US 11,677,679 B2
Method and system for managing sub-tenants in a cloud computing environment
Oliver Bantke, Erlangen (DE); Balazs Biro, Budapest (HU); Denes Andras Bisztray, Budapest (HU); Christoph Elsner, Erlangen (DE); Bernhard Gatzhammer, Pfaffenhofen a.d.llm (DE); Frank Hackländer, Stuttgart (DE); Dorottya Hanak, Gödöllö (HU); Ronny Hendrych, Nuremberg (DE); Matthias Herbort, Sulzbach-Rosenberg (DE); Balazs Jakab, Budapest (HU); Tobias Moser, Fürth (DE); Istvan Raska, Bekecs (HU); Sebastian Ries, Munich (DE); Janos Schmidt, Budapest (HU); Ulf Vesper, Adelsdorf (DE); and Andreas Walz, Zirndorf (DE)
Assigned to Siemens Aktiengesellschaft, Munich (DE)
Appl. No. 16/970,714
Filed by SIEMENS AKTIENGESELLSCHAFT, Munich (DE)
PCT Filed Feb. 19, 2019, PCT No. PCT/EP2019/054090
§ 371(c)(1), (2) Date Aug. 18, 2020,
PCT Pub. No. WO2019/158774, PCT Pub. Date Aug. 22, 2019.
Claims priority of application No. 18157408 (EP), filed on Feb. 19, 2018; application No. 18181234 (EP), filed on Jul. 2, 2018; and application No. 18214045 (EP), filed on Dec. 19, 2018.
Prior Publication US 2020/0382442 A1, Dec. 3, 2020
Int. Cl. H04L 47/762 (2022.01); H04L 47/726 (2022.01); H04L 47/783 (2022.01); H04L 67/148 (2022.01); H04L 9/40 (2022.01)
CPC H04L 47/762 (2013.01) [H04L 47/726 (2013.01); H04L 47/783 (2013.01); H04L 63/0807 (2013.01); H04L 67/148 (2013.01)] 17 Claims
OG exemplary drawing
 
1. A method of managing sub-tenants in a cloud computing environment, the method comprising:
receiving a request to access sub-set of data of an asset from a cloud computing system from a sub-tenant device associated with a sub-tenant of a tenant, wherein the sub-tenant is associated with an asset, wherein the request comprises a sub-tenant identifier, a tenant identifier, and an asset identifier;
determining that the tenant associated with the sub-tenant is authorized to access the sub-set of data of the asset using the tenant identifier;
determining, after determining that the tenant is authorized, at least one role defined for the sub-tenant based on the sub-tenant identifier;
determining one or more permissions associated with the at least one role;
determining whether the sub-tenant is authorized to access the sub-set of asset data based on the determined role and permissions associated with the sub-tenant;
and
providing access to the requested sub-set data of the asset to the sub-tenant when the sub-tenant is authorized to access the requested sub-set data of the asset.