IP Library Granted Patent US 10,798,057
Granted Patent B2
US 10,798,057 · App. 13/765,616 · Granted Oct 6, 2020

Method and apparatus for providing secure internal directory service for hosted services

Inventors: Paul Moore (Mercer Island, WA); Nathaniel Wayne Yocom (North Bend, WA)
Assignee: CENTRIFY CORPORATION
H04L63/02H04L61/15H04L61/6013H04L63/0281H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,798,057
App. No.
13/765,616
Granted
Oct 6, 2020
Kind
B2
Abstract

A system and method for providing secure access to an organization's internal directory service from external hosted services. The system includes a remote directory service configured to accept directory service queries from an application running on hosted services. The remote directory service passes the queries to a directory service proxy server inside a firewall of the organization via a secure rendezvous service. The directory service proxy server passes the queries to the internal directory service inside said firewall. Request responses from the internal directory service pass through the directory service proxy server to the remote directory service through said firewall via the secure rendezvous service. The remote directory servicer returns the response to the requesting application.

Claims (13)

1. A method for providing secure access to an organization's internal directory service from external hosted services comprising:

a) accepting directory service queries from a remote directory service interface for internal directory services from an application running on said hosted services, wherein said queries are for directory services which are offered by said internal directory service and said internal directory services are provided within a firewall of said organization, and wherein said accepting includes a validation protocol from said application, said validation protocol provided by said directory service proxy server;

b) passing said queries to a directory service proxy server inside said firewall of said organization via a secure connection service, wherein said directory service proxy server communicates directly with said internal directory service to obtain query responses to said passed queries from said internal directory service; and

c) returning said query responses from the directory service proxy server via said secure connection service and said remote directory service interface to said application, wherein said accepting, passing and returning enable said application to interact with said internal directory services through said secure connection service and said remote directory service interface.

2. The method defined by claim 1 wherein there are a plurality of said directory service proxy servers, said method further comprising assigning a directory service proxy identifier to each of said directory service proxy servers, and determining to which directory service proxy server queries should go based on said directory service proxy identifier.

3. The method defined by claim 1 wherein said directory service queries include at least user authentication queries and user permission queries.

4. The method defined by claim 1 wherein said directory service queries are limited to a non-destructive subset of directory service queries.

5. The method defined by claim 1 wherein said validation protocol comprises a security certificate and key from said application, said security certificate and key provided by said directory service proxy server.

6. A method for providing secure access to an organization's internal directory service from external hosted services comprising:

a) a directory service proxy server accepting requests originating from an application from a remote directory service interface through an organization's firewall via a secure connection service, wherein said requests are for directory services which are offered by said internal directory service within said organization's firewall, and wherein said accepting includes a validation protocol from said application, said validation protocol provided by said directory service proxy server;

b) said directory service proxy server communicating directly with said internal directory service to obtain responses to said requests from said internal directory service and passing said requests to said internal directory service; and

c) said directory service proxy server returning responses from said internal directory service to said requests to said remote directory service interface via said secure connection service, wherein said accepting, passing and returning enable said application to interact with said internal directory services through said secure connection service and said remote directory service interface.

7. The method defined by claim 6 wherein said validation protocol comprises sending a security certificate and key for said application to provide when requesting a directory service, and wherein said accepting refuses any directory service requests without said security certificate and key.

Assignments (10)
CHANGE OF NAME Recorded Apr 15, 2022
From: CENTRIFY CORPORATION
To: DELINEA INC.
Reel/Frame 059721/0804 →
RELEASE OF SECURITY INTEREST Recorded Mar 3, 2021
From: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
To: CENTRIFY CORPORATION
Reel/Frame 055476/0295 →
SECURITY INTEREST Recorded Mar 2, 2021
From: CENTRIFY CORPORATION
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 055456/0657 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2020
From: YOCOM, NATHANIEL WAYNE
To: CENTRIFY CORPORATION
Reel/Frame 053142/0755 →
RELEASE OF SECURITY INTEREST UNDER REEL/FRAME 46081/0609 Recorded Aug 17, 2018
From: GOLUB CAPITAL LLC
To: CENTRIFY CORPORATION
Reel/Frame 046854/0246 →
SECURITY INTEREST Recorded Aug 17, 2018
From: CENTRIFY CORPORATION
To: GOLUB CAPITAL LLC
Reel/Frame 046854/0210 →
RELEASE OF SECURITY INTEREST Recorded May 7, 2018
From: SILICON VALLEY BANK
To: CENTRIFY CORPORATION
Reel/Frame 045730/0364 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 5, 2018
From: CENTRIFY CORPORATION
To: GOLUB CAPITAL LLC, AS AGENT
Reel/Frame 046081/0609 →
SECURITY INTEREST Recorded Jan 27, 2017
From: CENTRIFY CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 041099/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2013
From: MOORE, PAUL
To: CENTRIFY CORPORATION
Reel/Frame 029800/0454 →