and / or (multiple) other authentication technologies), assigning users to one or more tenants, assigning roles to users, etc. Other examples of identity providers may be used as entity identity provider 102 without departing from the scope of the examples disclosed herein.
[0035] Regardless of the identity provider solution used as entity identity provider 102, entity identity provider 102 can be configured with constructs such as users, tenants, and roles. A user can be any entity configured within entity identity provider 102 (e.g., employee, customer, end-user, software entity, etc.), whose identity can be authenticated using any authentication technology. A user can be any entity (e.g., human user, software entity, etc.) that has been granted access to the resources of private cloud 100 and can provide any type of information that allows the user's identity to be authenticated. A tenant can be, for example, a group of users, departments, sub-entities, etc., within an entity that has deployed private cloud 100 and has access to a set of public resources of private cloud 100. A role can be a license, access permission, etc., where any user assigned to that role can access the public portion of the resources of private cloud 100. In one or more examples, any addition, deletion, or change of a role can be referred to as a role modification.
[0036] In one or more examples, Entity Identity Provider 102 may be configured at least partially to provide Single Sign-On (SSO) functionality to users, whereby a user can be authenticated once and then authorized to access any resource of the private cloud 100. As an example, a token (or any other similar information item) may be generated for a user authenticated by Entity Identity Provider 102, which may be provided to other components within the private cloud (e.g., via a browser) for authenticating and authorizing the user as they navigate to various locations to access and use resources of the private cloud 100.
[0037] In one or more examples, private cloud 100 includes private cloud platform 104. In one or more examples, private cloud platform is a computing device (as discussed above) that is at least partially configured to provide a UI through which users, administrators, etc. of private cloud 100 can interact with private cloud 100.
[0038] In one or more examples, private cloud platform 104 is configured to at least partially manage access to resources of private cloud 100. For this purpose, in one or more examples, the private cloud platform includes platform identity provider 106. In one or more examples, platform identity provider 106 is implemented using computing devices (as discussed above). In one or more examples, the platform identity provider is configured to provide SSO access to resources of private cloud 100. One example of platform identity provider 106 is PingFederate. Other examples of platform identity providers may be used without departing from the scope of the examples disclosed herein. In one or more examples, platform identity provider 106 is configured to trust entity identity provider 102, which may mean that the platform identity provider is configured to trust authentication of users by the entity identity provider and is configured to establish constructs that at least partially match the constructs configured by entity identity provider 102, such as the roles and tenants of entity identity provider 102.
[0039] As an example, regarding user authentication, a user can access an entity identity provider to provide authentication information (such as logging in using a username and password, biometric information, etc.). When a user is successfully authenticated, entity identity provider 102 can provide information (such as a token) to platform identity provider 106, which verifies the authentication information and thus verifies the user as an authenticated user for private cloud 100.
[0040] In one or more examples, platform identity provider 106 may include one or more workspaces (e.g., workspace A 110, workspace B 112). In one or more examples, the workspaces of private cloud platform 104 are configured to at least partially match any similar construct (e.g., tenant) of entity identity provider 102. In one or more examples, a workspace (e.g., workspace A 110, workspace B 112) is a bounded context of the computing resources of private cloud 100, within which authenticated users are authorized to operate. The set of workspaces (e.g., workspace A 110, workspace B 112) may be collectively referred to as platform workspace 108. Although Figure 1 An example including two platform workspaces 108 is shown, but the private cloud platform 104 may include any number of platform workspaces 108 without departing from the scope of the examples disclosed herein.
[0041] In one or more examples, platform identity provider 106 may also configure roles that can at least partially match roles defined within entity identity provider 102. Thus, roles within entity identity provider 102 can be imported into platform identity provider 106 to allow users assigned to those roles to access resources of the private cloud 100 associated with that role.
[0042] In addition to or as an alternative to Platform Identity Provider 106, which mirrors Entity Identity Provider 102's users, roles, and tenants, without departing from the scope of the examples disclosed herein, Platform Identity Provider 104 may also separately configure workspaces within Private Cloud 100, define user roles for Private Cloud 100 (e.g., perform role modifications), and / or add additional users that Entity Identity Provider 102 does not understand. As an example, an administrator of Private Cloud 100 may use Private Cloud Platform 104 to configure additional users, roles, and / or workspaces within Platform Identity Provider 106.
[0043] In one or more examples, the private cloud platform 104 includes a platform authorization information repository 116. In one or more examples, the platform authorization information repository 116 is one or more data constructs of any type that include information about users, roles, workspaces, etc. As an example, the platform authorization information repository 116 may include data constructs that include an identified user and the corresponding role, license, user access permissions, and computing resources of the private cloud 100 associated with that user. In one or more examples, one or more data constructs of the platform authorization information repository 116 are stored in one or more storage devices of any type configured to function as a data repository.
