IP Library › Granted Patent US 9,847,991
Granted Patent B2
US 9,847,991 · App. 15/311,009 · Granted Dec 19, 2017

Method for managing user accounts in a hosted application

Inventor: Christophe Guionneau (Grenoble, FR)
Assignee: EVIDIAN
H04L63/0815G06F21/41H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,847,991
App. No.
15/311,009
Granted
Dec 19, 2017
Kind
B2
Abstract

A method for managing user accounts in an application of an application provider, includes: receiving a request for proof of authentication to authenticate a user attempting to access the application, the user being registered with an identity provider having a trust relationship with the application provider; obtaining, from a local database, user data including authentication data and access rights data; authenticating the user by the authentication data; determining the user right to access the application, by the access rights data; determining the existence or absence of a user account associated with the user, by querying an external database managed by the application provider; if the user has the right to access the application and there is no user account associated with the user: triggering provisioning of the user account at an entity, generating a proof of authentication associated with the user, sending the proof of authentication to the application provider.

Claims (36)

1. A method for managing user accounts in an application of an application service provider, comprising the following steps, performed by an identity provider sharing a trust relationship with the application service provider:

receiving a request for proof of authentication in order to authenticate a user attempting to access the application, said user being registered with the identity provider;

obtaining, from a local database, data about the user, said data comprising authentication data and access rights data;

authenticating the user by means of the authentication data;

determining the right to access the application by the user by means of the access rights data;

determining an existence or absence of a user account associated with the user, by querying an external database managed by the application service provider;

when the user has the right to access the application and there is no user account associated with the user:

triggering provisioning of the user account at an entity;

generating a proof of authentication associated with the user;

sending said proof of authentication to the application service provider.

2. The method according to claim 1 , comprising: when the user does not have the right to access the application and there is a user account associated with the user, triggering deprovisioning of the user account at the entity.

3. The method according to claim 1 , wherein the entity is the application service provider, the identity provider providing account provisioning or deprovisioning instructions to the external database.

4. The method according to claim 1 , wherein the entity is an external management component, the external management component providing account provisioning or deprovisioning instructions to the external database.

5. The method according to claim 1 , wherein after provisioning or deprovisioning triggering of a user account, the identity provider updates information of user accounts, indicating the user accounts associated with the application service provider and the user accounts associated with the user.

6. The method according to claim 5 , wherein the identity provider performs an overall checking step, comprising:

for each user registered with the identity provider, obtaining form the local database access rights data relating to the user;

determining a list of user accounts to be deprovisioned, based on the access rights and the information of user accounts;

triggering the deprovisioning of the user accounts from the list of accounts to be deprovisioned.

7. The method according to claim 5 , wherein the identity provider performs a reconciliation step, comprising:

obtaining from the external database a list of user accounts provisioned;

comparing the information of user accounts with the list of accounts to be provisioned;

updating the information of user accounts based on the result of the comparison.

8. The method according to claim 5 , wherein the identity provider performs an account deletion step, comprising:

obtaining a piece of information for modifying access rights data of a user;

determining a list of user accounts to be deprovisioned, based on the access rights data modified and the information of user accounts;

triggering the deprovisioning of the user accounts from the list of accounts to be deprovisioned.

9. A non-transitory computer readable medium, comprising a set of instructions, which when run by a computer, causes the implementation of a method for managing user accounts in an application of an application service provider, comprising the following steps, performed by an identity provider sharing a trust relationship with the application service provider:

receiving a request for proof of authentication in order to authenticate a user attempting to access the application, said user being registered with the identity provider;

obtaining, from a local database, data about the user, said data comprising authentication data and access rights data;

authenticating the user by means of the authentication data;

determining the right to access the application by the user by means of the access rights data;

determining an existence or absence of a user account associated with the user, by querying an external database managed by the application service provider;

when the user has the right to access the application and there is no user account associated with the user:

triggering provisioning of the user account at an entity;

generating a proof of authentication associated with the user;

sending said proof of authentication to the application service provider.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2022
From: EVIDIAN
To: BULL SAS
Reel/Frame 060838/0884 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2017
From: GUIONNEAU, CHRISTOPHE
To: EVIDIAN
Reel/Frame 041195/0887 →
Priority Claims (1)
FR 14 54303 · May 14, 2014 · national
Continuity (1)
Related Publication 20170078272A1 · Mar 16, 2017