IP Library Granted Patent US 8,856,887
Granted Patent B2
US 8,856,887 · App. 13/544,565 · Granted Oct 7, 2014

Methods and apparatus for delegated authentication token retrieval

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,856,887
App. No.
13/544,565
Granted
Oct 7, 2014
Kind
B2
Abstract

In some embodiments, a non-transitory processor-readable medium includes code to cause a processor to send, from an authorization client on a device to a client authorization module, an indication of multiple applications installed on the device, and receive, at the authorization client and in response to the indication, multiple application tokens from the client authorization module. Each individual application token from the multiple application tokens received by the authorization client is uniquely associated with an application from the multiple applications installed on the device. The authorization client provides each application its associated application token such that each application from the multiple applications can use that application token in order to be authenticated to an application server associated with the application.

Claims (39)

1. A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:

send, at a first time, from an authorization client on a device to a client authorization module, an indication of a plurality of applications installed on the device, subsequent to intercepting a request to launch at least one application from the plurality of applications such that the application is prevented from receiving the indication;

receive, at a second time after the first time, at the authorization client and in response to the indication, a plurality of application tokens from the client authorization module, each application token from the plurality of application tokens being uniquely associated with an application from the plurality of applications; and

provide, using the authorization client, each application from the plurality of applications its associated application token from the plurality of application tokens such that each application from the plurality of applications is authenticated to an application server associated with that application from the plurality of applications when its associated application token is received at the application server.

2. The non-transitory processor-readable medium of claim 1 , wherein the code to cause the processor to send includes code to cause the processor to:

send, from the authorization client to the client authorization module, an identifier associated with an access level of a user associated with the device, the plurality of applications being associated with the access level.

3. The non-transitory processor-readable medium of claim 1 , further comprising code to cause the processor to:

determine, prior to sending the indication, an identifier associated with each application from the plurality of applications installed on the device.

4. The non-transitory processor-readable medium of claim 1 , wherein the authorization client is a native application installed on the device.

5. The non-transitory processor-readable medium of claim 1 , wherein a first application from the plurality of applications is an enterprise application, a second application from the plurality of applications is a Software as a Service (SaaS) application.

6. The non-transitory processor-readable medium of claim 1 , wherein the plurality of applications is a first plurality of applications installed on the device, the indication being an indication of the first plurality of applications and a second plurality of applications installed on the device, the code further comprising code to cause the processor to:

receive an indication that a user associated with the device is unauthorized to use each application from the second plurality of applications.

7. An apparatus, comprising:

an authorization client installed on a device associated with a user, the authorization client configured to send, at a first time, to a client authorization module, an application token request associated with a plurality of applications installed on the device, subsequent to intercepting a request to launch an application from the plurality of applications such that the application is prevented from receiving the indication, the authorization client configured to receive, at a second time after the first time, in response to the application token request, (1) a set of application tokens associated with a first set of applications from the plurality of applications, and (2) an indication that the user associated with the device is unauthorized to use each application from a second set of applications from the plurality of applications and mutually exclusive of the first set of applications, each application token from the set of application tokens being uniquely associated with an application from the first set of applications,

the authorization client configured to provide each application from the first set of applications with its associated application token from the set of application tokens such that each application from the first set of applications is authenticated to an application server associated with that application when its associated application token is received at the application server.

8. The apparatus of claim 7 , wherein the authorization client is configured to send an identifier associated with the user to the client authorization module, the authorization client configured to receive, in response to the identifier, a user authorization token, the authorization client configured to provide the user authorization token to the client authorization module with the client token request.

9. The apparatus of claim 7 , wherein the application server is at least one of a Software as a Service (SaaS) host or an enterprise host.

10. The apparatus of claim 7 , wherein the authorization client is configured to retrieve, prior to sending the application token request, a plurality of identifiers, each identifier from the plurality of identifiers being uniquely associated with an application from the plurality of applications installed on the device, the application token request being based at least in part on the plurality of identifiers.