[0044] In one or more examples, the private cloud platform 104 includes a platform event transmitter 114. In one or more examples, the platform event transmitter 114 is any hardware or a combination of hardware and software configured to be aware of any identity events occurring within the private cloud platform 104 and to send all or any part of such identity events to the event manager (e.g., event manager 120 discussed below) of the SSO agent (e.g., SSO agent 118 discussed below). In one or more examples, an identity event is any event representing a change to any user, role, workspace, etc., of the private cloud platform 104. Examples of identity events include, but are not limited to, adding a new user, deleting a user, making user-related changes, adding, removing, and / or changing roles (e.g., co-modifying roles), adding or removing a user from a workspace, adding a workspace, removing a workspace, changing a workspace, etc. In one or more examples, the platform event transmitter 114 is configured to send at least some information about the identity event as a notification to the event manager 120 (discussed below) of the SSO agent 118 (discussed below) at any time an identity event occurs. As an example, a notification may include a limited amount of information, such as the identity of the user and / or (multiple) workspaces to which the identity event corresponds.
[0045] In one or more examples, the private cloud platform 104 is configured to provide an interface through which authenticated users of the private cloud 100 can interact with their authorized resources within the private cloud 100. The resources of the private cloud 100 may include private cloud resources 136. In one or more examples, private cloud resources 136 are any computing resources (e.g., computing devices, network devices, management devices, etc.) deployed within the private cloud 100 and / or services (e.g., storage services, file services, network services, management services, monitoring services, etc.) implemented on such computing resources. The resources of the private cloud 100 may additionally or alternatively include other applications 128, which... Figure 1 The display shows applications A 130, B 132, and N 134. (As shown by...) Figure 1 As indicated by the three points between application B 132 and application N 134 shown herein, other applications 128 may include any number of applications without departing from the scope of the examples disclosed herein. In one or more examples, other applications 128 may be any one or more applications that can be used for any purpose and can be provided by the provider of private cloud 100 or any third party for use by users of private cloud 100.
[0046] As an example, a user can authenticate via entity identity provider 102 and access a web-based UI of private cloud platform 104, where the user can see links to various resources of private cloud 100 to which the user is authorized (such as private cloud resource 136 and / or other applications 128 mentioned above), such as configuring and / or accessing virtual machines via VMaaS services, configuring and / or accessing physical computing resources via BMaaS services, and / or accessing one or more applications (e.g., 130, 132, 134) deployed in the private cloud by the private cloud provider or any third-party application provider. In one or more examples, access to such resources may be facilitated at least in part via SSO proxy 118.
[0047] In one or more examples, the SSO agent 118 of the private cloud 100 is a computing device (as discussed above) configured to facilitate access to various computing resources of the private cloud 100 for users of the private cloud (including but not limited to human users, software entities, etc.). In one or more examples, the private cloud platform 104 is configured to interact with other applications, devices, components, etc. of the private cloud 100 via a private cloud platform-specific application programming interface (API). However, all or any part of the computing resources of the private cloud 100 may not be configured to use such an API.
[0048] As an example, many resources and / or applications of private cloud 100 (e.g., other applications 128, services within private cloud resources 136) are configured with tenant and workspace structures similar to those described above, which control which users are allowed to access and use the applications and / or resources, and which features and / or functionalities of the applications and / or resources are allowed for a given user. For example, such applications may be configured with certain identity technologies and protocols (e.g., SAML) that must be used to access and use the applications and / or resources, which may differ from the API of private cloud platform 104. Therefore, SSO agent 118 may be deployed in private cloud 100 to at least partially act as a bridge between private cloud platform 104 and the various private cloud resources 136 and other applications 128 of private cloud 100.
[0049] In one or more examples, SSO agent 118 includes IAM tool 122. The IAM tool can be a computing device (as discussed above) configured to implement identity and access management within private cloud 100. One example of IAM tool 122 is Keycloak. Other IAM tools can be used as IAM tool 122 without departing from the scope of the examples disclosed herein. In one or more examples, IAM tool 122 is configured to trust platform identity provider 106 of private cloud platform 104. Therefore, in one or more examples, IAM tool 122 can be configured to have a construct that mirrors the construct of the platform identity provider. In one or more examples, IAM tool 122 is configured to have any number of fields (e.g., field 124, field 126). Although Figure 1 The IAM tool is shown as two fields with configuration, but the IAM tool can include any number of fields without departing from the scope of the examples disclosed herein.
[0050] In one or more examples, a domain (e.g., 124, 126) is a construct within IAM tool 122 that mirrors the workspace of platform identity provider 106 on private cloud platform 104. Therefore, a domain (such as a workspace) can be a bounded context of computing resources, applications, etc., within which authenticated users are authorized to operate. In one or more examples, a user assigned to a specific workspace (e.g., 110, 112) can thus be assigned to the corresponding domain (e.g., 124, 126) of IAM tool 122.
[0051] IAM tool 122 can also be configured to have a construct corresponding to the role construct of platform identity provider 106, which is referred to herein as a group. Therefore, users assigned to a specific role within platform identity provider 106 can be assigned to a corresponding group within IAM tool 122, and any role modification made within entity identity provider and / or platform identity provider will result in a notification to SSO agent 118, which triggers a modification of the corresponding group in IAM tool 122.
