IP Library Granted Patent US 7,836,493
Granted Patent B2
US 7,836,493 · App. 10/421,948 · Granted Nov 16, 2010

Proxy server security token authorization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,836,493
App. No.
10/421,948
Granted
Nov 16, 2010
Kind
B2
Abstract

A management server manufactures a secure, tamper-resistant token for a particular user specifying the permissions and authorizations that user possesses. The token may be in the form of a digitally-signed message specifying, for example, a particular computer and associated port number that the user is permitted to access. The management server delivers the token to the user, preferably over a secure communications session. When challenged, the user presents the secure token to the security proxy server. The security proxy server examines the token to be sure it is authentic and has not be tampered with, and then extracts information contained in the token to determine the user's authorization to access a particular computer, particular port number and/or other resource. The security proxy server then establishes authorized communication with the authorized computing resource based on the information contained in the user's token, and thereafter may act in one embodiment as essentially a passthrough or proxy for permitting the user to access and communicate with the resource.

Claims (25)

1. A method of authorizing use of a particular computing resource by a user, comprising:

(a) a management server issuing, to a user computer, a secure authorization token, said secure authorization token having data including connection permission information that identifies the specific protected computer resource by at least one of name and port number;

(b) examining, with a proxy server, the secure authorization token for authenticity, and extracting, with said proxy server, said connection permission information contained in the token to determine the user's authorization to access said specific protected computing resource; and

(c) if the secure authorization token is authentic, said proxy server using said secure authorization token data connection permission information to establish a proxy connection with said specific protected computing resource on behalf of the user and acting as an intermediary to pass information between the user computer and the specific protected computing resource, without said proxy server accessing or communicating with the management server to obtain user authorization information,

wherein said management server is separate from said proxy server, said protected computing resource and said user computer.

2. The method of claim 1 wherein said management server comprises a trusted entity different from said proxy server.

3. The method of claim 1 wherein said management server digitally signs said token with a digital signature and said examining includes authenticating said digital signature.

4. The method of claim 1 wherein said management server time-stamps said token.

5. The method of claim 1 further including said proxy server challenging said user for said token and said user responding to said challenge by presenting said token to said proxy server.

6. The method of claim 1 wherein said using step is performed conditionally based at least in part on whether said token is unexpired.

7. The method of claim 1 wherein said using step includes extracting both a computer name and port number from said token and establishing a connection using said computer name and port number.

8. A proxy server comprising:

means for receiving a secure authorization token from a user device, said secure authorization token having been issued by a management server, said authorization token including connection data comprising computer name and port number

means for examining said token to determine the authenticity thereof and to extract at least connection data therefrom; and

means for establishing a proxy server session conditioned on the authenticity of said token, wherein said proxy server acts as an intermediary between said user device and a specific protected computing resource the token specifies and said extracted connection data is used to establish said proxy server session without said proxy server accessing or communicating with said management server to obtain user authorization information.

9. A proxy server comprising:

a challenge function that challenges a user device to present a secure authorization token issued by a management server;

a token validator that validates said secure authorization token; and

a token content extractor that extracts connection information from said validated token including at least one of computer name and port number; and

a session controller that establishes a proxy connection with a specific protected computing resource based at least in part on the extracted connection information without need for said session controller to directly access or communicate with said management server to obtain user device authorization information, and intermediates a session between said user device and the specific protected computing resource conditioned at least in part on token validation by said token validator, said proxy server using secure authorization token data connection permission information within said secure authorization token to establish a proxy connection with said specific protected computing resource on behalf of the user and acting as an intermediary to pass information between the user computer and the specific protected computing resource.

10. The proxy server of claim 9 wherein said token is digitally signed and said token validator validates said digital signature.

11. The proxy server of claim 9 wherein connection information contained in said token includes at least computer name and port number.

12. The proxy server of claim 9 wherein said token validator determines whether said token has expired and whether said token has been tampered with.

13. The proxy server of claim 9 wherein said management server comprises a trusted entity different from said proxy server.

14. The proxy server of claim 9 wherein said proxy server establishes a first connection behind a firewall with a legacy host computer not equipped with SSL/TLS and establishes a second connection with said user device through said firewall, said proxy server proxying, in said first connection, on behalf of the user device connection.

Assignments (25)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028253/0098 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: ATTACHMATE CORPORATION
Reel/Frame 034443/0621 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028253/0086 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: ATTACHMATE CORPORATION
Reel/Frame 034443/0558 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028253/0086 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028253/0098 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026268/0096) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: ATTACHMATE CORPORATION
Reel/Frame 028253/0059 →
RELEASE OF SECURITY INTEREST IN PATENTS SECOND LIEN (RELEASES RF 026275/0105) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: ATTACHMATE CORPORATION
Reel/Frame 028253/0042 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0105 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026268/0096 →
RELEASE OF PATENTS AT REEL/FRAME NOS. 17870/0329 AND 020929 0225 Recorded May 2, 2011
From: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS SECOND LIEN COLLATERAL AGENT
To: ATTACHMATE CORPORATION
Reel/Frame 026213/0762 →
RELEASE OF PATENTS AT REEL/FRAME NOS. 017858/0915 AND 020929/0228 Recorded May 2, 2011
From: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS FIRST LIEN COLLATERAL AGENT
To: ATTACHMATE CORPORATION
Reel/Frame 026213/0265 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded Jul 4, 2006
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS SECOND LIEN COLLATERAL AGENT
Reel/Frame 017870/0329 →
RELEASE OF SECURITY INTEREST Recorded Jun 30, 2006
From: WELLS FARGO FOOTHILL, INC.
To: ATTACHMATE CORPORATION, ATTACHMATE ACQUISITION CORPORATION, WRQ, INC., WIZARD HOLDING CORPORATION
Reel/Frame 017870/0001 →
GRANT OF PATENT SECURITY INTEREST (FIRST LIEN) Recorded Jun 30, 2006
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 017858/0915 →
RELEASE OF SECURITY INTEREST Recorded Jun 30, 2006
From: D. B. ZWIRN
To: ATTACHMATE CORPORATION, ATTACHMATE ACQUISITION CORPORATION, WRQ, INC., WIZARD HOLDING CORPORATION
Reel/Frame 017858/0923 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2005
From: WRQ, INC.
To: ATTACHMATE CORPORATION
Reel/Frame 017215/0729 →
SECURITY AGREEMENT Recorded May 26, 2005
From: WRQ, INC.; ATTACHMATE ACQUISITION CORP.; ATTACHMATE CORPORATION
To: WELLS FARGO FOOTHILL, INC., AS AGENT
Reel/Frame 016059/0775 →
SECURITY INTEREST Recorded Jan 4, 2005
From: WRQ, INC.; WIZARD HOLDING CORPORATION, A DELAWARE CORPORATION; WRQ INTERNATIONAL, INC., A WASHINGTON CORPORATION
To: D.B. ZWIRN SPECIAL OPPORTUNITIES FUND, L.P.
Reel/Frame 015529/0804 →
SECURITY AGREEMENT Recorded Dec 29, 2004
From: WRQ, INC.; WIZARD MERGER CORPORATION
To: WELLS FARGO FOOTHILL, INC.
Reel/Frame 015499/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2003
From: XIA, SHARON; BROMBAUGH, DAN
To: WRQ, INC.
Reel/Frame 014255/0441 →