IP Library Granted Patent US 9,552,444
Granted Patent B2
US 9,552,444 · App. 13/898,242 · Granted Jan 24, 2017

Identification verification mechanisms for a third-party application to access content in a cloud-based platform

Inventors: Michael Smith (Palo Alto, CA); Benjamin Campbell Smith (Mountain View, CA); Simon Tan (Daly City, CA); Rico Yao (San Jose, CA)
Assignee: Box, Inc.
G06F17/30997G06F17/301H04L63/0428H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,552,444
App. No.
13/898,242
Granted
Jan 24, 2017
Kind
B2
Abstract

Techniques are disclosed for using a third-party application to access or edit a file within a cloud-based environment within a cloud-based platform or environment. In one embodiment, a method includes, in response to a request to access the content in the cloud-based environment, providing the third-party application with a login view to verify an identity of a user. The login view is generated from a server hosting the environment. The method further includes, upon the verification of the user's identity, providing the requested content to the third-party application.

Claims (37)

1. A method for providing a third-party application with access to encrypted content in a cloud-based environment, the method comprising:

in response to a request to access the encrypted content of a workspace in the cloud-based environment, providing the third-party application with an identity verification of a user if the user is not already logged into the workspace, wherein the identity verification is generated from a server hosting the cloud-based environment;

upon the verification of the user's identity, transmitting an authentication token to the third-party application, the authentication token allowing the third-party application to access the encrypted content of the workspace in the cloud-based environment without verifying the user's identity, wherein the authentication token includes a decryption key to decrypt the encrypted content;

providing the requested encrypted content to the third-party application;

decrypting the encrypted content with the decryption key included with the authentication token; and

in response to receiving a request to store content in the workspace from the third-party application, preventing the third-party application from storing the content, wherein the content is exclusive of the requested encrypted content.

2. The method of claim 1 , wherein the providing is performed based on whether the user is logged into the cloud-based environment.

3. The method of claim 1 , wherein the identity verification is not generated again by the server if, upon receiving a subsequent request to access the cloud-based environment, the authentication token is present on the third-party application.

4. The method of claim 1 , wherein the authentication token automatically expires after a period of time.

5. The method of claim 1 , wherein the provided identity verification is embedded in an interface of the third-party application.

6. The method of claim 1 , wherein the request is transmitted from the third-party application.

7. The method of claim 1 , wherein the third-party application has a user interface customized to enable the storage of the accessed content back to the cloud-based environment.

8. The method of claim 1 , wherein the third-party application is listed in a list of approved third-party applications.

9. The method of claim 1 , further comprising:

keeping a history of the access, the history including at least information regarding which third-party application accessed what content.

10. A system for providing a third-party application to access to encrypted content in a cloud-based environment, the system comprising:

one or more processors;

memory circuitry coupled to the processors and having stored thereon instructions which, when executed by at least one of the processors, causes the system to:

in response to a request to access the encrypted content of a workspace in the cloud-based environment, provide the third-party application with an identity verification of a user based on whether the user is logged into the workspace in the cloud-based environment, wherein the identity verification is generated from a server hosting the cloud-based environment;

upon the verification of the user's identity, transmit an authentication token to the third-party application, the authentication token allowing the third-party application to access the encrypted content of the workspace in the cloud-based environment without verifying the user's identity, wherein the authentication token includes a decryption key to decrypt the encrypted content;

provide the requested encrypted content to the third-party application;

decrypt the encrypted content with the decryption key included with the authentication token; and

in response to receiving a request to store content in the workspace from the third-party application, prevent the third-party application from storing the content, wherein the content is exclusive of the requested encrypted content.

11. The method of claim 1 , further comprising instructing a deletion of the content provided to the third-party application.

12. The method of claim 1 , further comprising restricting the third-party application from storing the content back to the cloud-based environment.

13. A non-transitory machine readable storage medium encoded with instructions for performing a method for providing a third-party application with access to encrypted content in a cloud-based environment, the instructions comprising:

in response to a request to access the encrypted content of a workspace in the cloud-based environment, provide the third-party application with an identity verification of a user if the user is not already logged into the workspace, wherein the identity verification is generated from a server hosting the cloud-based environment;

upon the verification of the user's identity, transmit an authentication token to the third-party application, the authentication token allowing the third-party application to access the encrypted content of the workspace in the cloud-based environment without verifying the user's identity, wherein the authentication token includes a decryption key to decrypt the encrypted content;

provide the requested encrypted content to the third-party application;

decrypt the encrypted content with the decryption key included with the authentication token; and

in response to receiving a request to store content in the workspace from the third-party application, prevent the third-party application from storing the content, wherein the content is exclusive of the requested encrypted content.

14. The non-transitory machine readable storage medium of claim 13 , wherein the instructions to provide are performed based on whether the user is logged into the cloud-based environment.

15. The non-transitory machine readable storage medium of claim 13 , wherein the identity verification is not generated again by the server if, upon receiving a subsequent request to access the cloud-based environment, the authentication token is present on the third-party application.

16. The non-transitory machine readable storage medium of claim 13 , wherein the authentication token automatically expires after a period of time.

17. The non-transitory machine readable storage medium of claim 13 , wherein the provided identity verification is embedded in an interface of the third-party application.

18. The non-transitory machine readable storage medium of claim 13 , wherein the request is transmitted from the third-party application.

19. The non-transitory machine readable storage medium of claim 13 , wherein the third-party application has a user interface customized to enable the storage of the accessed content back to the cloud-based environment.

Assignments (4)
SECURITY INTEREST Recorded Jul 26, 2023
From: BOX, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 064389/0686 →
RELEASE OF SECURITY INTEREST Recorded Dec 8, 2015
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: BOX, INC.
Reel/Frame 037237/0503 →
PATENT SECURITY AGREEMENT Recorded Aug 27, 2013
From: BOX, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 031368/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2013
From: SMITH, MICHAEL KOLLIN; SMITH, BENJAMIN CAMPBELL; TAN, SIMON; YAO, RICO
To: BOX, INC.
Reel/Frame 030581/0453 →
Continuity (3)
Provisional Application 61650840 · May 23, 2012
Provisional Application 61653876 · May 31, 2012
Related Publication 20130318586A1 · Nov 28, 2013