[0052] In one or more examples, a domain (e.g., 124, 126) may be configured to have one or more application identity management instances (not shown), each of which may correspond to an application in other applications 128 (e.g., 130, 132, 134). As an example, a domain (e.g., domain A 124) may include a SAML application instance corresponding to application A 130. In one or more examples, the application identity management instances in a domain are configured to provide users in that domain with access to the corresponding application. As an example, a user may be authenticated via entity identity provider 102 and access the web-based UI of private cloud platform 104 based on authentication provided to platform identity provider 106, which is configured to trust entity identity provider 102. In the web-based UI, users can see links to various resources of the private cloud 100 to which they are authorized to access (such as the aforementioned private cloud resource 136 and / or other applications 128), such as configuring and / or accessing virtual machines via VMaaS services, configuring or accessing physical computing resources via BMaaS services, and / or using one or more applications (e.g., 130, 132, 134) deployed in the private cloud by the private cloud provider or any third-party application provider. When a user selects an application, service, or resource, authentication information (e.g., a token) corresponding to the user can be provided to the IAM tool 122, which is configured to trust the authenticated user from the platform identity provider 106. If the user selects one of the other applications 128, the IAM tool 122 can provide authentication information to the application identity management instance within the domain to which the user is authorized and which corresponds to the application the user is attempting to access. In one or more examples, the application identity management instance can provide authentication information to the corresponding application, which can be configured to trust the IAM tool, thereby authorizing the user to use the application or any part thereof.
[0053] In one or more examples, the SSO agent 118 includes an event manager 120. In one or more examples, the event manager 120 is any hardware or software executing on any hardware, configured to receive identity events from the private cloud platform 104, parse the identity events to obtain information therein, use this information to obtain additional information about the identity events, and use the additional information to enable the IAM tool 122 to make any modifications to the domains (e.g., 124, 126) based on changes that triggered the identity events. The event manager 120 of the SSO agent is described below. Figure 2 It is discussed in more detail in the description.
[0054] Although Figure 1Specific configurations of the devices and / or components are shown, but other configurations may be used without departing from the scope of the examples described herein. Therefore, the examples disclosed herein should not be limited to... Figure 1 The configuration of the displayed devices and / or components.
[0055] Figure 2 This is a block diagram of an SSO agent 200 based on one or more examples disclosed herein. For example... Figure 2 As shown, the SSO agent 200 includes an IAM tool 202 and an event manager 208. In one or more examples, the IAM tool 202 includes domain A 204 and domain B 206. In one or more examples, the event manager 208 includes an event receiver 210, an event handler 212, an authorization synchronization handler 214, an IAM tool interface 216, and a platform authorization library 218. Each of these components is described below.
[0056] In one or more examples, SSO agent 200 and Figure 1 The example shown is the same as or substantially similar to the SSO agent 118 discussed above. In one or more examples, the IAM tool 202 is... Figure 1 The IAM tool 122 shown above is the same as or substantially similar to the one described. In one or more examples, Domain A 204 and Domain B 206 are... Figure 1 The fields shown are the same as or substantially similar to those discussed above, 124 and 126.
[0057] In one or more examples, Event Manager 208 is Figure 1 The example of Event Manager 120 shown and discussed above. Therefore, Event Manager 208 is part of an SSO agent (e.g., SSO agent 200) and is operatively connected to the IAM tool 202 of SSO agent 200. Although Figure 1 Although not shown in the image, Event Manager 208 can also be operatively connected to a private cloud platform (e.g., Figure 1 The private cloud platform 104 shown in the diagram and discussed above, and more specifically, the platform event transmitter (e.g., [missing information]) connected to the private cloud platform. Figure 1 The platform event transmitter 114 shown in the figure and discussed above) and the platform authorization information repository (e.g. Figure 1 The platform authorization information repository 116 shown in the document and discussed above.
[0058] In one or more examples, the event manager 208 includes an event receiver 210. In one or more examples, the event receiver 210 may be configured to receive data from a private cloud platform (e.g., Figure 1The platform event transmitter (e.g., the private cloud platform 104) Figure 1 The platform event transmitter 114 receives identity event notifications (as discussed above) from any hardware (e.g., one or more processors) or software executing on hardware (e.g., one or more processors). In one or more examples, the event receiver 210 is configured to receive an identity event notification each time an identity event occurs within the private cloud platform. In one or more examples, the identity event notification includes a limited amount of information, such as the identifier of one or more users and / or one or more workspaces corresponding to the identity event.
[0059] In one or more examples, event manager 208 includes event handler 212. In one or more examples, event handler 212 is configured to subscribe to receive notifications of specific types of events, including identity events. In one or more examples, based on this subscription, event handler 212 can receive notifications of identity events from event receiver 210 and parse such notifications to obtain information included therein, such as the identifier of the user and / or workspace corresponding to the notification. In one or more examples, based on this information, event handler 212 can provide the information extracted from the notification to IAM tool interface 216 and / or authorization synchronization handler 214.
[0060] In one or more examples, when an identity event is the addition or deletion of a user, the identity event can be treated as an authentication event, and the associated information can be provided to the IAM tool interface 216 of the event manager 208. In this case, the IAM tool interface 216 can be configured to interact with the IAM tool 202 to add or remove users from one or more fields (e.g., 204, 206) in the case of the IAM tool.
[0061] In one or more examples, when an identity event is related to authorization for a user to access private cloud resources, create or remove workspaces, or create, remove or modify roles (e.g., role modification), the event handler 212 may provide information extracted from the notification of the identity event to the authorization synchronization handler 214.
