IP Library Granted Patent US 10,027,670
Granted Patent B2
US 10,027,670 · App. 15/586,973 · Granted Jul 17, 2018

Distributed authentication

Inventors: Michael S. W. Tovino (Bend, OR); Amy S. Pendleton (Austin, TX)
Assignee: Mitel Networks, Inc.
H04L63/10G06F9/4401G06F21/57H04L9/0861H04L9/32H04L9/3247H04L63/0428H04L63/0807H04L67/16H04L67/10H04L67/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,027,670
App. No.
15/586,973
Granted
Jul 17, 2018
Kind
B2
Abstract

A method can include receiving a request from a requestor to a given resource, which requestor is registered to access a set of one or more resources. The request includes a ticket that includes signature data generated by an authenticating entity in response to authenticating the requestor. The signature data may be decrypted to provide a decrypted signature. The ticket may be validated in response to the request based on evaluating the decrypted signature. A response can be provided to the requestor based on the validation, and the response can grant the requestor access to the given resource if the validation determines the ticket to be authentic and authorized for the given resource or the response can deny the requestor access to the given resource if the validation determines to reject the ticket.

Claims (51)

1. A system comprising:

a cloud-based authenticator programmed to:

receive an authentication request from a requestor, the authentication request specifying credentials for the requestor,

authenticate the requestor based on the credentials for the requestor, and

provide a response to the requestor, the response comprising a ticket redeemable for accessing resources operating in a hybrid system, the ticket including payload data and a signature encrypted based on a private key generated by the authenticator, and

a ticket evaluator associated with a given resource of the resources, the ticket evaluator being programmed to:

select a public key for the authenticator based on a key identifier specified in the payload data of the ticket,

decrypt the signature of the ticket by applying the public key to the ticket to provide a decrypted signature,

validate the ticket provided in a request from the requestor to access the given resource according to validation parameters stored in the payload data, and

grant the requestor access to the given resource in response to validating the ticket.

2. The system of claim 1 , wherein the resources comprise at least one premise-based resource and at least one cloud-based resource.

3. The system of claim 1 , wherein the ticket evaluator is at least partially cloud-based.

4. The system of claim 1 , wherein the cloud-based authenticator further comprises:

an authenticator API to receive the authentication request from the requestor, the authentication request including the credentials of the requestor;

a credential evaluator to evaluate the credentials of the requestor to determine if the requestor is authorized to operate in the hybrid system; and

a ticket generator to generate the ticket in response to the credential evaluator determining that the requestor is authorized to operate in the hybrid system.

5. The system of claim 4 , wherein the ticket generator employs key data to identify the public key for the ticket, wherein the identity of the public key is provided in the payload data.

6. The system of claim 1 , wherein the ticket is a transparent ticket that does not allow the resources access to sensitive data on a premise system.

7. The system of claim 1 , further comprising another ticket evaluator associated with another resource of the resources, wherein the other ticket evaluator is programmed to receive from the requestor another request to access the other resource, the other request comprising the ticket, the other ticket evaluator to grant or deny the requestor access to the other resource based on validating the ticket by the other resource in response to the other request.

8. The system of claim 7 , wherein the other resource comprises a bootstrapper service and the other request comprises a location request for a location of the given resource, the bootstrapper service providing the location of the given resource in a response to the requestor in response to the other ticket evaluator determining that the validating the ticket to grant the requestor access to the bootstrapper service, the requestor providing the request to the location of the given resource that is provided in the response from the bootstrapper service.

9. A method comprising,

receiving, at a cloud-based authenticator, an authentication request from a requestor, the authentication request specifying credentials for the requestor,

authenticating, at the cloud-based authenticator, the requestor based on the credentials for the requestor, and

providing, at the cloud-based authenticator, a response to the requestor, the response comprising a ticket redeemable for accessing resources operating in a hybrid system, the ticket including payload data and a signature encrypted based on a private key generated by the authenticator,

wherein the ticket is used to authenticate the requestor for access to one or more resources operating in the hybrid system, and

wherein the resources operating in the hybrid system comprise both premise-based resources and cloud-based resources.

10. The method of claim 9 , wherein the ticket is a transparent ticket that does not allow the resources access to sensitive data on a premise system.

11. A method comprising:

receiving, at a cloud-based authenticator, an authentication request from a requestor, the authentication request specifying credentials for the requestor;

authenticating, at the cloud-based authenticator, the requestor based on the credentials for the requestor;

providing, at the cloud-based authenticator, a response to the requestor, the response comprising a ticket redeemable for accessing resources operating in a hybrid system, the ticket including payload data and a signature encrypted based on a private key generated by the authenticator,

wherein the ticket is used to authenticate the requestor for access to one or more resources operating in the hybrid system;

receiving, by a ticket evaluator associated with a given resource of the resources, a request for the requestor to access the given resource, wherein the request comprises the ticket;

validating, by the ticket evaluator, the ticket based on parameters stored in payload data of the ticket,

wherein the parameters stored in the payload data comprise a key identifier that is used to select a public key to match with the public key of the ticket; and

granting, by the ticket evaluator, the requestor access to the given resource in response to validating the ticket.

12. The method of claim 11 , wherein the validating further comprises:

selecting, by the ticket evaluator, the public key based on the key identifier, and

decrypting, by the ticket evaluator, the signature by applying the public key to the ticket.

