IP Library Granted Patent US 9,098,539
Granted Patent B2
US 9,098,539 · App. 14/335,774 · Granted Aug 4, 2015

System, method and computer program product for enabling access to a resource of a multi-tenant on-demand database service utilizing a token

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,098,539
App. No.
14/335,774
Granted
Aug 4, 2015
Kind
B2
Abstract

In accordance with embodiments, there are provided mechanisms and methods for enabling access to a resource of a multi-tenant on-demand database service utilizing a token. These mechanisms and methods for enabling access to a resource of a multi-tenant on-demand database service utilizing a token can be utilized to prevent identification of a user attempting to access the resource, and thus unwanted use of the user's identity.

Claims (43)

1. A method, comprising:

receiving, at a first domain of a first system, a first request from a device of a user to make a resource accessible;

in response to the first request, generating, by the first system, a token that includes a time-to-live;

storing, in memory of the first system, the token;

storing, in association with the token in the memory of the first system, an identifier of the user and information to be utilized for accessing the resource;

in response to the first request, sending by the first system to the device of the user the token and an instruction to transmit the token to a second domain of a second system;

in response to the second system receiving the token through the second domain from the device of the user:

performing a look-up of the token,

through the performance of the look-up, verifying that the token is stored and the token has not expired,

in response to the verifying, providing, to the second system, the information to be utilized for accessing the resource that is stored in association with the token, and

permitting access to the resource via the second domain, wherein the access is permitted through use by the second system of the information.

2. The method of claim 1 , wherein the first domain is of a multi-tenant on-demand database system.

3. The method of claim 1 , wherein the resource is an application.

4. The method of claim 1 , wherein the first request is received in association with a login by the user.

5. The method of claim 1 , wherein the token includes a randomly generated identifier.

6. The method of claim 5 , wherein generating the token includes generating the randomly generated identifier.

7. The method of claim 1 , wherein the token is associated with a one-time use policy.

8. The method of claim 7 , wherein verifying the token includes determining that the token has not previously been utilized for accessing the resource.

9. The method of claim 1 , wherein in response to the second domain receiving from the device of the user the second request to access the resource further comprising:

preventing access to the resource via the second domain when the token is not verified.

10. A computer program product, comprising a non-transitory computer usable medium having a computer readable program code embodied therein, the computer readable program code adapted to be executed to cause a computer to implement a method, the method comprising:

receiving, at a first domain of a first system, a first request from a device of a user to make a resource accessible;

in response to the first request, generating, by the first system, a token that includes a time-to-live;

storing, in memory of the first system, the token;

storing, in association with the token in the memory of the first system, an identifier of the user and information to be utilized for accessing the resource;

in response to the first request, sending by the first system to the device of the user the token and an instruction to transmit the token to a second domain of a second system;

in response to the second system receiving the token through the second domain from the device of the user:

performing a look-up of the token,

through the performance of the look-up, verifying that the token is stored and the token has not expired,

in response to the verifying, providing, to the second system, the information to be utilized for accessing the resource that is stored in association with the token, and

permitting access to the resource via the second domain, wherein the access is permitted through use by the second system of the information.

11. An apparatus, comprising:

a first processor of a first system for:

receiving, at a first domain of the first system, a first request from a device of a user to make a resource accessible;

in response to the first request, generating, by the first system, a token that includes a time-to-live;

storing, in memory of the first system, the token;

storing, in association with the token in the memory of the first system, an identifier of the user and information to be utilized for accessing the resource;

in response to the first request, sending by the first system to the device of the user the token and an instruction to transmit the token to a second domain of a second system;

in response to the second system receiving the token through the second domain from the device of the user:

performing a look-up of the token,

through the performance of the look-up, verifying that the token is stored and the token has not expired,

in response to the verifying, providing, to the second system, the information to be utilized for accessing the resource that is stored in association with the token, and

permitting access to the resource via the second domain, wherein the access is permitted through use by the second system of the information.

Assignments (2)
CHANGE OF NAME Recorded Oct 25, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069268/0034 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2015
From: LISSACK, RYAN; SNELL, ROBERT JOSEPH; FLY, ROBERT CHARLES
To: SALESFORCE.COM, INC.
Reel/Frame 035930/0861 →