IP Library Granted Patent US 12676844
Granted Patent B2
US 12676844 · App. 18/171,948 · Granted Jul 7, 2026

Methods and systems for performing domain-wide authentication and authorization

Inventors: Christopher Tucker (South San Francisco, CA); Fernando Cerenza (San Francisco, CA); Kimberly Kung (San Bruno, CA); Prachi Jadhav (Emerald Hills, CA)
Assignee: Box, Inc.
H04L63/0807H04L67/1097H04L67/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12676844
App. No.
18/171,948
Granted
Jul 7, 2026
Kind
B2
Abstract

According to one embodiment, a method for performing domain-wide authentication and authorization in a cloud-based environment can comprise receiving, from a third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the third-party service for accessing a cloud-based storage system of the cloud-based environment. A mapping of the user of the third-party service to a user account of the cloud-based storage system can be generated and one or more tokens for the user of the third-party service can in turn be generated based on the mapping of the user of the third-party service to the user account of the cloud-based storage system. The one or more tokens can provide access to services of the cloud-based storage system. The one or more tokens can be provided to the third-party service.

Claims (90)

1 . A method for performing domain-wide authentication and authorization in a cloud-based environment, the method comprising:

initiating, by a domain-wide authorization system, a backfill process performing domain-wide authentication and authorization for a plurality of users of a third-party service of the cloud-based environment, wherein the backfill process comprises onboarding of the plurality of users of the third-party service as users of the cloud-based environment;

receiving, by the domain-wide authorization system, from the third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the of the plurality of users of the third-party service for accessing a cloud-based storage system of the cloud-based environment through the third-party service, wherein the user of the third party service is logged into the third-party service but not the cloud-based storage system;

generating, by the domain-wide authorization system, a mapping of the user of the third-party service to a user account of the user of the third-party service on the cloud-based storage system;

generating, by the domain-wide authorization system, one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system, wherein the one or more tokens provide access to services of the cloud-based storage system; and

providing, by the domain-wide authorization system, the one or more tokens to the third-party service.

2 . The method of claim 1 , further comprising, prior to generating the mapping of the user of the third-party service to the user account of the cloud-based storage system, determining, by the domain-wide authorization system, whether the user of the third-party service is eligible for domain-wide authentication and authorization and wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system, generating the one or more tokens for the user of the third-party service, and providing the one or more tokens to the third-party service are performed in response to determining the user of the third-party service is eligible for domain-wide authentication and authorization.

3 . The method of claim 1 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:

receiving, by the domain-wide authorization system, from the third-party service, user information for the user of the third-party service;

searching, by the domain-wide authorization system, a set of user information of the cloud-based storage system based on the received user information for the user of the third-party service; and

determining, by the domain-wide authorization service, whether the user information for the user of the third-party service matches any user information in the set of user information of the cloud-based storage system, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user information for the user of the third-party service matches user information in the set of user information of the cloud-based storage system.

4 . The method of claim 3 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining, by the domain-wide authorization system, whether the user of the third-party service is eligible for domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service is eligible for domain-wide authentication and authorization.

5 . The method of claim 3 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining, by the domain-wide authorization system, whether the user of the third-party service has opted out of domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service has not opted out of domain-wide authentication and authorization.

6 . The method of claim 1 , wherein generating the one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:

receiving, by the domain-wide authorization system, from the cloud-based storage system, information indicating a scope for authorization of the user of the third-party system;

obtaining, by the domain-wide authorization system, the one or more tokens for the user of the third-party service based on the information indicating the scope for authorization of the user of the third-party system;

providing, by the domain-wide authorization system, the one or more tokens for the user of the third-party service to the third-party service; and

notifying, by the domain-wide authorization system, the user of the third-party service of authorization completion.

7 . The method of claim 1 , wherein the backfill process comprises:

adding, by the domain-wide authorization system, an initiation message for the backfill process to a backfill queue, the initiation message identifying an entity for which the backfill process is performed, wherein the user and the set of users are associated with the entity;

reading, by the domain-wide authorization system, the initiation message for the backfill process from the backfill queue;

retrieving, by the domain-wide authorization system, user information for the set of users based on the entity identified in the initiation message;

assigning, by the domain-wide authorization system, the set of users to a group of users for the backfill process;

creating, by the domain-wide authorization system, a fanout job for the group of users;

adding, by the domain-wide authorization system, the fanout job to a job queue;

reading, by the domain-wide authorization system, the fanout job from the job queue;

mapping, by the domain-wide authorization system, the set of users of the third-party service to a set of users account of the cloud-based storage system;

generating, by the domain-wide authorization system, one or more tokens for the set of users of the third-party service based on the mapping of the set of users of the third-party service to the set of users account of the cloud-based storage system;

providing, by the domain-wide authorization system, the one or more tokens for the set of users of the third-party service to the third-party service; and

notifying, by the domain-wide authorization system, the set of users of the third-party service of authorization completion.

8 . A system comprising:

a processor; and

a memory coupled with and readable by the processor and storing therein a set of instructions which, when executed by the processor, causes the processor to perform domain-wide authentication and authorization in a cloud-based environment by:

initiating a backfill process performing domain-wide authentication and authorization for a plurality of users of a third-party service of the cloud-based environment, wherein the backfill process comprises onboarding of the plurality of users of the third-party service as users of the cloud-based environment;

receiving, from the third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the of the plurality of users of the third-party service for accessing a cloud-based storage system of the cloud-based environment through the third-party service, wherein the user of the third party service is logged into the third-party service but not the cloud-based storage system;

generating a mapping of the user of the third-party service to a user account of the user of the third-party service on the cloud-based storage system;

generating one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system, wherein the one or more tokens provide access to services of the cloud-based storage system; and

providing the one or more tokens to the third-party service.