[0062] In one or more examples, the authorization synchronization handler 214 may then generate a request to the platform authorization library 218 to obtain authorization from a private cloud platform (e.g., Figure 1 The platform authorization information repository of the private cloud platform 104 (e.g.) Figure 1 The platform authorization information repository 218 is used to obtain information. In one or more examples, the platform authorization repository 218 is configured to work with a private cloud platform (e.g., Figure 1The platform authorization library 218 is a repository (e.g., code, functions, scripts, etc.) that interacts with at least one or more APIs of the private cloud platform 104. In one or more examples, the platform authorization library 218 is configured to interact with the private cloud platform via API to obtain information related to authorization type identity events and to provide such information to the authorization synchronization handler 214 and / or the IAM tool interface 216.
[0063] As an example, when an identity event is related to a change in a private cloud resource that allows the user access, the authorization synchronization handler 214 can use the platform authorization library 218 to obtain user access permissions from the platform authorization information repository of the private cloud platform, which will include any changes made to such user access permissions. In one or more examples, the IAM tool interface 216 can then be invoked to interact with the IAM tool 202 to update one or more fields (e.g., 204, 206) to correctly reflect these changes.
[0064] Although Figure 2 Specific configurations of the devices and / or components are shown, but other configurations may be used without departing from the scope of the examples described herein. Therefore, the examples disclosed herein should not be limited to... Figure 2 The configuration of the devices and / or components shown in the document.
[0065] Figure 3 An overview of example methods for managing identity events via an SSO agent in a private cloud environment, based on one or more examples disclosed herein, is shown.
[0066] Method 300 can be at least partially provided by a private cloud (e.g., Figure 1 The private cloud 100) can be executed by one or more devices and / or components. Therefore, for example, all or any part of method 300 can be performed by an SSO agent (e.g., Figure 1 SSO agent 118 Figure 2 The SSO agent 200) is executed.
[0067] Although Figure 3 The steps in the flowchart shown are presented and described sequentially, but some or all of the steps may be performed in a different order, some or all of the steps may be combined or omitted, and some or all of the steps may be combined with... Figure 3 Other steps and / or Figure 3 The steps not shown in the text are executed in parallel.
[0068] In step 302, method 300 includes an SSO agent (e.g., Figure 1 SSO agent 118 Figure 2 The SSO agent 200) obtains access to private clouds (e.g., Figure 1 Identity events associated with users of a private cloud (e.g., a private cloud 100). In one or more examples, identity events can occur when a private cloud platform (e.g., a private cloud 100) is accessed. Figure 1 Any changes of any kind related to users, roles, or workspaces on the private cloud platform (104) can occur at any time. For example, changes can be made by the private cloud platform (e.g., Figure 1 This change can be made by the administrator of the private cloud platform 104 or the administrator of the entity identity provider (e.g., entity identity provider 102). Examples of identity events include, but are not limited to, adding a new user, deleting a user, user-related changes, adding, removing and / or changing roles (e.g., role modification), adding or removing a user from a workspace, adding a workspace, removing a workspace, changing a workspace, etc. For example, identity events can be made by the administrator and the entity identity provider (e.g., the administrator of the private cloud platform 104) or the administrator of the entity identity provider (e.g., the administrator of the private cloud platform 104). Figure 1 Entity identity provider 102) and / or platform identity provider (e.g. Figure 1 The SSO agent is triggered by interacting with the platform identity provider 106. In one or more examples, the SSO agent is triggered via an event receiver (e.g., Figure 2 The event receiver 210 can obtain the identity event, and can be transmitted via the event handler (e.g., Figure 2 The event handler 212) parses identity events to obtain information related to the identity events, such as, for example, the identifiers of one or more users, roles, and / or workspaces corresponding to the identity events.
[0069] In step 304, method 300 includes the use of an SSO agent (e.g., Figure 1 SSO agent 118 Figure 2 The SSO agent 200 requests a set of user information corresponding to the user from the private cloud platform corresponding to the private cloud in response to an identity acquisition event. In one or more examples, the set of user information is associated with the private cloud platform (e.g., Figure 1 This includes any set of information related to the user of the private cloud platform (104). Such user information may include, for example, user access permissions, indicating that the user is entitled to access and / or otherwise use the private cloud (e.g., Figure 1 The user information set refers to the resources within a private cloud (100). In one or more examples, the user information set includes, but is not limited to, information related to a user's workspace, role, application, etc., and portions of such resources that a particular user is authorized to access and / or otherwise use. In one or more examples, the user information set may include information related to a single user or any number of users. In one or more examples, the user information set may include information about roles or workspaces, including information about which users are authorized to access them. As an example, when a new workspace is added, the user information set may include information about the set of users associated with the new workspace.
[0070] In one or more examples, the SSO agent requests a user information set based on the information about the identity event obtained in step 302. In one or more examples, the SSO agent uses a platform authorization library (e.g., Figure 2 The platform authorization repository (218) is used to obtain a set of user information. As an example, the platform authorization repository may be provided with at least a portion of the information obtained from notifications of identity events, and this information is used to form a set of information from the platform authorization information repository (e.g., [the repository]) to be sent to the private cloud platform. Figure 1 The platform authorization repository (116) requests corresponding information. In one or more examples, the platform authorization repository is configured to communicate with the private cloud platform to request user information sets using one or more APIs specific to the private cloud platform. In one or more examples, the private cloud platform responds to such requests by providing the user information set to the SSO agent, which includes corresponding user access permissions, information about changes to one or more workspaces, and / or information about changes to one or more roles.
