IP Library Granted Patent US 7,844,625
Granted Patent B2
US 7,844,625 · App. 12/110,695 · Granted Nov 30, 2010

Managing secured resources in web resources that are accessed by multiple portals

Assignee: BEA Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,844,625
App. No.
12/110,695
Granted
Nov 30, 2010
Kind
B2
Abstract

A method, apparatus, and computer-readable media for authorizing users of network portals to access a secure resource hosted by a secure server comprises storing a plurality of user identifiers, each representing a user of an owning portal; storing for each of the user identifiers an access privilege to the secure resource; storing a proxy user identifier representing a guest portal and a guest access privilege to the secure resource for all of the users of the guest portal; receiving from the owning portal a first request for access to the secure resource, the first request comprising a first user identifier representing a user of the owning portal; granting to the user of the owning portal access to the secure resource according to the access privilege stored for the first user identifier; receiving from the guest portal a second request for access to the secure resource, the second request comprising a second user identifier representing a user of the guest portal and a portal identifier representing the guest portal; and granting to the user of the guest portal access to the secure resource according to the guest access privilege stored in the authorization table for the proxy user identifier.

Claims (13)

1. An apparatus for authorizing users of network portals to access a project hosted by a secure server, comprising:

an owning portal including an owning portal (OP) policy manager, an OP repository, and an authorization table,

the OP policy manager for determining whether a user is authorized to communicate with the secure server,

the OP repository for comparing authentication information to stored information, and

the authorization table for storing a plurality of user identifiers, each representing a user of the owning portal, and for storing for each of the user identifiers an access privilege to the project;

wherein the owning portal is configured for assigning a proxy user identifier to a guest portal, and for associating a role with the proxy user identifier that conveys certain access privileges to the project, the role including an access level and an activity security; and

wherein the authorization table stores a portal identifier, role, and proxy user identifier representing the guest portal and a guest access privilege to the project for users of the guest portal;

a secure server including a secure server policy manager for receiving from the owning portal a first request for access to the project, the first request comprising a first user identifier representing a user of the owning portal,

wherein the secure server policy manager grants to the user of the owning portal access to the project according to the access privilege stored in the authorization table for the first user identifier;

wherein the secure server policy manager receives from the guest portal a second request for access to the project, the second request comprising a second user identifier representing a user of the guest portal and the portal identifier representing the guest portal,

wherein the secure server policy manager grants to the user of the guest portal access to the project according to the guest access privilege stored in the authorization table for the proxy user identifier, and

wherein the first request comprises a portal identifier representing the owning portal, wherein the apparatus further comprises a portal repository to receive the first request, and to authenticate the owning portal using the portal identifier in the first request; and

an owning portal authentication information to comprise a http basic authentication header that includes an identifier, a password and a cookie for the owning portal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2011
From: BEA SYSTEMS, INC.
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 025986/0548 →
Continuity (3)
Continuation 1146383900 · Aug 10, 2006
Continuation 1015953200 · May 31, 2002
Related Publication 20080289010A1 · Nov 20, 2008