IP Library Granted Patent US 9,473,468
Granted Patent B2
US 9,473,468 · App. 14/856,371 · Granted Oct 18, 2016

Methods and systems of data security in browser storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,473,468
App. No.
14/856,371
Granted
Oct 18, 2016
Kind
B2
Abstract

Mechanisms and methods are provided for managing OAuth access in a database network system, and extending the OAuth flow of authentication to securely store the OAuth encrypted refresh token in the storage available with current browsers or any other non-secure storage on user system.

Claims (22)

1. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, are configurable to cause the one or more processors to:

authenticate a client browser via an identity provider;

grant permission for a service to access data and/or services of the identity provider;

redirect, with the identity provider, the client browser to an endpoint provided by service provider, wherein the service provider provides an on-demand service environment comprising at least a multitenant database system;

send an authorization code, with the identity provider, during the redirect, the authorization code to be exchanged, by the service provider, for one or more refresh tokens and access to the data and/or services;

wherein the client browser establishes communications with the service provider, the service provider prompts the user to set-up a passcode before obtaining the tokens and once the passcode is provided, and after the service provider obtains the tokens from the identity provider, the service provider encrypts the refresh token(s) by using the passcode and/or by a private key generated by the service provider; and

wherein the encrypted token is returned to the client browser to be saved locally in local storage of the client browser.

2. The non-transitory computer-readable medium of claim 1 wherein the encrypted result further comprises a unique identifier to track future authentication requests.

3. The non transitory computer-readable medium of claim 1 further comprising instructions that, when executed by the one or more processors, cause the one or more processors to, during future access attempts, cause the client browser to send the encrypted token along with the passcode to the service provider to access the data and/or services of the identity provider.

4. A method comprising:

authenticating a client browser via an identity provider;

granting permission for an service to access data and/or services of the identity provider;

redirecting, with the identity provider, the client browser to an endpoint provided by a service provider, wherein the service provider provides an on-demand service environment comprising at least a multitenant database system;

sending an authorization code, with the identity provider, during the redirect, the authorization code to be exchanged, by the service provider, for one or more refresh tokens and access to the data and/or services;

wherein the client browser establishes communications with the service provider, the service provider prompts the user to set-up a passcode before obtaining the tokens and once the passcode is provided, and after the service provider obtains the tokens from the identity provider, the service provider encrypts the refresh token(s) by using the passcode and/or by a private key generated by the service provider; and

wherein the encrypted token is returned to the client browser to be saved locally in local storage of the client browser.

5. The method of claim 4 wherein the encrypted result further comprises a unique identifier to track future authentication requests.

6. The method of claim 4 further comprising during future access attempts, causing the client browser to send the encrypted token along with the passcode to the service provider to access the data and/or services of the identity provider.

7. A computer system comprising:

one or more processors communicatively coupled to each other to authenticate a client browser via an identity provider, to grant permission for an service to access data and/or services of the identity provider, to redirect, with the identity provider, the client browser to an endpoint provided by a service provider, wherein the service provider provides an on-demand service environment comprising at leas a multitenant database system, and to send an authorization code, with the identity provider, during the redirect, the authorization code to be exchanged, by the service provider, for one or more refresh tokens and access to the data and/or services, wherein the client browser establishes communications with the service provider, the service provider prompts the user to set-up a passcode before obtaining the tokens and once the passcode is provided, and after the service provider obtains the tokens from the identity provider, the service provider encrypts the refresh token(s) by using the passcode and/or by a private key generated by the service provider, wherein the encrypted token is returned to the client browser to be saved locally in local storage of the client browser.

8. The system of claim 7 wherein the encrypted result further comprises a unique identifier to track future authentication requests.

9. The system of claim 7 , wherein the one or more processors are further configured to cause the one or more processors to, during future access attempts, cause the client browser to send the encrypted token along with the passcode to the service provider to access the data and/or services of the identity provider.

Assignments (2)
CHANGE OF NAME Recorded Nov 21, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069430/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2015
From: GUPTA, AKHILESH
To: SALESFORCE.COM, INC.
Reel/Frame 036583/0656 →