IP Library Granted Patent US 8,707,412
Granted Patent B2
US 8,707,412 · App. 13/335,592 · Granted Apr 22, 2014

Application identity design

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,707,412
App. No.
13/335,592
Granted
Apr 22, 2014
Kind
B2
Abstract

Methods and apparatus, including computer program products, implementing and using techniques for providing user credentials over a network to a remote computer application. User credentials for the remote computer application are stored in a central repository that is accessible through the network. A request is sent to a service to perform, on behalf of a user, a particular task involving the remote computer application. It is determined whether the service has been granted permission to act on behalf of the user with respect to the remote computer application. When the service has permission to act on behalf of the user, the service is used to retrieve the user's credentials for the remote computer application from the central repository and to supply the retrieved user credentials to the remote computer application.

Claims (44)

1. An interoperability network configured to assist a first service acting on behalf of a first user to obtain authorized access to and task performance by a second service, wherein the first and second service operate on service-associated machines, are separate from each other, and are coupled in communication with the interoperability network, the interoperability network comprising one or more computing devices configured to:

receive a request for the first service to perform a particular task, fulfillment of which requires authorized access to and task performance by the second service;

determine that the first service is authorized to act on behalf of the first user in obtaining authorized access to and task performance by the second service;

retrieve from an electronic storage repository, which stores a plurality of sets of credentials usable by the first user and by a plurality of other users, access information that enables the first user to obtain authorized access to and task performance by the second service; and

provide at least part of the access information to the second service to obtain authorized access to and task performance by the second service.

2. The interoperability network of claim 1 , wherein each of the plurality of sets of credentials defines access information that enables a corresponding user to obtain authorized access to and task performance by a corresponding service.

3. The interoperability network of claim 1 , wherein each of the plurality of sets of credentials is of a type that is specified by a respective service, and at least two of the plurality of sets of credentials correspond to different authentication protocols.

4. The interoperability network of claim 1 , wherein verifying that the first service is authorized to act on behalf of the first user with respect to the second service comprises:

retrieving a first policy from a plurality of policies stored on one or more storage media, the first policy defining first conditions under which the first service is enabled to act on behalf of the first user with respect to the second service; and

determining that the particular task complies with the first policy.

5. The interoperability network of claim 4 , wherein:

the first policy further defines one or more or more security requirements governing use of a first set of credentials that includes the access information, and

providing the access information from the first set of credentials to the second service comprises transmitting the access information in compliance with the security requirements defined by the first policy.

6. The interoperability network of claim 1 , wherein the access information specifies a message translation required for access to the second service and the computing devices are configured to translate the request by applying the message translation prior to providing the at least part of the access information to the second service.

7. The interoperability network of claim 1 , wherein each of the credentials specify permissions for one or more services to read and use the access information.

8. The interoperability network of claim 1 , wherein the first user is either an individual user or an organization representing one or more users.

9. A method of facilitating, via an interoperability network, authorized access to and task performance by a second service for a first service acting on behalf of a first user, wherein the first and second service operate on service-associated machines, are separate from each other, and are coupled in communication with the interoperability network, the interoperability network the method comprising:

receiving a request for the first service to perform a particular task, fulfillment of which requires authorized access to and task performance by the second service;

determining that the first service is authorized to act on behalf of the first user in obtaining authorized access to and task performance by the second service;

retrieving from an electronic storage repository, which stores a plurality of sets of credentials usable by the first user and by a plurality of other users, access information that enables the first user to obtain authorized access to and task performance by the second service; and

providing at least part of the access information to the second service to obtain authorized access to and task performance by the second service.

10. The method of claim 9 , wherein each of the plurality of sets of credentials defines access information that enables a corresponding user to obtain authorized access to and task performance by a corresponding service.

11. The method of claim 9 , wherein verifying that the first service is authorized to act on behalf of the first user with respect to the second service comprises:

retrieving a first policy from a plurality of policies stored on one or more storage media, the first policy defining first conditions under which the first service is enabled to act on behalf of the first user with respect to the second service; and

determining that the particular task complies with the first policy.

12. The method of claim 11 , wherein:

the first policy further defines one or more or more security requirements governing use of a first set of credentials that includes the access information, and

providing the access information from the first set of credentials to the second service comprises transmitting the access information in compliance with the security requirements defined by the first policy.

13. The method of claim 9 , wherein the access information specifies a message translation required for access to the second service and the computing devices are configured to translate the request by applying the message translation prior to providing the at least part of the access information to the second service.

14. The method of claim 9 , wherein each of the credentials specify permissions for one or more services to read and use the access information.

15. The method of claim 9 , wherein the first user is either an individual user or an organization representing one or more users.

16. A non-transitory computer readable storage medium storing instructions for facilitating, via an interoperability network, authorized access to and task performance by a second service for a first service acting on behalf of a first user, wherein the first and second service operate on service-associated machines, are separate from each other, and are coupled in communication with the interoperability network, the instructions comprising:

first instructions to receive a request for the first service to perform a particular task, fulfillment of which requires authorized access to and task performance by the second service;

second instructions to determine that the first service is authorized to act on behalf of the first user in obtaining authorized access to and task performance by the second service;

third instructions to retrieve from an electronic storage repository, which stores a plurality of sets of credentials usable by the first user and by a plurality of other users, access information that enables the first user to obtain authorized access to and task performance by the second service; and

fourth instructions to provide at least part of the access information to the second service to obtain authorized access to and task performance by the second service.

17. The computer readable medium of claim 16 , wherein each of the plurality of sets of credentials defines access information that enables a corresponding user to obtain authorized access to and task performance by a corresponding service.

18. The computer readable medium of claim 16 , wherein verifying that the first service is authorized to act on behalf of the first user with respect to the second service comprises:

retrieving a first policy from a plurality of policies stored on one or more storage media, the first policy defining first conditions under which the first service is enabled to act on behalf of the first user with respect to the second service; and

determining that the particular task complies with the first policy.

19. The computer readable medium of claim 18 , wherein:

the first policy further defines one or more or more security requirements governing use of a first set of credentials that includes the access information, and

providing the access information from the first set of credentials to the second service comprises transmitting the access information in compliance with the security requirements defined by the first policy.

20. The computer readable medium of claim 16 , wherein the access information specifies a message translation required for access to the second service and the computing devices are configured to translate the request by applying the message translation prior to providing the at least part of the access information to the second service.