[0071] In step 306, method 300 includes providing a user information set to an SSO agent (e.g., Figure 1 SSO agent 118 Figure 2 SSO agent 200) Identity Access Management (IAM) tools (e.g. Figure 1 IAM tools 122 Figure 2 IAM tools 202). In one or more examples, all or any part of the user information set is from the SSO agent's event manager (e.g., Figure 2 The event manager (208) is provided to the IAM tools. In one or more examples, the SSO agent's event manager uses the IAM tool interface (e.g., the event manager 208). Figure 2 The IAM tool interface 216 is used to provide a user information set to the IAM tool, and the IAM tool interface can be configured to pass the user information set to the IAM tool.
[0072] In step 308, method 300 includes updating the IAM tool (e.g., based on the user information set) used to reflect identity events. Figure 1 The domain of IAM tools 202 (e.g.) Figure 2(Fields 204, 206). In one or more examples, the fields of the IAM tool correspond to the workspace of the private cloud platform and / or the tenant of the entity identity provider. In one or more examples, one or more fields of the IAM tool are updated based on identity events and the changes(s) that cause the identity events to reflect information in the user information set. As an example, when a user is added or removed to the workspace, the field can be updated to include or remove the user. As another example, when a user is authorized to access a specific application (e.g., ... Figure 1 When an identity event occurs (e.g., granting a user access to an application or another application 128), the domain can be updated to reflect the user's new access permissions to that application. As another example, if a new workspace is created, a new domain can be created in the IAM tool to mirror the new workspace. As another example, if a role is modified, added, or removed (e.g., a role modification occurs), the corresponding group within the domain of the IAM tool is also modified, added, or removed (e.g., a corresponding group modification occurs). In one or more examples, when identity events include granting a user access and / or otherwise authorizing the use of an application within the private cloud, updating the domain can include updating the application identity management instance within the domain corresponding to the application, using the user's authorization information.
[0073] In one or more examples, although Figure 3 Not shown in the text, but when the domain of the IAM tool of the SSO agent has been updated, the user can authenticate via a single sign-on process with the entity identity provider. When the user accesses the private cloud platform, authentication can be provided to the private cloud platform, and the user may be able to access the resources of the private cloud, including the services and applications therein. This can be facilitated at least in part by the SSO agent. Therefore, the IAM tool is provided with information (such as a token) related to the authenticated user, which can be used to authorize the user to access and / or otherwise use the resources configured within the domain of the IAM tool.
[0074] Figure 4 A block diagram of a computing device 400 according to one or more examples disclosed herein is shown. The computing device 400 can be any of the computing devices described above (e.g., Figure 1 Private cloud platform 104 Figure 1 Entity identity provider 102 Figure 1 SSO agent 118 Figure 2 Examples of SSO agent 200 and / or computing device 500 as described below. (See above for examples of SSO agent 200 and / or computing device 500.) Figure 1 , Figure 2 and Figure 3 As discussed in the description, computing device 400 can be used to implement Figure 1 and / or Figure 2All or any part of the various components shown and described above, and / or performing Figure 3 All or any part of the methods 300 shown and described above.
[0075] Computing device 400 may include one or more processors 402 and memory 404. Memory 404 may include a non-transitory computer-readable medium storing programming for execution by one or more of the one or more processors 402. In this implementation, one or more modules within computing device 400 may be implemented, in whole or in part, as software for performing any of the functionalities described in this disclosure. For example, computing device 400 may be configured to perform by executing instructions included in memory 404 and executed by one or more processors 402. Figure 3 The method 300 shown and described above.
[0076] For example, memory 404 may include instructions 406 to obtain identity events associated with a user of the private cloud at a single sign-on (SSO) agent (e.g., referenced above). Figure 3 (as described in step 302).
[0077] For example, memory 404 may include instructions 408 to request a set of user information corresponding to the user from the private cloud platform corresponding to the private cloud (e.g., as referenced above) in response to an identity acquisition event by the SSO agent. Figure 3 (as described in step 304).
[0078] For example, memory 404 may include instructions 410 to provide a user information set to the SSO agent's Identity Access Management (IAM) tool (e.g., referenced above). Figure 3 (as described in step 306).
[0079] For example, memory 404 may include instructions 412 to update the domain of the IAM tool based on the user information set to reflect identity events (e.g., as referenced above). Figure 3 (as described in step 308).
[0080] Figure 5 A block diagram of a computing device according to one or more examples of this disclosure is shown. As discussed above, the examples described herein can be implemented at least in part using a computing device, and Figure 5 The computing device 500 shown in the document can be such a computing device. For example, Figure 1 (e.g., entity identity provider 102, private cloud platform 104, SSO agent 118) and / or Figure 2All or any part of the components shown in (e.g., SSO agent 200, IAM tool 202) can be implemented at least in part using a computing device such as computing device 500, and may include Figure 5 All or any part of the components of the computing device 500 shown in and described below.
