IP Library Granted Patent US 8,474,009
Granted Patent B2
US 8,474,009 · App. 12/787,727 · Granted Jun 25, 2013

Dynamic service access

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,474,009
App. No.
12/787,727
Granted
Jun 25, 2013
Kind
B2
Abstract

Apparatus, systems, and methods may operate to authenticate a desktop client to an identity service (IS), to receive a request, from an application, at the IS via the desktop client for a virtual service internet protocol (IP) address associated with a service. The IS may operate to build a routing token that includes an original physical IP address associated with the service when a policy associated with the IS permits access to the service by a user identity associated with the desktop client. After the routing token is validated, the application may be connected to the service via the desktop client. The application may comprise an e-mail application or a remote control application, such as a virtual network computing (VNC) application. Additional apparatus, systems, and methods are disclosed.

Claims (57)

1. An apparatus, comprising:

a node comprising an identity service (IS) arranged to:

receive a request from an application, via an authenticated desktop client, for a virtual service internet protocol (IP) address associated with a service, wherein the virtual service IP is intercepted by the apparatus and not sent on to a network containing the application;

build a routing token that includes an original physical IP address associated with the service when a policy associated with the IS permits access to the service by a user identity associated with the authenticated desktop client; and

transmit the routing token to a validation node so that the application can be connected using an original connection to the service via the authenticated desktop client after the validation node has validated the routing token.

2. The apparatus of claim 1 , further comprising:

a workload management system to detect changes to the original physical address and to start the service if the service is unavailable, in response to the request.

3. The apparatus of claim 1 , further comprising:

a storage node to store the policy, the storage node coupled to the node via a network.

4. A system, comprising:

a first node comprising an identity service (IS) arranged to:

receive a request from an application, via an authenticated desktop client, for a virtual service internet protocol (IP) address associated with a service, wherein the virtual service IP is intercepted by the apparatus and not sent on to a network containing the application;

build a routing token that includes an original physical IP address associated with the service when a policy associated with the IS permits access to the service by a user identity associated with the authenticated desktop client; and

transmit the routing token to a validation node so that the application can be connected using an original connection to the service via the authenticated desktop client after the validation node has validated the routing token; and

a second node to host the service.

5. The system of claim 4 , further comprising.

a third node to host the desktop client.

6. The system of claim 5 , wherein the third node includes a secure sockets layer virtual private network (SSL-VPN) module coupled to the application.

7. A processor-implemented, method to execute on one or more processors that perform the method, comprising:

authenticating a desktop client to an identity service (IS);

receiving a request, from an application, at the IS via the desktop client, for a virtual service internet protocol (IP) address associated with a service, the receiving including intercepting the virtual service IP and not sending the virtual IP on to a network containing the application;

building a routing token, by the IS, to include an original physical IP address associated with the service when a policy associated with the IS permits access to the service by a user identity associated with the desktop client; and

after validating the routing token, connecting the application using an original connection to the service via the desktop client.

8. The method of claim 7 , further comprising:

detecting an error associated with accessing the service in the original connection;

requesting, by the desktop client, a new physical address associated ith the service;

receiving the new physical address at the desktop client; and

making a new connection from the application to the service at the new physical address via the desktop client.

9. The method of claim 7 , further comprising:

receiving, by the IS, an indication that the original physical address associated with the service has been changed to a new physical address; and

transmitting, from the IS, the new physical address to the desktop client.

10. The method of claim 9 , wherein the receiving comprises:

receiving the indication from a workload management system.

11. The method of claim 9 , wherein the transmitting further comprises:

transmitting the new physical address to a secure sockets layer virtual private network (SSL-VPN) module forming part of the desktop client.

12. The method of claim 7 , further comprising:

transmitting the routing token via a secure network connection to a node hosting the service.

13. The method of claim 7 , further comprising:

validating the routing token by a node hosting the service.

14. A processor-implemented method to execute on one or more processors that perform the method, comprising:

authenticating a desktop client to an identity service (IS);

receiving a request, from one of an e-mail application or a remote control application, at the IS via the desktop client, for a virtual service internet protocol (IP) address associated with a service, the receiving including intercepting the virtual service IP and not sending the virtual IP on to a network containing the application;

building a routing token, by the IS, to include an original physical IP address associated with the service when a policy associated with the IS permits access to the service by a user identity associated with the desktop client; and

after validating the routing token, connecting the one of the e-mail application or the remote control application using an original connection to the service via the desktop client.

15. The method of claim 14 , further comprising:

receiving the virtual service IP address and a port as an address-port pair at the desktop client in response to the request.

16. The method of claim 14 , further comprising:

detecting an error due to the service not being available; and

starting the service.

17. The method of claim 16 , wherein the starting comprises:

starting the service using a workload management system.

18. The method of claim 14 , wherein the validating comprises:

validating the routing token at a secure sockets layer virtual private network (SSL-VPN) server.

19. The method of claim 18 , wherein the connecting comprises:

connecting the service to the one of the e-mail application or the remote control application via the SSL-VPN server.

20. The method of claim 14 , wherein the connecting comprises:

connecting the service as an e-mail service on an e-mail server to the e-mail application without using an SSL-VPN server.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2010
From: BURCH, LLOYD LEON; MUKKARA, PRAKASH UMASANKAR; EARL, DOUGLAS GARRY
To: NOVELL, INC.
Reel/Frame 024450/0196 →