IP Library › Granted Patent US 9,600,652
Granted Patent B2
US 9,600,652 · App. 14/791,733 · Granted Mar 21, 2017

Mobile application, identity interface

Inventors: Ajay Sondhi (San Jose, CA); Ching-Wen Chu (San Jose, CA); Beomsuk Kim (San Jose, CA); Sean Brydon (San Francisco, CA)
Assignee: Oracle International Corporation
G06F21/41H04L63/0807H04L63/0815H04L67/306H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,600,652
App. No.
14/791,733
Granted
Mar 21, 2017
Kind
B2
Abstract

Techniques for managing identities are provided. In some examples, identity management, authentication, authorization, and token exchange frameworks may be provided for use with mobile devices, mobile applications, cloud applications, and/or other web-based applications. For example a mobile client may request to perform one or more identity management operations associated with an account of a service provider. Based at least in part on the requested operation and/or the particular service provider, an application programming interface (API) may be utilized to generate and/or perform one or more instructions and/or method calls for managing identity information of the service provider.

Claims (47)

1. A system, comprising:

a memory storing a plurality of instructions; and

one or more hardware processors configured to access the memory, wherein the one or more hardware processors are further configured to execute the plurality of instructions to:

receive, from a mobile client application of a mobile device, an access request for requesting access to an access management service provider;

determine, based at least in part on the access request, an access management service call for accessing an access management service corresponding to the access management service provider;

receive, from the access management service provider, a mobile client token and a user token based at least in part on the access request;

provide, to the mobile client application, the mobile client token and the user token;

receive, from the mobile device, an access token request, the access token request identifying the mobile client token, the user token, and a resource to be accessed at an application service provider different from the access management service provider;

provide, to the access management service provider, the access token request;

receive, from the access management service provider, based at least in part on the access token request, an access token for accessing the resource at the application service provider; and

cause the mobile client application to perform a function associated with the application service provider based at least in part on the received access token.

2. The system of claim 1 , wherein the mobile client application comprises a software as a service (SaaS) application, or a Rich Internet Application (RIA).

3. The system of claim 1 , wherein the access request comprises an authentication request, an authorization request, a user profile management request, a policy management request, or a password management request.

4. The system of claim 3 , wherein the authentication request includes a user identifier (ID) associated with a user of the mobile client application, a password associated with the user of the mobile client application, and the mobile client token for indicating that the mobile client application is authenticated, and wherein the user ID and the password are configured for authenticating the user with the access management service.

5. The system of claim 1 , wherein the access management service call comprises a method call to implement a token exchange.

6. The system of claim 1 , further comprising instructions to determine the access management service call based on an Application Programming Interface (API) of the access management service provider for which the access request is requested.

7. The system of claim 1 , wherein the access request further includes an indication of the access management service provider for which access is requested, wherein the mobile client token indicates that the mobile client application is authenticated and the user token indicates that a user of the mobile client application is authenticated.

8. The system of claim 7 , wherein the one or more hardware processors are further configured to provide the access token to the mobile client application at least in response to receiving an indication that the user and the client application are granted access to the access management service provider by the access management service.

9. The system of claim 1 , wherein a first access management service call corresponding to a first service provider is different from a second access management service call corresponding to a second service provider.

10. The system of claim 1 , wherein the access management service to be used is specified by the access management service provider and not indicated to the mobile client application.

11. A computer-implemented method, comprising:

receiving, by a computer system, an access request for accessing a third-party server, the access request received from a mobile client application of a mobile device;

determining, by the computer system, an access management service call corresponding to the third-party server for which access is requested, the determining based at least in part on the access request received from the mobile client application;

receiving, from the third-party server, a mobile client token and a user token based at least in part on the access request;

providing, to the mobile client application, the mobile client token and the user token;

receiving, from the mobile device, an access token request, the access token request identifying the mobile client token, the user token, and a resource to be accessed at an application service provider different from the third-party server;

providing, to the third-party server, the access token request;

receiving, from the third-party server, based at least in part on the access token request, an access token for accessing the resource at the application service provider;

providing, by the computer system, the access token to the mobile client application; and

causing the mobile client application to perform a function associated with the application service provider based at least in part on the received access token.

12. The computer-implemented method of claim 11 , wherein the mobile client application comprises a rich Internet application, or a software as a service application.

13. The computer-implemented method of claim 11 , wherein the request to access the third-party server is received as a representational state transfer (REST) call independent of an application programming interface (API) of the third-party server for which access is requested.

14. The computer-implemented method of claim 11 , further comprising determining, based at least in part on an application programming interface (API) of the third-party server, a predefined manner for providing the access token request.

15. A computer-readable memory storing a plurality of instructions executable by one or more hardware processors, the plurality of instructions comprising:

instructions that cause the one or more hardware processors to receive, from a mobile client application of a mobile device, a first method call for requesting access to a service provider;

instructions that cause the one or more hardware processors to determine, based at least in part on the first method call from the mobile client application, a second method call for utilizing an access management service associated with the service provider;

instructions that cause the one or more hardware processors to receive from the service provider, a mobile client token and a user token based at least in part on the first method call for requesting access;

instructions that cause the one or more hardware processors to provide, to the mobile client application, the mobile client token and the user token;

instructions that cause the one or more hardware processors to receive, from the mobile device, an access token request, the access token request identifying the mobile client token, the user token, and a resource to be accessed at an application service provider different from the service provider;

instructions that cause the one or more hardware processors to provide, to the service provider, the access token request;

instructions that cause the one or more hardware processors to receive, from the service provider, based at least in part on the access token request, an access token for accessing the resource at the application service provider; and

instructions that cause the one or more hardware processors to provide the access token to the mobile client application to enable the mobile client application to perform a function associated with the service provider based at least in part on the access token.

16. The computer-readable memory of claim 15 , wherein the first method call for requesting access to the service provider comprises a representational state transfer (REST) call and includes at least a request to authenticate the user of the mobile client application.

17. The computer-readable memory of claim 15 , further comprising instructions that cause the one or more hardware processors to determine a format for transmission of the second method call based at least in part on an application programming interface (API) of the access management service.

18. The computer-readable memory of claim 17 , wherein a first format of a first set of method calls for a first access management service are different from a second format of a second set of method calls for a second access management service.

19. The computer-readable memory of claim 15 , wherein the access management service is configured to receive method calls other than representational state transfer (REST) interface calls.

20. The computer-readable memory of claim 15 , wherein the second method call comprises a request to authenticate a user of the mobile client application, a request to authorize the user of the mobile client application, or a request to perform a token exchange for providing user access to the service provider.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2015
From: SONDHI, AJAY; CHU, CHING-WEN; KIM, BEOMSUK; BRYDON, SEAN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 036025/0644 →
Continuity (3)
Continuation 13485509 · May 31, 2012
Provisional Application 61541034 · Sep 29, 2011
Related Publication 20150310202A1 · Oct 29, 2015