[0081] In one or more examples, a computing device (e.g., computing device 500) is any device, part of a device, or any set of devices capable of electronically processing instructions, and may include, but is not limited to, any of the following: one or more processors (e.g., components including circuitry) (e.g., processor 502), memory (e.g., random access memory (RAM)) (not shown), (multiple) input and output devices (e.g., non-persistent storage devices 506), non-volatile storage hardware (e.g., solid-state drives (SSDs), persistent memory (Pmem) devices, hard disk drives (HDDs) (not shown)), one or more physical interfaces (e.g., network ports, storage ports) (e.g., persistent storage devices 506), any number of other hardware components (not shown), and / or any combination thereof. As used herein, a processor can be any component that can be configured to perform operations, processes, threads, etc. In some examples, a computing device (e.g., computing device 500) may include any number of heterogeneous processors.
[0082] The computing device 500 may include a communication interface 512 (e.g., a Bluetooth interface, an infrared interface, a network interface, an optical interface, or any other type of communication interface), an input device 510, an output device 508, and many other components (not shown) and functionalities. Each of these components is described below.
[0083] In one or more examples, the computer processor(s) 502 may be an integrated circuit for processing instructions. For example, the computer processor(s) may be one or more cores or microcores of a processor. Processor 502 may be a general-purpose processor configured to execute program code included in software executed on computing device 500. Processor 502 may be a special-purpose processor, where certain instructions are incorporated into the processor design. Processor 502 may be a central processing unit (CPU), a multi-core CPU, an application-specific integrated circuit (ASIC), a graphics processing unit (GPU), a data processing unit (DPU), a tensor processing unit (TPU), an associative processing unit (APU), a vision processing unit (VPU), a quantum processing unit (QPU), and / or various other processing units using dedicated hardware (e.g., field-programmable gate array (FPGA), system-on-a-chip (SOC), digital signal processor (DSP)). Although in Figure 5Only one processor 502 is shown, but computing device 500 may include any number of processors without departing from the scope of the examples disclosed herein.
[0084] The computing device 500 may also include one or more input devices 510, such as a touchscreen, keyboard, mouse, microphone, touchpad, electronic pen, motion sensor, or any other type of input device. Input devices 510 allow users to interact with the computing device 500. In one or more examples, the computing device 500 may include one or more output devices 508, such as a screen (e.g., a liquid crystal display (LCD), plasma display, touchscreen, cathode ray tube (CRT) monitor, projector, or other display device), printer, external storage device, or any other output device. The one or more output devices may be the same as or different from the input devices(s). The input and output devices(s) may be locally or remotely connected to the computer processor(s) 502, non-persistent storage device(s) 504, and persistent storage device(s) 506. Many different types of computing devices exist, and the aforementioned input and output devices(s) may take other forms. In some instances, a multi-mode system allows users to provide multiple types of input / output to communicate with the computing device 500.
[0085] Furthermore, the communication interface 512 can facilitate the connection of the computing device 500 to a network (not shown) (e.g., a local area network (LAN), a wide area network (WAN) such as the Internet, a mobile network, or any other type of network) and / or another device (such as another computing device). The communication interface 512 can use wired and / or wireless transceivers of any type and / or technology to perform or facilitate the reception and / or transmission of wired or wireless communications. Examples include, but are not limited to, the use of audio jacks / plugs, microphone jacks / plugs, Universal Serial Bus (USB) ports / plugs, etc. Ports / plugs, Ethernet ports / plugs, fiber optic ports / plugs, proprietary wired ports / plugs Wireless signal transmission, BLE wireless signal transmission Wireless signal transmission, RFID wireless signal transmission, Near Field Communication (NFC) wireless signal transmission, Dedicated Short Range Communication (DSRC) wireless signal transmission, 802.11 Wi-Fi wireless signal transmission, WLAN signal transmission, Visible Light Communication (VLC), Global Microwave Access Interoperability (WiMAX), IR communication wireless signal transmission, Public Switched Telephone Network (PSTN) signal transmission, Integrated Services Digital Network (ISDN) signal transmission, 3G / 4G / 5G / LTE cellular data network wireless signal transmission, ad hoc network signal transmission, radio wave signal transmission, microwave signal transmission, infrared signal transmission, visible light signal transmission, ultraviolet light signal transmission, wireless signal transmission along the electromagnetic spectrum, or combinations thereof. Communication interface 512 may also include one or more Global Navigation Satellite System (GNSS) receivers or transceivers used to determine the location of computing device 500 based on receiving one or more signals from one or more satellites associated with one or more GNSS systems. GNSS systems include, but are not limited to, the US-based GPS, the Russian-based GLONASS, the Chinese-based BeiDou Navigation Satellite System (BDS), and the European-based Galileo GNSS. There are no restrictions on operation on any particular hardware layout, so the basic features here can be easily replaced by improved hardware or firmware layouts that are developed.
