US 12,309,135 B2
Federated login with centralized control
Seungyeop Han, Sunnyvale, CA (US); Hao Wu, Mountain View, CA (US); Xiaopeng Xu, Sunnyvale, CA (US); and Tiffany Lin, San Mateo, CA (US)
Assigned to Rubrik, Inc., Palo Alto, CA (US)
Filed by Rubrik, Inc., Palo Alto, CA (US)
Filed on Jun. 21, 2023, as Appl. No. 18/212,651.
Application 18/212,651 is a continuation of application No. 17/387,083, filed on Jul. 28, 2021, granted, now 11,722,475.
Claims priority of provisional application 63/058,650, filed on Jul. 30, 2020.
Prior Publication US 2023/0379317 A1, Nov. 23, 2023
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/0815 (2013.01) [H04L 63/083 (2013.01); H04L 63/101 (2013.01); H04L 63/104 (2013.01)] 14 Claims
OG exemplary drawing
 
1. A method, comprising:
configuring, at a centralized management system, an authority of a user to access resources associated with the centralized management system;
translating, at the centralized management system, the authority of the user to obtain a translated authorization information associated with an access control system of a cluster, wherein the translated authorization information comprises one or more role based attributes and is indicative of the authority of the user and is based at least in part on a version of the cluster;
receiving, from the cluster based at least in part on registration of the cluster at the centralized management system, a security assertion markup language (SAML)-based login handshake;
transmitting, to the cluster associated with the centralized management system and via a SAML-assertion in response to receiving the SAML-based login handshake, the translated authorization information corresponding to the authority of the user and comprising the one or more role based attributes for the user, wherein the translated authorization information is transmitted by the centralized management system in response to registration of the cluster with the centralized management system;
receiving, from the user and at the centralized management system, a selection of a resource of the cluster; and
directing, in response to the selection of the resource of the cluster, the user to a user interface (UI) of the cluster, wherein the SAML-assertion enables the user to manage the cluster without performing an individual cluster login.