11. The apparatus of claim 7 , wherein each token from the set of application tokens is an OAuth access token.

12. An apparatus, comprising:

a client authorization module configured to receive, at a first time, from an authorization client at a client device, subsequent to the authorization client intercepting a request to launch at least one application from a plurality of applications installed on the client device such that the at least one application is prevented from receiving the indication, an application token request associated with the plurality of applications, the client authorization module configured to send, at a second time after the first time, in response to the application token request, a plurality of tokens to the authorization client such that the authorization client provides each application from the plurality of applications with a uniquely associated token from the plurality of tokens,

the client authorization module configured to receive an authentication request from an application module associated with an application from the plurality of applications, the authentication request including a token from the plurality of tokens and uniquely associated with that application, the client authorization module configured to send an authentication signal to the application module in response to the client authorization module verifying the token as a valid token for the application.

13. The apparatus of claim 12 , wherein the client authorization module is configured to receive an identifier associated with a user of the client device, the client authorization module configured to send, in response to the identifier, a user authorization token associated with an access right of the user.

14. The apparatus of claim 12 , wherein the client authorization module and the application module are included in an enterprise server.

15. The apparatus of claim 12 , wherein the client authorization module is hosted at a first host device, the application module is hosted at a second host device different from the first host device.

16. A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:

intercept, at an authorization client on a device and at a first time, an indication that a user associated with the device has requested to launch an application installed on the device such that the application is prevented from receiving the indication;

send at a second time after the first time, from the authorization client to a client authorization module and in response to the indication, a request for an application token for the application;

receive, at the authorization client and in response to the request, the application token from the client authorization module;

associate, using the authorization client, the application token with the application at the device; and

send, using the authorization client and after associating the application token with the application, the indication to the application such that the application launches with the application token and in response to the indication.

17. The non-transitory processor-readable medium of claim 16 , wherein the code to cause the processor to send the request includes code to cause the processor to:

send, from the authorization client to the client authorization module, an identifier associated with an access level of the user, the application being approved for the access level.

18. The non-transitory processor-readable medium of claim 16 , wherein the authorization client is a native application installed on the device.

19. The non-transitory processor-readable medium of claim 16 , wherein the code to cause the processor to associate includes code to cause the processor to associate the application token with the application such that the application is authenticated to at least one of a Software as a Service (SaaS) host associated with the application or an enterprise host associated with the application based on the application token after launching the application.

20. The non-transitory processor-readable medium of 16 , wherein the indication is a first indication, the code to cause the processor to associate includes code to cause the processor to associate at a third time, the code further comprising code to cause the processor to:

intercept, at the authorization client and at a fourth time after the third time, a second indication that the user associated with the device has requested to launch the application;

determine that the application token is associated with the application at the device; and

send the second indication to the application such that the application launches with the application token in response to the second indication.

Assignments (12)
RELEASE OF SECURITY INTEREST AT R/F 61703/0988 Recorded Nov 14, 2025
From: BLUE OWL CAPITAL CORPORATION
To: PING IDENTITY CORPORATION
Reel/Frame 073570/0777 →
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
RELEASE OF SECURITY INTEREST Recorded Oct 19, 2022
From: BANK OF AMERICA, N.A.
To: PING IDENTITY CORPORATION
Reel/Frame 061709/0527 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Oct 18, 2022
From: PING IDENTITY CORPORATION
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 061703/0988 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2021
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: PING IDENTITY CORPORATION
Reel/Frame 058195/0557 →
SECURITY INTEREST Recorded Nov 23, 2021
From: PING IDENTITY CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 058944/0687 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL/FRAME NO. 44725/0443 Recorded Dec 12, 2019
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: PING IDENTITY CORPORATION
Reel/Frame 051265/0873 →
PATENT SECURITY AGREEMENT Recorded Dec 12, 2019
From: PING IDENTITY CORPORATION
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 051271/0247 →
SECURITY INTEREST Recorded Jan 25, 2018
From: PING IDENTITY CORPORATION
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 044725/0443 →
RELEASE OF SECURITY INTEREST Recorded Jan 25, 2018
From: GUGGENHEIM CORPORATE FUNDING, LLC
To: PING IDENTITY CORPORATION
Reel/Frame 044729/0597 →
SECURITY INTEREST Recorded Jun 30, 2016
From: PING IDENTITY CORPORATION
To: GUGGENHEIM CORPORATE FUNDING, LLC
Reel/Frame 039055/0274 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2012
From: FIELD-ELIOT, BRYAN; NARAHARI, SATEESH; MADSEN, PAUL
To: PING IDENTITY CORPORATION
Reel/Frame 028708/0185 →