-
公开(公告)号:US11580239B2
公开(公告)日:2023-02-14
申请号:US16660275
申请日:2019-10-22
Applicant: Microsoft Technology Licensing, LLC
Inventor: Daniel John Carroll, Jr. , Kameshwar Jayaraman , Stuart Kwan , Kartik Tirunelveli Kanakasabesan , Shefali Gulati , Charles Glenn Jeffries , Ganesh Pandey , Roberto Carlos Taboada , Parul Manek , Steven Mark Silverberg
Abstract: Access to data and resources in a multi-tenant computing system is managed by tagging the data and resources with attributes, as well as by tagging users with attributes. Tenant-specific access policies are configured. When an access request is received from a workload, a policy decision engine processes the attributes that are tagged to the requesting workload (e.g., user, application, etc.) as well as those tagged to the requested data or resource, given a relevant tenant-specific policy. An access decision is provided in response to the access request, and the access decision can be enforced by a tenant-specific enforcement system.
-
公开(公告)号:US20210117561A1
公开(公告)日:2021-04-22
申请号:US16660275
申请日:2019-10-22
Applicant: Microsoft Technology Licensing, LLC
Inventor: Daniel John CARROLL, JR. , Kameshwar Jayaraman , Stuart Kwan , Kartik Tirunelveli Kanakasabesan , Shefali Gulati , Charles Glenn Jeffries , Ganesh Pandey , Roberto Carlos Taboada , Parul Manek , Steven Mark Silverberg
Abstract: Access to data and resources in a multi-tenant computing system is managed by tagging the data and resources with attributes, as well as by tagging users with attributes. Tenant-specific access policies are configured. When an access request is received from a workload, a policy decision engine processes the attributes that are tagged to the requesting workload (e.g., user, application, etc.) as well as those tagged to the requested data or resource, given a relevant tenant-specific policy. An access decision is provided in response to the access request, and the access decision can be enforced by a tenant-specific enforcement system.
-