US 12,149,537 B2
Resource access control in cloud environments
Stanimir Lukanov, Sofia (BG); Georgi Lyubomirov Dimitrov, Sofia (BG); and Georgi Lekov, Sofia (BG)
Assigned to VMware LLC, Palo Alto, CA (US)
Filed by VMware Inc., Palo Alto, CA (US)
Filed on Jan. 12, 2022, as Appl. No. 17/574,306.
Prior Publication US 2023/0224304 A1, Jul. 13, 2023
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/105 (2013.01) [H04L 63/0853 (2013.01); H04L 63/20 (2013.01)] 24 Claims
OG exemplary drawing
 
1. A method for access management in a cloud-services computing environment, the method comprising:
receiving, by a resource managing service, a request to access resources of a resource directory managed by the resource managing service, wherein the request includes a token for identity authentication of a user;
in response to reading the token, determining a container membership associated with the user, wherein the container membership maps the user to a container from a set of containers for the resource directory, wherein the container groups a set of resources in a tree data structure of the resource directory;
filtering access rights defined in authorization primitives associated with the container membership based on container policy rules for the set of containers in the resource directory; and
in response to the filtering, providing access to the set of resources from the resource directory based on the received request.