IP Library Granted Patent US 8,327,434
Granted Patent B2
US 8,327,434 · App. 12/541,645 · Granted Dec 4, 2012

System and method for implementing a proxy authentication server to provide authentication for resources not located behind the proxy authentication server

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,327,434
App. No.
12/541,645
Granted
Dec 4, 2012
Kind
B2
Abstract

Networked resources that are not located behind a proxy authentication server may be enabled to use the proxy authentication server for authentication. This may provide one or more of the features associated with a proxy authentication server (e.g., centralized administration of authentication and/or access information, enhancing software security, centralized administration of permission information, and/or other features) for the resources not located behind the proxy authentication server. These features may be provided without requiring substantial modification of the proxy authentication server.

Claims (33)

1. A system configured to enable networked resources not behind a proxy authentication server to use the proxy authentication server for authentication, the system comprising:

electronic storage configured to store information related to one or more users, wherein the stored information for individual users includes authentication information;

a proxy authentication server configured to act as an intermediary between a client operated by a user and one or more servers behind the proxy authentication server that are configured to serve client requests to a first set of one or more resources, the proxy authentication server being further configured to authenticate the client based on a comparison between authentication information received from the client and authentication information stored in the electronic storage;

an identification server communicatively linked with the proxy and configured to transmit an identifier that authenticates the client to one or more servers not behind the proxy authentication server;

wherein the proxy authentication server and the identification server are further configured to (i) receive an authentication request from a server that is not located behind the proxy server and is configured to serve client resources to a second set of one or more resources, (ii) in response to receiving such a request, to initiate a determination by the proxy authentication server as whether or not the client is currently authenticated by the proxy authentication server, and (iv) to transmit the identifier from the identification server to the server not behind the proxy authentication server only if the proxy authentication server determines that the client is currently authenticated.

2. The system of claim 1 , wherein the proxy authentication server and the identification server are further configured to direct the client to the proxy authentication server to enable the proxy authentication server to request authentication information from the client only if the proxy authentication server determines that the client is not currently authenticated.

3. The system of claim 2 , wherein the proxy authentication server is further configured such that if the client is not currently authenticated and is directed to the proxy authentication server, the proxy authentication server (i) requests authentication information from the client, (ii) receives authentication information from the client, (iii) compares the received authentication information with authentication information stored in the electronic storage, (iv) authenticates the client only if the received authentication information corresponds to stored authentication information, and (v) transmits an indication of the authentication to the identification server.

4. The system of claim 3 , wherein the identification server is further configured to receive the indication of the authentication of the client from the proxy authentication server, and to transmit the identifier to the server not behind the proxy authentication server in response to reception of the indication of authentication.

5. The system of claim 1 , wherein the client comprises a processor executing a web browser application.

6. The system of claim 1 , wherein the identification server comprises an identity provider.

7. The system of claim 6 , wherein the identity provider is an OpenID provider.

8. The system of claim 1 , wherein the authentication information comprises login information.

9. The system of claim 8 , wherein the login information includes a user identification and a password.

10. A method of enabling of networked resources not behind a proxy authentication server to use the proxy authentication server for authentication, the method comprising:

receiving, at an identification server and/or a proxy authentication server communicatively linked with each other, a request from a server not behind the proxy authentication server for an identifier that authenticates a client to the server not behind the proxy authentication server;

determining, via the proxy authentication server, whether the client is currently authenticated to the proxy authentication server; and

transmitting the identifier from the identification server to the server not behind the proxy authentication server only if the proxy authentication server determines that the client is currently authenticated to the proxy authentication server.

11. The method of claim 10 , further comprising directing the client to the proxy authentication server to enable the proxy authentication server to request authentication information from the client only if the proxy authentication server determines that the client is not currently authenticated.

12. The method of claim 11 , further comprising:

storing information related to one or more users to machine-readable electronic storage media, wherein the stored information for individual users includes authentication information;

transmitting a request from the proxy authentication server to the client for authentication information from the client;

receiving authentication information at the proxy authentication server from the client;

comparing the received authentication information with authentication information stored in the electronic storage media;

authenticating the client only if the received authentication information corresponds to stored authentication information; and

transmitting an indication of the authentication from the proxy authentication server to the identification server.

13. The method of claim 12 , further comprising:

receiving the indication of the authentication of the client from the proxy authentication server; and

transmitting the identifier to the server not behind the proxy authentication server in response to reception of the indication of authentication.

14. The method of claim 10 , wherein the client comprises a processor executing a web browser application.

15. The method of claim 10 , wherein the identification server comprises an identity provider.

16. The method of claim 15 , wherein the identity provider is an OpenID provider.

17. The method of claim 10 , wherein the authentication information comprises login information.

18. The method of claim 17 , wherein the login information includes a user identification and a password.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2009
From: BOWEN, PETER
To: NOVELL, INC.
Reel/Frame 023102/0890 →