IP Library Granted Patent US 8,479,259
Granted Patent B2
US 8,479,259 · App. 12/570,868 · Granted Jul 2, 2013

Secure customer interface for web based data management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,479,259
App. No.
12/570,868
Granted
Jul 2, 2013
Kind
B2
Abstract

An integrated series of security protocols is disclosed that protect remote user communications with remote enterprise services, and simultaneously protect the enterprises services from third parties. In the first layer, an implementation of the Secure Sockets Layer (SSL) version of HTTPS provides communications security, including authentication of the enterprise web server and the security of the transmitted data. The protocols provide for an identification of the user, and an authentication of the user to ensure the user is who he/she claims to be and a determination of entitlements that the user may avail themselves of within the enterprise system. Session security is described, particularly as to the differences between a remote user's copper wire connection to a legacy system and a user's remote connection to the enterprise system over a “stateless” public Internet, where each session is a single transmission, rather than an interval of time between logon and logoff, as is customary in legacy systems. Security for the enterprise network and security for the data maintained by the various enterprise applications is also described.

Claims (36)

1. A method comprising:

establishing a secure session with a web server;

receiving a message over the secure session from a browser application via the web server, wherein the message is encrypted using a first encryption key;

decrypting the received message to determine a user identifier associated with the browser application;

verifying that the user identifier associated with the browser application is entitled to access a communication service;

reencrypting the message using a second encryption key; and

selectively forwarding the reencrypted message to an application proxy corresponding to the communication service based on the verification of the user identifier.

2. A method according to claim 1 , wherein the message is received from the web server through a firewall, the web server being part of a web server cluster.

3. A method according to claim 2 , wherein the browser application communicates with the web server over a public data network through another firewall coupled to the web server.

4. A method according to claim 1 , wherein the message includes an outer protocol layer, the method further comprising:

unwrapping the outer protocol layer from the message.

5. A method according to claim 1 , wherein the application proxy is an application specific daemon residing on an intranet server.

6. A method according to claim 1 , wherein the application proxy is an application specific daemon residing on an intranet server, and is configured to access another service provided by another intranet server.

7. A method according to claim 1 , wherein the first encryption key and the second encryption key are associated with a public key encryption scheme.

8. A method according to claim 1 , wherein the secure session includes a session cookie corresponding to the browser application.

9. An apparatus comprising:

a processor configured to initiate establishment of a secure session with a web server; and

a communication interface coupled to the processor and configured to receive a message over the secure session from a browser application via the web server, wherein the message is encrypted using a first encryption key,

wherein the processor is further configured to decrypt the received message to determine a user identifier associated with the browser application, to verify that the user identifier associated with the browser application is entitled to access a communication service, to reencrypt the message using a second encryption key, and to selectively forward the reencrypted message to an application proxy corresponding to the communication service based on the verification of the user identifier.

10. An apparatus according to claim 9 , wherein the message is received from the web server through a firewall, the web server being part of a web server cluster.

11. An apparatus according to claim 10 , wherein the browser application communicates with the web server over a public data network through another firewall coupled to the web server.

12. An apparatus according to claim 9 , wherein the message includes an outer protocol layer, the processor being further configured to unwrap the outer protocol layer from the message.

13. An apparatus according to claim 9 , wherein the application proxy is an application specific daemon residing on an intranet server.

14. An apparatus according to claim 9 , wherein the application proxy is an application specific daemon residing on an intranet server, and is configured to access another service provided by another intranet server.

15. An apparatus according to claim 9 , wherein the first encryption key and the second encryption key are associated with a public key encryption scheme.

16. An apparatus according to claim 9 , wherein the secure session includes a session cookie corresponding to the browser application.

17. A system comprising:

a web server cluster configured to communicate with a browser application; and

a dispatcher configured to establish a secure session with the web server cluster, wherein the dispatcher is further configured to receive a message over the secure session from the browser application via the web server cluster, the message being encrypted using a first encryption key,

wherein the dispatcher is further configured to decrypt the received message to determine a user identifier associated with the browser application, to verify that the user identifier associated with the browser application is entitled to access a communication service, to reencrypt the message using a second encryption key, and to selectively forward the reencrypted message to an application proxy corresponding to the communication service based on the verification of the user identifier.

18. A system according to claim 17 , wherein the web server is part of a web server cluster, the system further comprising:

a firewall coupled to the web server cluster and the dispatcher, wherein the message is received from the web server cluster through the firewall.

19. A system according to claim 18 , further comprising:

another firewall coupled to the web server cluster and a public data network, wherein the browser application communicates with the web server cluster over the public data network through the other firewall.

20. A system according to claim 17 , wherein the application proxy is an application specific daemon, the system further comprising:

an intranet server configured to execute the application specific daemon.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 032734 FRAME: 0502. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: VERIZON BUSINESS GLOBAL LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 044626/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2014
From: VERIZON COMMUNICATIONS, INC.
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 032830/0797 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2014
From: VERIZON BUSINESS GLOBAL LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 032734/0502 →
CHANGE OF NAME Recorded Apr 8, 2014
From: MCI WORLDCOM, INC.
To: WORLDCOM, INC.
Reel/Frame 032632/0055 →
MERGER Recorded Apr 8, 2014
From: WORLDCOM, INC.
To: MCI, INC.
Reel/Frame 032632/0446 →
MERGER Recorded Apr 8, 2014
From: MCI, INC.
To: MCI, LLC
Reel/Frame 032632/0244 →
CHANGE OF NAME Recorded Apr 8, 2014
From: MCI, LLC
To: VERIZON BUSINESS GLOBAL LLC
Reel/Frame 032632/0404 →