IP Library Granted Patent US 10,122,707
Granted Patent B2
US 10,122,707 · App. 15/352,282 · Granted Nov 6, 2018

User impersonation/delegation in a token-based authentication system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,122,707
App. No.
15/352,282
Granted
Nov 6, 2018
Kind
B2
Abstract

A “trusted service” establishes a trust relationship with an identity provider and interacts with the identity provider over a trusted connection. The trusted service acquires a token from the identity provider for a given user (or set of users) without having to present the user's credentials. The trusted service then uses this token (e.g., directly, by invoking an API, by acquiring another token, or the like) to access and obtain a cloud service on a user's behalf even in the user's absence. This approach enables background services to perform operations within a hosted session (e.g., via OAuth-based APIs) without presenting user credentials or even having the user present.

Claims (35)

1. An identity provider apparatus, comprising:

a processor;

computer memory holding computer program instructions executed by the processor to perform a set of operations, comprising:

establishing a trust relationship with a trusted service over a trusted connection;

receiving over the trusted connection from the trusted service a request for a token for one or more authorized users within an authentication domain;

responsive to receiving the request over the trusted connection, generating the token without requiring presentation by the trusted service of a user credential;

returning the token to the trusted service;

responsive to a subsequent receipt from a service provider of the token together with a user identifier associated with a user, the service provider having received the token from the trusted service, validating that the user identifier is within the authentication domain associated with the token; and

upon a successful validation, returning a response to the service provider that enables the trusted service to impersonate the user to the service provider.

2. The identity provider apparatus as described in claim 1 wherein the token is a generic token for a set of authorized users and the validating checks to determine that the user credential is associated with the generic token.

3. The identity provider apparatus as described in claim 1 wherein the token is a specific token for an authorized user, and the validating identifies a username associated with the specific token and verifies that the username matches the user credential.

4. The identity provider apparatus as described in claim 1 wherein, for the trusted connection between the trusted service and the identity provider apparatus, the token represents a trusted service-configured subset of a set of target users.

5. The identity provider apparatus as described in claim 1 wherein the generating operation includes scoping the token as a function of one or more of a set of attributes, the attributes being one of: time, location, status and role.

6. A method, operable within an identity provider, comprising:

establishing a trust relationship with a trusted service over a trusted connection;

receiving over the trusted connection from the trusted service a request for a token for one or more authorized users within an authentication domain;

responsive to receiving the request over the trusted connection, generating the token without requiring presentation by the trusted service of a user credential;

returning the token to the trusted service;

responsive to a subsequent receipt from a service provider of the token together with a user identifier associated with a user, the service provider having received the token from the trusted service, validating that the user identifier is within the authentication domain associated with the token; and

upon a successful validation, returning a response to the service provider that enables the trusted service to impersonate the user to the service provider.

7. The method as described in claim 6 wherein the token is a generic token for a set of authorized users and the validating checks to determine that the user credential is associated with the generic token.

8. The method as described in claim 6 wherein the token is a specific token for an authorized user, and the validating identifies a username associated with the specific token and verifies that the username matches the user credential.

9. The method as described in claim 6 wherein, for the trusted connection between the trusted service and the identity provider, the token represents a trusted service-configured subset of a set of target users.

10. The method as described in claim 6 wherein the generating operation includes scoping the token as a function of one or more of a set of attributes, the attributes being one of: time, location, status and role.

11. A computer program product in a non-transitory computer readable medium for use in a data processing system, the computer program product holding computer program instructions which, when executed by the data processing system serving as an identity provider, perform a set of operations, comprising:

establishing a trust relationship with a trusted service over a trusted connection;

receiving over the trusted connection from the trusted service a request for a token for one or more authorized users within an authentication domain;

responsive to receiving the request over the trusted connection, generating the token without requiring presentation by the trusted service of a user credential;

returning the token to the trusted service;

responsive to a subsequent receipt from a service provider of the token together with a user identifier associated with a user, the service provider having received the token from the trusted service, validating that the user identifier is within the authentication domain associated with the token; and

upon a successful validation, returning a response to the service provider that enables the trusted service to impersonate the user to the service provider.

12. The computer program product as described in claim 11 wherein the token is a generic token for a set of authorized users and the validating checks to determine that the user credential is associated with the generic token.

13. The computer program product as described in claim 11 wherein the token is a specific token for an authorized user, and the validating identifies a username associated with the specific token and verifies that the username matches the user credential.

14. The computer program product as described in claim 11 wherein, for the trusted connection between the trusted service and the identity provider, the token represents a trusted service-configured subset of a set of target users.

15. The computer program product as described in claim 11 wherein the generating operation includes scoping the token as a function of one or more of a set of attributes, the attributes being one of: time, location, status and role.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2025
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: WORKDAY, INC.
Reel/Frame 073051/0916 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF THE NAME IN THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 040330 FRAME 0281. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 30, 2018
From: FORK, MICHAEL JOHN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047363/0321 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2018
From: PRICE, VINCENT EDMUND
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047872/0567 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 20, 2018
From: PRICE, VINCENT EDMUND
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047570/0872 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2016
From: FORK, MICHAEL JOHN
To: INTERNATIONAL BUSINSS MACHINES CORPORATION
Reel/Frame 040330/0281 →