IP Library › Granted Patent US 10,348,713
Granted Patent B2
US 10,348,713 · App. 15/473,502 · Granted Jul 9, 2019

Pluggable authentication for enterprise web application

Inventor: Dhiraj D. Thakkar (Foster City, CA)
Assignee: Oracle International Corporation
H04L63/08H04L63/06H04L63/0807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,348,713
App. No.
15/473,502
Granted
Jul 9, 2019
Kind
B2
Abstract

A system and method for facilitating authenticating a client application to enable communications with another server-side application running on a server in communication with the client application (client). An example embodiment involves providing an authenticator for the client to a shared library that is accessible to the client and server, and then registering the authenticator for the client at the server. After registration, the client sends a request message (addressed to a server-side application) and token to the server. The token is derived using the authenticator at the shared library. The server then uses the token to check that the authenticator associated with the received token is registered. The server then communicates with the shared library to authenticate the client by verifying that the received token identifies the client that has provided the authenticator to the shared library. Client identity is then set to enable communications with the server-side application.

Claims (38)

1. A method for facilitating authenticating a client application for communications with another application running on a server, the method comprising:

using the server to access a shared library to register a description of an authenticator for the client application in a descriptor file maintained by the server, yielding a registered authenticator in response thereto, wherein the authenticator includes token-generating code that can be executed to produce a secure token, and wherein the secure token includes information identifying the client application, wherein the authenticator further includes interface code for interfacing the client application with the shared library and for generating one or more tokens, wherein the server is an application server that includes authenticator interfacing code for facilitating handling one or more tokens received from the client application;

receiving a request message in combination with a token from the client application at the server, wherein the token has been generated by the authenticator, and wherein the request message is addressed to a server-side application that requires authentication of the client application before enabling communications therewith;

determining that the token is associated with the registered authenticator;

confirming that the client application that is associated with the registered authenticator has sent the token;

setting an identity of the client application at the server based on confirming; and

processing the request message by the server-side application running on the server.

2. The method of claim 1 , wherein the authenticator is stored at the shared library as an authenticator class.

3. The method of claim 1 , wherein confirming further includes accessing the shared library to execute the authenticator therein that is associated with the received token, resulting in generation of a confirming token.

4. The method of claim 1 , wherein the confirming token matches the token received with the request message by the server from the client application.

5. The method of claim 1 , wherein the server selectively accesses the shared library, the descriptor file, and an application server security module.

6. The method of claim 5 , wherein setting the identity of the client application includes using an Application Programming Interface (API) of the application server security module to establish that an identity of the client application has been authenticated.

7. The method of claim 6 , wherein the server-side application employs similar authentication technology as that employed by the server.

8. The method of claim 1 , wherein the client application runs on the server, and wherein the client application employs authentication technology that is different from the authentication technology employed by the server-side application that requires authentication of a client application before a request message from the client can be fulfilled by the server-side application.

9. A non-transitory processor-readable storage device including instructions executable by one or more processors for:

using the server to access a shared library to register a description of an authenticator for the client application in a descriptor file maintained by the server, yielding a registered authenticator in response thereto, wherein the authenticator includes token-generating code that can be executed to produce a secure token, and wherein the secure token includes information identifying the client application, wherein the authenticator further includes interface code for interfacing the client application with the shared library and for generating one or more tokens, wherein the server is an application server that includes authenticator interfacing code for facilitating handling one or more tokens received from the client application;

receiving a request message in combination with a token from the client application at the server, wherein the token has been generated by the authenticator, and wherein the request message is addressed to a server-side application that requires authentication of the client application before enabling communications therewith;

determining that the token is associated with the registered authenticator;

confirming that the client application that is associated with the registered authenticator has sent the token;

setting an identity of the client application at the server based on confirming; and

processing the request message by the server-side application running on the server.

10. The non-transitory processor-readable storage device of claim 9 , wherein the authenticator includes token-generating code that can be executed to produce a secure token, and wherein the secure token includes information identifying the client application.

11. The non-transitory processor-readable storage device of claim 10 , wherein the authenticator is stored at the shared library as an authenticator class.

12. The non-transitory processor-readable storage device of claim 10 , wherein confirming further includes accessing the shared library to execute the authenticator therein that is associated with the received token, resulting in generation of a confirming token.

13. The non-transitory processor-readable storage device of claim 10 , wherein the confirming token matches the token received with the request message by the server from the client application.

14. The non-transitory processor-readable storage device of claim 10 , wherein the authenticator further includes interface code for interfacing the client application with the shared library and for generating one or more tokens.

15. The non-transitory processor-readable storage device of claim 14 , wherein the server is an application server that includes authenticator interfacing code for facilitating handling one or more tokens received from the client application and for selectively accessing the shared library, the descriptor file, and an application server security module.

16. The non-transitory processor-readable storage device of claim 15 , wherein setting the identity of the client application includes using an Application Programming Interface (API) of the application server security module to establish that an identity of the client application has been authenticated.

17. The non-transitory processor-readable storage device of claim 16 , wherein the server-side application employs similar authentication technology as that employed by the server, and wherein the client application runs on the server, and wherein the client application employs authentication technology that is different from the authentication technology employed by the server-side application that requires authentication of a client application before a request message from the client can be fulfilled by the server-side application.

18. An apparatus for facilitating authenticating a client application for communications with another application running on a server, the apparatus comprising:

one or more processors;

a storage device including instructions for:

using the server to access a shared library to register a description of an authenticator for the client application in a descriptor file maintained by the server, yielding a registered authenticator in response thereto, wherein the authenticator includes token-generating code that can be executed to produce a secure token, and wherein the secure token includes information identifying the client application, wherein the authenticator further includes interface code for interfacing the client application with the shared library and for generating one or more tokens, wherein the server is an application server that includes authenticator interfacing code for facilitating handling one or more tokens received from the client application;

receiving a request message in combination with a token from the client application at the server, wherein the token has been generated by the authenticator, and wherein the request message is addressed to a server-side application that requires authentication of the client application before enabling communications therewith;

determining that the token is associated with the registered authenticator;

confirming that the client application that is associated with the registered authenticator has sent the token;

setting an identity of the client application at the server based on confirming; and

processing the request message by the server-side application running on the server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2017
From: THAKKAR, DHIRAJ D.
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 041790/0318 →
Continuity (2)
Provisional Application 62395991 · Sep 16, 2016
Related Publication 20180083941A1 · Mar 22, 2018