IP Library Granted Patent US 10,104,079
Granted Patent B2
US 10,104,079 · App. 15/593,232 · Granted Oct 16, 2018

Authentication proxy agent

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,104,079
App. No.
15/593,232
Granted
Oct 16, 2018
Kind
B2
Abstract

An authentication engine may be configured to receive an authentication request and credentials from a client. The authentication engine may then generate a proxy agent configured to interact with an identity provider to authenticate the client on behalf of the client, using the credentials. In this way, the authentication engine may receive an assertion of authentication of the client from the identity provider, by way of the proxy agent.

Claims (41)

1. A server comprising:

an authentication engine configured to cause at least one processor of the server to receive, at the server, an authentication request and credentials from a client;

store the credentials at the server;

generate, at the server, a proxy agent;

send, from the proxy agent, the credentials to an identity provider to authenticate the client on behalf of the client, using the credentials;

receive, at the proxy agent, an assertion of authentication of the client from the identity provider;

create a session for the client, based on the assertion; and

delete the stored credentials at the server.

2. The server of claim 1 , wherein the authentication engine is implemented by a mobile server providing services to the client, and the client includes a mobile client.

3. The server of claim 1 , wherein the authentication engine is configured to cause the at least one processor, in response to the receipt of the authentication request and credentials, to resolve a previously-stored authentication configuration, including identifying the identity provider from among a plurality of identity providers as being associated with the client.

4. The server of claim 1 , wherein the proxy agent is configured to store configuration data governing content, format, and timing of interactions with the identity provider.

5. The server of claim 1 , wherein the proxy agent includes a virtual browser manager configured to implement a virtual browser used to relay the credentials to the identity provider on behalf of the client.

6. The server of claim 5 , wherein the virtual browser manager is configured to access a virtual browser pool storing a plurality of available virtual browsers, and to select the virtual browser therefrom.

7. The server of claim 1 , wherein the proxy agent is configured to execute the Security Assertion Markup Language (SAML) standard with the identity provider, including receiving the assertion therefrom, on behalf of the client.

8. The server of claim 1 , wherein the server includes a mobile server, and the authentication engine is provided by the mobile server, and wherein the session provides access to multiple services of the mobile server to the client.

9. A method comprising:

receiving, at a server, an authentication request and credentials from a client;

storing the credentials at the server;

generating, at the server, a proxy agent;

sending, from the proxy agent, the credentials to an identity provider to authenticate the client on behalf of the client, using the credentials;

receiving, at the proxy agent, an assertion of authentication of the client from the identity provider;

creating a session for the client, based on the assertion; and

deleting the stored credentials at the server.

10. The method of claim 9 , wherein receiving the authentication request and credentials further comprises resolving a previously-stored authentication configuration, including identifying the identity provider from among a plurality of identity providers as being associated with the client.

11. The method of claim 9 , wherein the proxy agent is configured to store configuration data governing content, format, and timing of interactions with the identity provider.

12. The method of claim 9 , wherein the proxy agent includes a virtual browser manager configured to implement a virtual browser used to relay the credentials to the identity provider on behalf of the client.

13. The method of claim 9 , wherein the proxy agent is configured to execute the Security Assertion Markup Language (SAML) standard with the identify provider, including receiving the assertion therefrom, on behalf of the client.

14. The method of claim 9 , wherein the server includes a mobile server, and wherein the session provides access to multiple services of the mobile server to the client.

15. A computer program product including instructions recorded on a non-transitory computer readable storage medium and configured to cause at least one processor to:

receive, at a server, an authentication request and credentials from a client;

store the credentials at the server;

generate, at the server, a proxy agent;

send, from the proxy agent, the credentials to an identity provider to authenticate the client on behalf of the client, using the credentials;

receive, at the proxy agent, an assertion of authentication of the client from the identity provider;

create a session for the client, based on the assertion; and

delete the stored credentials at the server.

16. The computer program product of claim 15 , wherein the instructions, when executed, are further configured, in response to the receipt of the authentication request and credentials, to resolve a previously-stored authentication configuration, including identifying the identity provider from among a plurality of identity providers as being associated with the client.

17. The computer program product of claim 15 , wherein the proxy agent is configured to store configuration data governing content, format, and timing of interactions with the identity provider.

18. The computer program product of claim 15 , wherein proxy agent includes a virtual browser manager configured to implement a virtual browser used to relay the credentials to the identity provider on behalf of the client.

19. The computer program product of claim 18 , wherein the virtual browser manager is configured to access a virtual browser pool storing a plurality of available virtual browsers, and to select the virtual browser therefrom.

20. The computer program product of claim 15 , wherein the proxy agent is configured to execute the Security Assertion Markup Language (SAML) standard with the identify provider, including receiving the assertion therefrom, on behalf of the client.

Assignments (15)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2025
From: BMC SOFTWARE, INC.
To: BMC HELIX, INC.
Reel/Frame 070442/0197 →
GRANT OF FIRST LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0628 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0568 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052854/0139) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0617 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052844/0646) Recorded Aug 6, 2024
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 068339/0408 →
OMNIBUS ASSIGNMENT OF SECURITY INTERESTS IN PATENT COLLATERAL Recorded Mar 4, 2024
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING COLLATERAL AGENT
To: GOLDMAN SACHS BANK USA, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 066729/0889 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 1, 2024
From: ALTER DOMUS (US) LLC
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.
Reel/Frame 066567/0283 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Sep 30, 2021
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 057683/0582 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052854/0139 →
SECURITY INTEREST Recorded Jun 4, 2020
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052844/0646 →
SECURITY INTEREST Recorded Sep 10, 2019
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050327/0634 →
RELEASE OF PATENTS Recorded Oct 5, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: BMC SOFTWARE, INC.; BLADELOGIC, INC.; BMC ACQUISITION L.L.C.
Reel/Frame 047198/0468 →
SECURITY INTEREST Recorded Oct 2, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047185/0744 →
SECURITY INTEREST Recorded Jun 22, 2018
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046176/0477 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2017
From: MILLER, KARL FREDERICK
To: BMC SOFTWARE, INC.
Reel/Frame 044024/0521 →