13. The method of claim 11 , wherein the ticket evaluator is at least partially cloud-based.

14. A method comprising

receiving, at a cloud-based authenticator, an authentication request from a requestor, the authentication request specifying credentials for the requestor;

authenticating, at the cloud-based authenticator, the requestor based on the credentials for the requestor;

providing, at the cloud-based authenticator, a response to the requestor, the response comprising a ticket redeemable for accessing resources operating in a hybrid system, the ticket including payload data and a signature encrypted based on a private key generated by the authenticator,

wherein the ticket is used to authenticate the requestor for access to one or more resources operating in the hybrid system;

receiving, by a ticket evaluator associated with a given resource of the resources, a request for the requestor to access the given resource, wherein the request comprises the ticket;

receiving, by another ticket evaluator associated with another resource of the resources, a request for the requestor to access the other resource, wherein the request comprises the ticket; and

granting, by the other ticket evaluator, the requestor access to the other resource in response to validating the ticket,

wherein the other resource comprises a bootstrapper service and the other request comprises a location request for a location of the given resource, the bootstrapper service providing the location of the given resource in a response to the requestor in response to the other ticket evaluator determining that the validating the ticket to grant the requestor access to the bootstrapper service.

15. The method of claim 14 , wherein the requestor providing the request to the location of the given resource that is provided in the response from the bootstrapper service.

16. The method of claim 14 , wherein the resources operating in the hybrid system comprise at least one premise-based resource and at least one cloud-based resource.

Assignments (23)
SECURITY INTEREST Recorded Jun 30, 2025
From: MLN US HOLDCO LLC; MITEL (DELAWARE), INC.; MITEL NETWORKS CORPORATION; MITEL NETWORKS, INC.
To: U.S. PCI SERVICES, LLC
Reel/Frame 071758/0843 →
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: MITEL (DELAWARE), INC.; MITEL NETWORKS, INC.; MITEL NETWORKS CORPORATION
Reel/Frame 071730/0632 →
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2025
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: MITEL (DELAWARE), INC.; MITEL COMMUNICATIONS, INC.; MITEL NETWORKS, INC.; MITEL NETWORKS CORPORATION
Reel/Frame 071712/0821 →
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2025
From: ANKURA TRUST COMPANY, LLC
To: MITEL (DELAWARE), INC.; MITEL COMMUNICATIONS, INC.; MITEL CLOUD SERVICES, INC.; MITEL NETWORKS, INC.; MITEL NETWORKS CORPORATION
Reel/Frame 071722/0721 →
SECURITY INTEREST Recorded Jun 20, 2025
From: MITEL (DELAWARE), INC.; MITEL NETWORKS CORPORATION; MITEL NETWORKS, INC.
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 071676/0815 →
SECURITY INTEREST Recorded Mar 12, 2025
From: MITEL (DELAWARE), INC.; MITEL NETWORKS CORPORATION; MITEL NETWORKS, INC.
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070689/0857 →
NOTICE OF SUCCCESSION OF AGENCY - 3L Recorded Jan 14, 2025
From: UBS AG, STAMFORD BRANCH, AS LEGAL SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 070006/0268 →
NOTICE OF SUCCCESSION OF AGENCY - PL Recorded Jan 14, 2025
From: UBS AG, STAMFORD BRANCH, AS LEGAL SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 069895/0755 →
NOTICE OF SUCCESSION OF AGENCY - 5L Recorded Jan 14, 2025
From: UBS AG, STAMFORD BRANCH, AS LEGAL SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 069897/0046 →
NOTICE OF SUCCCESSION OF AGENCY - 2L Recorded Jan 14, 2025
From: UBS AG, STAMFORD BRANCH, AS LEGAL SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 069896/0001 →
NOTICE OF SUCCESSION OF AGENCY - 4L Recorded Jan 14, 2025
From: UBS AG, STAMFORD BRANCH, AS LEGAL SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 069896/0827 →
SECURITY INTEREST Recorded Nov 1, 2022
From: MITEL (DELAWARE), INC.; MITEL NETWORKS, INC.; MITEL COMMUNICATIONS, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 061830/0760 →
SECURITY INTEREST Recorded Nov 1, 2022
From: MITEL (DELAWARE), INC.; MITEL NETWORKS, INC.; MITEL COMMUNICATIONS, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 061830/0643 →
SECURITY INTEREST Recorded Nov 1, 2022
From: MITEL (DELAWARE), INC.; MITEL NETWORKS, INC.; MITEL COMMUNICATIONS, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 061830/0715 →
SECURITY INTEREST Recorded Dec 13, 2018
From: MITEL NETWORKS, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047988/0478 →
SECURITY INTEREST Recorded Dec 13, 2018
From: MITEL NETWORKS, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047909/0814 →
RELEASE OF SECURITY INTEREST Recorded Dec 3, 2018
From: CITIZENS BANK, N.A., AS ADMINISTRATIVE AGENT
To: SHORETEL, INC.
Reel/Frame 047713/0843 →
CHANGE OF NAME Recorded Oct 15, 2018
From: SHORETEL, INC.
To: MITEL NETWORKS, INC.
Reel/Frame 047239/0088 →
MERGER AND CHANGE OF NAME Recorded Oct 15, 2018
From: MITEL NETWORKS, INC.; SHORETEL, INC.
To: SHORETEL, INC.
Reel/Frame 047239/0183 →
CHANGE OF NAME Recorded Jul 10, 2018
From: SHORETEL, INC.
To: MITEL NETWORKS, INC.
Reel/Frame 046309/0033 →
MERGER AND CHANGE OF NAME Recorded Jul 10, 2018
From: SHORETEL, INC.; MITEL NETWORKS, INC.
To: SHORETEL, INC.
Reel/Frame 046308/0980 →
SECURITY INTEREST Recorded Sep 25, 2017
From: SHORETEL, INC.
To: CITIZENS BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 043829/0711 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2017
From: TOVINO, MICHAEL S.W.; PENDLETON, AMY S.
To: SHORETEL, INC.
Reel/Frame 042244/0365 →
Continuity (2)
Continuation 14590418 · Jan 6, 2015
Related Publication 20170237740A1 · Aug 17, 2017