[0086] The term computer-readable medium includes, but is not limited to, portable or non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or carrying instructions and / or data. Computer-readable media can include non-transient media in which data can be stored and excludes carrier waves and / or transient electronic signals propagated wirelessly or via a wired connection. Examples of non-transient media include, but are not limited to, magnetic disks or magnetic tapes, optical storage media such as CDs or DVDs, flash memory, memory, or memory devices. Computer-readable media may have code and / or machine-executable instructions stored thereon, which may represent procedures, functions, subroutines, programs, routines, subroutines, modules, software groups, categories, or any combination of instructions, data structures, or program statements. A code segment can be coupled to another code segment or hardware circuitry by passing and / or receiving information, data, variables, parameters, or memory contents. Information, variables, parameters, data, etc., can be passed, forwarded, or transmitted via any suitable means, including memory sharing, messaging, token passing, network transmission, etc.
[0087] All or any part of the components of computing device 500 may be implemented in a circuit arrangement. For example, these components may include electronic circuits or other electronic hardware and / or may be implemented using electronic circuits or other electronic hardware, which may include one or more programmable electronic circuits (e.g., microprocessors, GPUs, DSPs, FPGAs, CPUs, CAMs, and / or other suitable electronic circuits), and / or may include computer software, firmware, or any combination thereof and / or may be implemented using computer software, firmware, or any combination thereof to perform the various operations described herein. In some aspects, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referred to, non-transient computer-readable storage media expressly exclude media such as energy, carrier signals, electromagnetic waves, and the signals themselves.
[0088] In the foregoing description, numerous details have been set forth as examples described herein. Those skilled in the art (and who also benefit from this disclosure) will understand that one or more of the examples described herein can be practiced without these specific details, and that many variations or modifications may be possible without departing from the scope of the examples described herein. Certain details known to those skilled in the art may have been omitted to avoid obscuring the description.
[0089] Specific details are provided in the foregoing description to provide a thorough understanding of the various aspects and examples presented herein. However, those skilled in the art will understand that the various aspects and examples can be practiced without these specific details. For clarity, in some instances, the technology may be presented as including functional blocks that may include devices, device components, steps, or routines in methods implemented in software or a combination of hardware and software. Additional components may be used in addition to those shown in the figures and / or described herein. For example, circuits, systems, networks, processes, and other components may be shown as components in block diagram form so as not to obscure the aspects with unnecessary detail. In other instances, well-known circuits, processes, algorithms, structures, and techniques may be shown without unnecessary detail so as not to obscure the aspects of the examples disclosed herein.
[0090] The above can describe various aspects as a process or method, depicted as a flowchart, flow diagram, data flow diagram, structure diagram, or block diagram. Although a flowchart can describe operations as a sequential process, many operations can be executed in parallel or concurrently. Additionally, the order of operations can be rearranged. A process can terminate when its operations are completed, but it can also have additional steps not included in the figures. A process can correspond to a method, function, procedure, subroutine, subroutine, etc. When a process corresponds to a function, its termination can correspond to the function returning to the calling function or the main function.
[0091] The processes and methods described in the examples above can be implemented using computer-executable instructions that are stored or otherwise available from a computer-readable medium. Such instructions may include, for example, instructions and data that cause a general-purpose computer, special-purpose computer, network device, or processing device to perform a particular function or set of functions, or otherwise configure a general-purpose computer, special-purpose computer, network device, or processing device to perform a particular function or set of functions. Part of the computer resources used may be network-accessible. The computer-executable instructions may be, for example, binary, intermediate format instructions (such as assembly language), firmware, source code, etc. Examples of computer-readable media that may be used to store instructions, information used, and / or information created during the methods according to the described examples include disks or optical discs, flash memory, USB devices provided with non-volatile memory, networked storage devices, etc.
[0092] In the above description of the accompanying drawings, in the various examples described herein, any component described with respect to the drawings may be equivalent to one or more components with the same or similar names and / or numbers described with respect to any other drawing. For the sake of brevity, the description of these components may not be repeated with respect to every drawing. Thus, each example of a component in each drawing is incorporated by reference, and it is assumed that they may optionally exist in each other drawing having one or more components with the same or similar names and / or numbers. Additionally, any description of a component in a drawing, based on the various examples described herein, shall be interpreted as an optional example, which may be implemented in addition to, in combination with, or in lieu of an example described with respect to one or more corresponding components with the same or similar names and / or numbers in any other drawing.
[0093] Throughout the application, ordinal numbers (e.g., first, second, third) may be used as adjectives for elements (i.e., any noun in this application). The use of ordinal numbers does not imply or create any particular ordering of elements, nor does it limit any element to having only a single element, unless explicitly stated otherwise, such as through the use of terms like “before,” “after,” “single,” and other such terms. Rather, ordinal numbers are used to distinguish elements. By example, the first element is different from the second element, and the first element may encompass more than one element and is in the order of elements after (or before) the second element.
[0094] As used herein, the phrase "operably connected," "operable connection," and its variations imply the existence of a direct or indirect connection between elements / components / devices that allows the elements to interact with each other in a certain way. For example, the phrase "operably connected" can refer to any direct (e.g., a wired connection directly between two devices or components) or indirect (e.g., a wired and / or wireless connection between any number of devices or components that are operably connected). Therefore, any path through which information can pass can be considered an operational connection.
[0095] While the examples disclosed herein have been described with respect to a limited number of examples, those skilled in the art who benefit from this disclosure will understand that other examples can be contemplated without departing from the scope of the examples disclosed herein. Therefore, the scope of the examples described herein should be limited only by the appended claims.