9 . The system of claim 8 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:

receiving, from the third-party service, user information for the user of the third-party service;

searching a set of user information of the cloud-based storage system based on the received user information for the user of the third-party service; and

determining whether the user information for the user of the third-party service matches any user information in the set of user information of the cloud-based storage system, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user information for the user of the third-party service matches user information in the set of user information of the cloud-based storage system.

10 . The system of claim 9 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining whether the user of the third-party service is eligible for domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service is eligible for domain-wide authentication and authorization.

11 . The system of claim 9 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining whether the user of the third-party service has opted out of domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service has not opted out of domain-wide authentication and authorization.

12 . The system of claim 8 , wherein generating the one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:

receiving, from the cloud-based storage system, information indicating a scope for authorization of the user of the third-party system;

obtaining the one or more tokens for the user of the third-party service based on the information indicating the scope for authorization of the user of the third-party system;

providing the one or more tokens for the user of the third-party service to the third-party service; and

notifying the user of the third-party service of authorization completion.

13 . The system of claim 8 , wherein the backfill process comprises:

adding an initiation message for the backfill process to a backfill queue, the initiation message identifying an entity for which the backfill process is performed, wherein the user and the set of users are associated with the entity;

reading the initiation message for the backfill process from the backfill queue;

retrieving user information for the set of users based on the entity identified in the initiation message;

assigning the set of users to a group of users for the backfill process;

creating a fanout job for the group of users;

adding the fanout job to a job queue;

reading the fanout job from the job queue;

mapping the set of users of the third-party service to a set of users account of the cloud-based storage system;

generating one or more tokens for the set of users of the third-party service based on the mapping of the set of users of the third-party service to the set of users account of the cloud-based storage system;

providing the one or more tokens for the set of users of the third-party service to the third-party service; and

notifying the set of users of the third-party service of authorization completion.

14 . A non-transitory, computer-readable medium comprising a set of instructions stored therein which, when executed by a processor, causes the processor to perform domain-wide authentication and authorization in a cloud-based environment by:

initiating a backfill process performing domain-wide authentication and authorization for a plurality of users of a third-party service of the cloud-based environment, wherein the backfill process comprises onboarding of the plurality of users of the third-party service as users of the cloud-based environment;

receiving, from the third-party service of the cloud-based environment, a request to perform authentication and authorization of a user of the of the plurality of users of the third-party service for accessing a cloud-based storage system of the cloud-based environment through the third-party service, wherein the user of the third party service is logged into the third-party service but not the cloud-based storage system;

generating a mapping of the user of the third-party service to a user account of the user of the third-party service on the cloud-based storage system;

generating one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system, wherein the one or more tokens provide access to services of the cloud-based storage system; and

providing the one or more tokens to the third-party service.

15 . The non-transitory, computer-readable medium of claim 14 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:

receiving, from the third-party service, user information for the user of the third-party service;

searching a set of user information of the cloud-based storage system based on the received user information for the user of the third-party service; and

determining whether the user information for the user of the third-party service matches any user information in the set of user information of the cloud-based storage system, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user information for the user of the third-party service matches user information in the set of user information of the cloud-based storage system.

16 . The non-transitory, computer-readable medium of claim 15 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining whether the user of the third-party service is eligible for domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service is eligible for domain-wide authentication and authorization.

17 . The non-transitory, computer-readable medium of claim 15 , wherein generating the mapping of the user of the third-party service to the user account of the cloud-based storage system further comprises determining whether the user of the third-party service has opted out of domain-wide authentication and authorization, wherein mapping of the user of the third-party service to the user account of the cloud-based storage system is performed in response to determining the user of the third-party service has not opted out of domain-wide authentication and authorization.

18 . The non-transitory, computer-readable medium of claim 14 , wherein generating the one or more tokens for the user of the third-party service based on the mapping of the user of the third-party service to the user account of the cloud-based storage system comprises:

receiving, from the cloud-based storage system, information indicating a scope for authorization of the user of the third-party system;

obtaining the one or more tokens for the user of the third-party service based on the information indicating the scope for authorization of the user of the third-party system;

providing the one or more tokens for the user of the third-party service to the third-party service; and

notifying the user of the third-party service of authorization completion.

19 . The non-transitory, computer-readable medium of claim 14 , wherein the backfill process comprises:

adding an initiation message for the backfill process to a backfill queue, the initiation message identifying an entity for which the backfill process is performed, wherein the user and the set of users are associated with the entity;

reading the initiation message for the backfill process from the backfill queue;

retrieving user information for the set of users based on the entity identified in the initiation message;

assigning the set of users to a group of users for the backfill process;

creating a fanout job for the group of users;

adding the fanout job to a job queue;

reading the fanout job from the job queue;

mapping the set of users of the third-party service to a set of users account of the cloud-based storage system;

generating one or more tokens for the set of users of the third-party service based on the mapping of the set of users of the third-party service to the set of users account of the cloud-based storage system;

providing the one or more tokens for the set of users of the third-party service to the third-party service; and

notifying the set of users of the third-party service of authorization completion.