IP Library Granted Patent US 9,792,426
Granted Patent B1
US 9,792,426 · App. 14/169,103 · Granted Oct 17, 2017

System and method for providing anonymous access to shared resources

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,792,426
App. No.
14/169,103
Granted
Oct 17, 2017
Kind
B1
Abstract

In one embodiment, a method is performed on a shared-resources system. The method includes creating an anonymous target. The method further includes assigning shared resources to the anonymous target. In addition, the method includes receiving a request for anonymous access from an anonymous user of a client system. The method also includes, responsive to the request, performing the following: generating anonymous-user credentials for the anonymous user; determining the shared resources assigned to the anonymous target; based, at least in part, on the determining, communicating a list of authorized resources to the client system; receiving a request from the client system to access a target resource from the list of authorized resources; and causing an anonymous-user account to be created on the target resource using the anonymous-user credentials.

Claims (60)

1. A method comprising, on a broker server comprising a computer processor and memory, wherein the broker server provides single sign-on (SSO) access to shared resources:

creating an anonymous target that generically represents anonymous users;

assigning at least a portion of the shared resources to the anonymous target;

receiving a request for anonymous access from a client system of an anonymous user, wherein the request for anonymous access excludes credentials;

responsive to the request for anonymous access:

generating, by the broker server, single-session anonymous-user credentials for the anonymous user, wherein the single-session anonymous-user credentials are not presented to or provided by the anonymous user;

determining the shared resources assigned to the anonymous target;

communicating at least a portion of the determined shared resources to the client system as authorized anonymous-access resources;

responsive to the communicating, receiving a request from the client system to access a target resource of the authorized anonymous-access resources;

responsive to the request to access the target resource, causing an anonymous-user account to be created on the target resource using the single-session anonymous-user credentials; and

allowing the client system anonymous SSO access to the target resource via the anonymous-user account and without the client system providing credentials to the broker server.

2. The method of claim 1 , wherein the assigning comprises assigning virtual desktops and related resources to the anonymous target.

3. The method of claim 2 , wherein the related resources are selected from the group consisting of: applications, mapped drives, mapped printers, user-profile settings, environment variables, application shortcuts, connection policies, desktop background bitmap, login settings, and host restrictions.

4. The method of claim 2 , wherein:

the related resources comprise at least one application; and

the at least one application authenticates the anonymous user in a non-anonymous fashion as the anonymous user accesses the at least one application.

5. The method of claim 1 , wherein the generating of the single-session anonymous-user credentials comprises randomly generating a user name and a password.

6. The method of claim 1 , comprising, prior to the generating, returning a session cookie to the client system, the session cookie comprising a random identifier mapped to the request for anonymous access.

7. The method of claim 1 , wherein the determining comprises querying a data store for the shared resources assigned to the anonymous target.

8. The method of claim 1 , wherein the causing comprises sending a message to the target resource, the message comprising an instruction to add the anonymous-user account to a resource group for the target resource.

9. The method of claim 1 , comprising, upon logout by the anonymous user from the target resource, destroying the anonymous-user account.

10. The method of claim 9 , wherein the destroying comprises:

removing the anonymous-user account from a resource group for the target resource;

deleting a user profile associated with the anonymous-user account; and

deleting any user data created within the anonymous user's session.

11. The method of claim 1 , comprising enabling anonymous access on the broker server.

12. The method of claim 1 , comprising authenticating the single-session anonymous-user credentials on the target resource.

13. The method of claim 1 , comprising authenticating the single-session anonymous-user credentials on the client system.

14. An information handling system comprising a computer processor, wherein the computer processor is operable to implement a method, the method comprising:

creating an anonymous target that generically represents anonymous users;

assigning shared resources to the anonymous target;

receiving a request for anonymous access from a client system of an anonymous user, wherein the request for anonymous access excludes credentials;

responsive to the request for anonymous access:

generating, by the information handling system, single-session anonymous-user credentials for the anonymous user, wherein the single-session anonymous-user credentials are not presented to or provided by the anonymous user;

determining the shared resources assigned to the anonymous target;

communicating at least a portion of the determined shared resources to the client system as authorized anonymous-access resources;

responsive to the communicating, receiving a request from the client system to access a target resource of the authorized anonymous-access resources;

causing an anonymous-user account to be created on the target resource using the single-session anonymous-user credentials; and

allowing the client system anonymous single sign-on access to the target resource via the anonymous-user account and without the client system providing credentials to the information handling system.

15. The information handling system of claim 14 , wherein the assigning comprises assigning virtual desktops and related resources to the anonymous target.

16. The information handling system of claim 15 , wherein:

the related resources comprise at least one application; and

the at least one application authenticates the anonymous user in a non-anonymous fashion as the anonymous user accesses the at least one application.

17. The information handling system of claim 14 , wherein the causing comprises sending a message to the target resource, the message comprising an instruction to add the anonymous-user account to a resource group for the target resource.

18. The information handling system of claim 14 , comprising, upon logout by the anonymous user from the target resource, destroying the anonymous-user account.

19. The information handling system of claim 18 , wherein the destroying comprises:

removing the anonymous-user account from a resource group for the target resource;

deleting a user profile associated with the anonymous-user account; and

deleting any user data created within the anonymous user's session.

20. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

creating an anonymous target that generically represents anonymous users;

assigning at least a portion of the shared resources to the anonymous target;

receiving a request for anonymous access from a client system of an anonymous user, wherein the request for anonymous access excludes credentials;

responsive to the request for anonymous access:

generating, by a broker server that provides single sign-on (SSO) access to shared resources, single-session anonymous-user credentials for the anonymous user, wherein the single-session anonymous-user credentials are not presented to or provided by the anonymous user;

determining the shared resources assigned to the anonymous target;

communicating at least a portion of the determined shared resources to the client system as authorized anonymous-access resources;

responsive to the communicating, receiving a request from the client system to access a target resource of the authorized anonymous-access resources;

responsive to the request to access the target resource, causing an anonymous-user account to be created on the target resource using the single-session anonymous-user credentials; and

allowing the client system anonymous SSO access to the target resource via the anonymous-user account and without the client system providing credentials to the broker server.

Assignments (16)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL USA L.P.; ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2018
From: DELL SOFTWARE INC.
To: DELL PRODUCTS L.P.
Reel/Frame 044947/0749 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 032810 FRAME 0206 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040027/0204 →
RELEASE OF SECURITY INTEREST OF REEL 032809 FRAME 0930 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040045/0255 →
RELEASE OF REEL 032809 FRAME 0887 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; CREDANT TECHNOLOGIES, INC.; COMPELLENT TECHNOLOGIES, INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
Reel/Frame 040017/0314 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 032810/0206 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 032809/0930 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 1, 2014
From: COMPELLENT TECHNOLOGIES, INC.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; SECUREWORKS, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032809/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2014
From: DRISCOLL, ADAM ROBERT; ZAPF, MARC EDWARD
To: DELL SOFTWARE INC.
Reel/Frame 032312/0586 →