Claims
1. A system comprising: One or more processors; as well as One or more non-transient computer-readable media, the one or more non-transient computer-readable media storing instructions, the instructions, when executed by the one or more processors, causing the one or more processors to: At the Single Sign-On (SSO) agent, obtain identity events associated with the user in the private cloud; In response to the identity acquisition event, the SSO agent requests a set of user information corresponding to the user from the private cloud platform corresponding to the private cloud. The user information set is provided to the Identity Access Management (IAM) tool of the SSO agent; as well as Based on the user information set, the domain of the IAM tool is updated to reflect the identity event.
2. The system of claim 1, wherein the domain of the IAM tool is configured to correspond to the workspace of the private cloud platform.
3. The system according to claim 2, wherein the workspace of the private cloud platform corresponds to the tenant of the entity identity provider.
4. The system according to claim 1, wherein: The identity events include role modifications for roles associated with the user. The domain of the IAM tool is configured with groups corresponding to the roles. Furthermore, in order to update the field of the IAM tool, the instructions, when executed by the one or more processors, also cause the one or more processors to: Modify the group corresponding to the modified role.
5. The system according to claim 1, wherein: The IAM tool's domain is configured with an application identity management instance corresponding to the application deployed within the private cloud, and The identity event includes granting the user access to the application in the private cloud, the application corresponding to the application identity management instance in the domain.
6. The system of claim 1, wherein, in order for the SSO agent to request the user information set, the instruction further causes the one or more processors to: interact with the private cloud platform via the SSO agent through an application programming interface (API) provided by the private cloud platform.
7. The system of claim 1, wherein execution of the instructions further causes the one or more processors to: When the user performs an SSO action via the private cloud platform, the user's identity is authenticated; and Following the authentication, the user is authorized to access the services and applications configured within the domain of the IAM tool of the SSO agent.
8. A computer-implemented method, comprising: At the Single Sign-On (SSO) agent, obtain identity events associated with the user in the private cloud; In response to the identity acquisition event, the SSO agent requests a set of user information corresponding to the user from the private cloud platform corresponding to the private cloud. The user information set is provided to the Identity Access Management (IAM) tool of the SSO agent; as well as Based on the user information set, the domain of the IAM tool is updated to reflect the identity event.
9. The computer-implemented method of claim 8, wherein the domain of the IAM tool is configured to correspond to the workspace of the private cloud platform.
10. The computer-implemented method of claim 9, wherein the workspace of the private cloud platform corresponds to a tenant of the entity identity provider.
11. The computer-implemented method according to claim 8, wherein: The identity events include role modifications for roles associated with the user. The domain of the IAM tool is configured with groups corresponding to the roles. And updating the domain of the IAM tool based on the user information set to reflect the identity event includes: Modify the group corresponding to the modified role.
12. The computer-implemented method according to claim 8, wherein: The IAM tool's domain is configured with an application identity management instance corresponding to the application deployed within the private cloud, and The identity event includes granting the user access to the application in the private cloud, the application corresponding to the application identity management instance in the domain.
13. The computer-implemented method of claim 8, wherein requesting the user information set by the SSO agent comprises: The SSO agent interacts with the private cloud platform through the application programming interface (API) provided by the private cloud platform.
14. The computer-implemented method according to claim 8, further comprising: When the user performs an SSO action via the private cloud platform, the user's identity is authenticated; as well as Following the authentication, the user is authorized to access the services and applications configured within the domain of the IAM tool of the SSO agent.
15. A non-transient computer-readable medium storing a program for execution by one or more processors, the programming comprising instructions to: At the Single Sign-On (SSO) agent, obtain identity events associated with the user in the private cloud; In response to the identity acquisition event, the SSO agent requests a set of user information corresponding to the user from the private cloud platform corresponding to the private cloud. The user information set is provided to the Identity Access Management (IAM) tool of the SSO agent; as well as Based on the user information set, the domain of the IAM tool is updated to reflect the identity event.
16. The non-transient computer-readable medium according to claim 15, wherein: The domain of the IAM tool is configured to correspond to the workspace of the private cloud platform, and The workspace of the private cloud platform corresponds to the tenant of the entity identity provider.
17. The non-transient computer-readable medium according to claim 15, wherein: The identity events include role modifications for roles associated with the user. The domain of the IAM tool is configured with groups corresponding to the roles. Furthermore, in order to update the area of the IAM tool, the program also includes instructions to: Modify the group corresponding to the modified role.
18. The non-transient computer-readable medium according to claim 15, wherein: The IAM tool's domain is configured with an application identity management instance corresponding to the application deployed within the private cloud, and The identity event includes granting the user access to the application in the private cloud, the application corresponding to the application identity management instance in the domain.
19. The non-transient computer-readable medium of claim 15, wherein, in order for the SSO agent to request the user information set, the program further includes instructions for the SSO agent to interact with the private cloud platform via an application programming interface (API) provided by the private cloud platform.
20. The non-transient computer-readable medium of claim 15, wherein the program further comprises instructions to: When the user performs an SSO action via the private cloud platform, the user's identity is authenticated; and Following the authentication, the user is authorized to access the services and applications configured within the domain of the IAM tool of the SSO agent.