IP Library Granted Patent US 9,800,586
Granted Patent B2
US 9,800,586 · App. 15/268,287 · Granted Oct 24, 2017

Secure identity federation for non-federated systems

Inventors: Thomas Nabiel Boulos (Corte Madera, CA); Prasanta Kumar Behera (Cupertino, CA)
Assignee: salesforce.com, inc.
H04L63/102G06F21/30G06F21/33G06F21/41H04L63/08H04L63/0815H04L63/0823H04L63/10H04L63/20H04L67/02H04L67/306H04L69/329
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,800,586
App. No.
15/268,287
Granted
Oct 24, 2017
Kind
B2
Abstract

Methods and apparatus, including computer program products, implementing and using techniques for providing user credentials over a network to a remote computer application. User credentials for the remote computer application are stored in a central repository that is accessible through the network. A request is sent to a service to perform, on behalf of a user, a particular task involving the remote computer application. It is determined whether the service has been granted permission to act on behalf of the user with respect to the remote computer application. When the service has permission to act on behalf of the user, the service is used to retrieve the user's credentials for the remote computer application from the central repository and to supply the retrieved user credentials to the remote computer application.

Claims (39)

1. A method of providing a unified access to systems, the method including:

storing a plurality of sets of user credentials for a plurality of remote computer applications in a central repository accessible via an interoperability network, wherein the plurality of remote computer applications include non-federated entities that do not share a common identity verification protocol;

receiving an interoperability network credential that authorizes a user to use the plurality of remote computer applications and access the stored plurality of sets of the user credentials;

verifying that an intermediary service coupled to the interoperability network, upon receiving a request to perform, on behalf of the user, a particular task that requires access to and task performance by a particular remote computer application from the plurality of remote computer applications, has authorization to act on behalf of the user in obtaining authorized access to and task performance by the particular remote computer application; and

upon verification of authorization, automatically supplying the intermediary service with particular user credentials for the particular remote computer application from the central repository.

2. The method of claim 1 , further including for a plurality of intermediary services coupled to the interoperability network, receiving a selection specifying at least one intermediary service to act on behalf of the user by accessing user's credentials.

3. The method of claim 1 , further including receiving instructions specifying a degree of authorization of the intermediary service.

4. The method of claim 1 , wherein the particular remote computer application is an on-demand service.

5. The method of claim 1 , wherein the intermediary service is an on-demand service.

6. The method of claim 1 , wherein verifying that the intermediary service has authorization includes checking a policy to determine conditions that the user has set for the intermediary service to act on behalf of the user.

7. The method of claim 1 , further including retrieving user credentials for the particular remote computer application and applying an enrichment prior to automatically providing the particular user credentials to the particular remote computer application.

8. The method of claim 7 , wherein the enrichment includes at least one of a digital signature and a tariff calculator for a purchase order.

9. The method of claim 1 , further including sending a notification to the user when the intermediary service accesses user credentials of the user.

10. The method of claim 9 , wherein the notification identifies at least one of:

the intermediary service;

the particular remote computer application for which the user credentials were accessed;

a user account associated with the user credentials; and

an outcome of the intermediary service accessing user credentials of the user.

11. The method of claim 9 , further including, in response to sending the notification, receiving instructions from the user for at least one of:

revoking authorization of the intermediary service to act on behalf of the user; and

modifying authorization of the intermediary service to act on behalf of the user.

12. A system of providing a unified access to systems, the system including:

one or more processors coupled to memory storing computer instructions that, when executed on the processors, implement actions including:

storing a plurality of sets of user credentials for a plurality of remote computer applications in a central repository accessible via an interoperability network, wherein the plurality of remote computer applications include non-federated entities that do not share a common identity verification protocol;

receiving an interoperability network credential that authorizes a user to use the plurality of remote computer applications and access the stored plurality of sets of the user credentials;

verifying that an intermediary service coupled to the interoperability network, upon receiving a request to perform, on behalf of the user, a particular task that requires access to and task performance by a particular remote computer application from the plurality of remote computer applications, has authorization to act on behalf of the user in obtaining authorized access to and task performance by the particular remote computer application; and

upon verification of authorization, automatically supplying the intermediary service with particular user credentials for the particular remote computer application from the central repository.

13. The system of claim 12 , further configured to receive, for a plurality of intermediary services coupled to the interoperability network, a selection specifying at least one intermediary service to act on behalf of the user by accessing user's credentials.

14. The system of claim 12 , further configured to receive instructions specifying a degree of authorization of the intermediary service.

15. The system of claim 12 , wherein the particular remote computer application is an on-demand service.

16. The system of claim 12 , wherein the intermediary service is an on-demand service.

17. The system of claim 12 , wherein verifying that the intermediary service has authorization includes checking a policy to determine conditions that the user has set for the intermediary service to act on behalf of the user.

18. The system of claim 12 , further including retrieving user credentials for the particular remote computer application and applying an enrichment prior to automatically providing the particular user credentials to the particular remote computer application.

19. The system of claim 18 , wherein the enrichment includes at least one of a digital signature and a tariff calculator for a purchase order.

20. A non-transitory computer readable medium storing a plurality of instructions for programming one or more processors to provide a unified access to systems, the instructions, when executed on the processors, implementing actions including:

storing a plurality of sets of user credentials for a plurality of remote computer applications in a central repository accessible via an interoperability network, wherein the plurality of remote computer applications include non-federated entities that do not share a common identity verification protocol;

receiving an interoperability network credential that authorizes a user to use the plurality of remote computer applications and access the stored plurality of sets of the user credentials;

verifying that an intermediary service coupled to the interoperability network, upon receiving a request to perform, on behalf of the user, a particular task that requires access to and task performance by a particular remote computer application from the plurality of remote computer applications, has authorization to act on behalf of the user in obtaining authorized access to and task performance by the particular remote computer application; and

upon verification of authorization, automatically supplying the intermediary service with particular user credentials for the particular remote computer application from the central repository.

Assignments (1)
CHANGE OF NAME Recorded Jan 27, 2025
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 070014/0854 →
Continuity (9)
Continuation 14754653 · Jun 29, 2015
Continuation 13886209 · May 2, 2013
Continuation 13874418 · Apr 30, 2013
Continuation 13620208 · Sep 14, 2012
Continuation 13335592 · Dec 22, 2011
Continuation 12753495 · Apr 2, 2010
Continuation 11012639 · Dec 14, 2004
Provisional Application 60615314 · Oct 1, 2004
Related Publication 20170006041A1 · Jan 5, 2017