IP Library Granted Patent US 9,384,339
Granted Patent B2
US 9,384,339 · App. 13/736,557 · Granted Jul 5, 2016

Authenticating cloud computing enabling secure services

Inventors: John L. Griffin (Brookline, MA); Keith A. McFarland (Annapolis, MD); William P. Wells (Federal Way, WA)
Assignee: Telecommunication Systems, Inc.
G06F21/34G06F21/33G06F21/629H04L63/0807H04L63/0884G06F2221/2115H04L63/0815H04L63/0892
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,384,339
App. No.
13/736,557
Granted
Jul 5, 2016
Kind
B2
Abstract

Authenticating cloud computing enabling secure services (ACCESS) offloads “client authentication” activity onto a third-party authenticating cloud computing enabling secure services (ACCESS) node. Instead of having a client device authenticate itself directly to a network server, the client device instead authenticates itself to a third-party authenticating cloud computing enabling secure services (ACCESS) node. The authenticating cloud computing enabling secure services (ACCESS) node then provides credentials that are used by the client device to communicate directly with the server (and utilize the service) without any further authentication being necessary.

Claims (16)

1. A method of pre-authenticating a client device for direct access to a cloud-based secure service, comprising:

receiving a request for pre-authorization from a client device, at an access node separate from a cloud-based secure service server;

receiving credentials from said client device, at said access node separate from said cloud-based secure service server, said credentials comprising a registration message encrypted using a shared secret cryptographic key;

passing a pre-authorized authentication token together with a redirect to said client device, said pre-authorized authentication token for provision by said client device directly to said cloud-based secure service server without passage through said access node;

providing a push or pull notification, when authenticated, from said access node to said cloud-based secure service server, said notification identifying said client device;

receiving a request at said access node, from said cloud-based secure service server, to verify validity of said pre-authorized authentication token received by said cloud-based secure service server from said client device; and

receiving a request from said cloud-based secure service server for additional information regarding authentication of said client device to access a cloud-based secure service on said cloud-based secure service server;

whereby said client device directly provides its own authorization token directly to said cloud-based secure service server bypassing said access node to directly access said cloud-based secure service server.

2. Apparatus to pre-authenticate a client device for direct access to a cloud-based secure service, comprising:

means for receiving a request for pre-authorization from a client device, at an access node separate from a cloud-based secure service server;

means for receiving credentials from said client device, at said access node separate from said cloud-based secure service server, said means for receiving credentials receives a registration message encrypted using a shared secret cryptographic key;

means for passing a pre-authorized authentication token together with a redirect to said client device, said pre-authorized authentication token for provision by said client device directly to said cloud-based secure service server without passage through said access node;

means for providing a push or pull notification, when authenticated, from said access node to said cloud-based secure service server, said notification identifying said client device;

means for receiving a request at said access node, from said cloud-based secure service server, to verify validity of said pre-authorized authentication token received by said cloud-based secure service server from said client device; and

means for receiving a request from said cloud-based secure service server for additional information regarding authentication of said client device to access a cloud-based secure service on said cloud-based secure service server;

whereby said client device is enabled to directly provide its own authorization token directly to said cloud-based secure service server, bypassing said access node, to directly access said cloud-based secure service server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2013
From: GRIFFIN, JOHN L.; MCFARLAND, KEITH A.; WELLS, WILLIAM P.
To: TELECOMMUNICATION SYSTEMS, INC.
Reel/Frame 029627/0276 →
Continuity (2)
Provisional Application 61586467 · Jan 13, 2012
Related Publication 20130269020A1 · Oct 10, 2013