IP Library Granted Patent US 10,148,637
Granted Patent B2
US 10,148,637 · App. 15/836,641 · Granted Dec 4, 2018

Secure authentication to provide mobile access to shared network resources

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,148,637
App. No.
15/836,641
Granted
Dec 4, 2018
Kind
B2
Abstract

Techniques to perform secure authentication to provide mobile access to shared content are disclosed. In various embodiments, a user credential associated with a request to access content is received at a connector node from a mobile application running on a mobile device. The user credential is used to create at the connector node a secure credential token that includes the user credential. The secure credential token is used to provide to the mobile application on the mobile device, via the connector node, access to content on two or more servers residing on a protected network with which the user credential is associated.

Claims (38)

1. A method of providing mobile access to content, comprising:

receiving at a connector node, from a mobile application running on a mobile device, a user credential associated with a request to access content;

using the user credential to create at the connector node a secure credential token that includes the user credential;

using the secure credential token to provide to the mobile application running on the mobile device, via the connector node, access to content on two or more servers in a manner that is consistent with privileges associated; and

providing metadata to the mobile device, wherein the mobile device is configured to provide access to the content based on one or more restrictions included in the metadata, wherein the metadata at least indicates a type of application that may access the content.

2. The method of claim 1 , wherein the user credential comprises a username and password.

3. The method of claim 1 , wherein the connector node is configured to authenticate a user with which the request access content, based at least in part on the user credential and a user directory associated with the protected network.

4. The method of claim 1 , wherein the connector node is configured to store the user credential in memory at the connector node.

5. The method of claim 4 , wherein the connector node is configured to associate the user credential as stored at the connector node with a session with which the request to access content is associated.

6. The method of claim 1 , wherein the secure credential token includes one or more of the following: the user credential; a device UUID of the mobile device; a date-time stamp indicating when token was created; and a duration through which the secure credential token is valid.

7. The method of claim 1 , wherein using the secure credential token to provide access to the mobile application on the mobile device includes providing the secure credential token to the mobile application on the mobile device.

8. The method of claim 1 , wherein using the secure credential token to provide access to the mobile application on the mobile device includes presenting the secure credential token to one or more of the two or more servers on behalf of the mobile application running on the mobile device.

9. The method of claim 1 , wherein the two or more servers are configured to use the secure credential token to determine an access privilege of a user with which the secure credential token is associated.

10. The method of claim 9 , wherein the access privilege is determined based at least in part on an access control list (ACL).

11. The method of claim 1 , wherein the type of application is a viewer application that prevents a user of the mobile device from editing the content.

12. The method of claim 1 , wherein the type of application is an editing application that allows a user of the mobile device to edit the content.

13. The method of claim 1 , wherein in the event the one or more restrictions included in the metadata indicates a user of the mobile device has read only rights associated with the content, the type of application with which the user of the mobile device is permitted to access the content is a viewer application that prevents the user of the mobile device from editing the content.

14. The method of claim 1 , wherein in the event the one or more restrictions included in the metadata indicates a user of the mobile device has read/write rights associated with the content, the type of application with which the user of the mobile device is permitted to access the content is an editing application that allows the user of the mobile device to edit the content.

15. A system to provide mobile access to content, comprising:

a communication interface; and

a hardware processor coupled to the communication interface and configured to:

receive at a connector node via the communication interface, from a mobile application running on a mobile device, a user credential associated with a request to access content;

use the user credential to create at the connector node a secure credential token that includes the user credential;

use the secure credential token to provide to the mobile application on the mobile device, via the connector node, access to content on two or more servers in a manner that is consistent with privileges associated; and

provide metadata to the mobile device, wherein the mobile device is configured to provide access to the content based on one or more restrictions included in the metadata, wherein the metadata at least indicates a type of application that may access the content.

16. The system of claim 15 , wherein the user credential comprises a username and password.

17. The system of claim 15 , wherein the connector node is configured to authenticate a user with which the request access content, based at least in part on the user credential and a user directory associated with the protected network.

18. The system of claim 15 , wherein the connector node is configured to store the user credential in memory at the connector node.

19. The system of claim 18 , wherein the connector node is configured to associate the user credential as stored at the connector node with a session with which the request to access content is associated.

20. The system of claim 15 , wherein the secure credential token includes one or more of the following: the user credential; a device UUID of the mobile device; a date-time stamp indicating when token was created; and a duration through which the secure credential token is valid.

21. The system of claim 15 , wherein using the secure credential token to provide access to the mobile application on the mobile device includes providing the secure credential token to the mobile application on the mobile device.

22. The system of claim 15 , wherein using the secure credential token to provide access to the mobile application on the mobile device includes presenting the secure credential token to one or more of the two or more servers on behalf of the mobile application running on the mobile device.

23. The system of claim 15 , wherein the two or more servers are configured to use the secure credential token to determine an access privilege of a user with which the secure credential token is associated.

24. A computer program product to provide mobile access to content, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving at a connector node, from a mobile application running on a mobile device, a user credential associated with a request to access content;

using the user credential to create at the connector node a secure credential token includes the user credential;

using the secure credential token to provide to the mobile application on the mobile device, via the connector node, access to content on two or more servers in a manner that is consistent with privileges associated; and

providing metadata to the mobile device, wherein the mobile device is configured to provide access to the content based on one or more restrictions included in the metadata, wherein the metadata at least indicates a type of application that may access the content.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED ON REEL 044344 FRAME 0027. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 2, 2018
From: TARALIKA, ANAND; CHALLA, DIVAKARA; KUMAR, SRIN; OJHA, ALOK; CHUNG, LEONARD
To: EMC CORPORATION
Reel/Frame 044980/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2017
From: TARALIKA, ANAND; CHALLA, DIVAKARA; KUMAR, SRIN; OJHA, ALOK; CHUNG, LEONARD
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 044344/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2017
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 044777/0557 →