IP Library Granted Patent US 10,282,522
Granted Patent B2
US 10,282,522 · App. 16/031,363 · Granted May 7, 2019

Cross-application authentication on a content management system

Inventors: Sang Tian (San Francisco, CA); Joshua Kaplan (San Francisco, CA); Devdatta Akhawe (Berkeley, CA)
Assignee: Dropbox, Inc.
G06F21/10G06F16/00G06F16/955G06F21/00H04L61/303H04L63/0236H04L63/08G06F2221/2101H04L63/1483H04L63/168H04L67/02H04L67/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,282,522
App. No.
16/031,363
Granted
May 7, 2019
Kind
B2
Abstract

Systems, methods, and computer-readable media for cross-application authentication on a content management system. A client application running at a client device that is not authenticated with a content management system can receive, from a website associated with the content management system, a request to authenticate with the content management system under a user account used to authenticate a current session between a browser application at the client device and the website with the content management system. The client application can then obtain a uniform resource locator (URL) with a nonce associated with the client application, and send a command to the browser application including the URL and nonce. The command can trigger the browser application to use the URL and nonce to authenticate the client application with the content management system under the user account with which the current session between the browser application and the website is currently authenticated.

Claims (40)

1. A method comprising:

establishing a communication channel through a content management system, between a client application at a client device and a website associated with the content management system, wherein establishing the communication channel comprises:

sending, from the client application to the content management system, a message comprising a nonce that identifies an association between the client application and at least one of a browser application at the client device or a user account used by the client application to authenticate with the content management system, wherein the association enables the content management system to relay one or more communications between the client application and the website;

when the browser application at the client device is not authenticated with the content management system, receiving, by the client application from the content management system via the communication channel, a request for the user account used by the client application to authenticate with the content management system;

receiving, by the client application, an instruction to authenticate the browser application with the content management system under the user account; and

sending, from the client application to the browser application, a command instructing the browser application to open a web page to verify the browser application is associated with the client device at the content management system, wherein the browser application is authenticated with the content management system under the user account via a communication session between the browser application and the website.

2. The method of claim 1 , further comprising:

after sending the message to the content management system, obtaining, by the client application from the content management system, a uniform resource locator (URL) associated with the web page, wherein the command triggers the browser application to use the URL and the nonce to authenticate with the content management system.

3. The method of claim 2 , wherein the command triggers a script associated with the web page, wherein the script is configured to instruct the content management system to authenticate the browser application based on the nonce and validate a session associated with the browser application under the user account based on credentials used to authenticate a current session between the client application and the content management system.

4. The method of claim 1 , wherein the command comprises an operating system (OS) command.

5. The method of claim 1 , wherein the nonce is associated with a client identifier at the content management system, the client identifier being associated with at least one of the client application or the browser application.

6. The method of claim 1 , wherein the request for the user account used by the client application to authenticate with the content management system is received by the client application from the website via the communication channel.

7. The method of claim 1 , wherein the web page comprises a local web page file on the client device generated by the client application.

8. A system comprising:

one or more processors; and

at least one computer-readable medium storing computer-readable instructions that, when executed by the one or more processors, cause the system to:

establish a communication channel through a content management system, between a client application at a client device and a website associated with the content management system, wherein establishing the communication channel comprises:

sending, from the client application to the content management system, a message comprising a nonce that identifies an association between the client application and at least one of a browser application at the client device or a user account used by the client application to authenticate with the content management system, wherein the association enables the content management system to relay one or more communications between the client application and the website;

when the browser application at the client device is not authenticated with the content management system, receive, by the client application from the content management system via the communication channel, a request for the user account used by the client application to authenticate with the content management system;

receive, by the client application, an instruction to authenticate the browser application with the content management system under the user account; and

send, from the client application to the browser application, a command instructing the browser application to open a web page to verify the browser application is associated with the client device at the content management system, wherein the browser application is authenticated with the content management system under the user account via a communication session between the browser application and the website.

9. The system of claim 8 , the at least one computer-readable medium storing computer-readable instructions that, when executed by the one or more processors, cause the system to: obtain, by the client application from the content management system, a uniform resource locator (URL) associated with the web page, wherein the command triggers the browser application to use the URL and the nonce to authenticate with the content management system.

10. The system of claim 9 , wherein the command triggers a script associated with the web page, wherein the script is configured to instruct the content management system to authenticate the browser application based on the nonce and validate a session associated with the browser application under the user account based on credentials used to authenticate a current session between the client application and the content management system.

11. The system of claim 8 , wherein the nonce is associated with a client identifier at the content management system, the client identifier being associated with the client application.

12. The system of claim 8 , wherein the command comprises an operating system (OS) command.

13. The system of claim 8 , wherein the request for the user account used by the client application to authenticate with the content management system is received by the client application from the website via the communication channel.

14. The system of claim 8 , wherein the web page comprises a local web page file on the client device generated by the client application.

15. A non-transitory computer-readable storage medium comprising:

computer-readable instructions stored thereon, wherein the computer-readable instructions, when executed by one or more processors, cause the one or more processors to:

establish a communication channel through a content management system, between a client application at a client device and a website associated with the content management system, wherein establishing the communication channel comprises:

sending, from the client application to the content management system, a message comprising a nonce that identifies an association between the client application and at least one of a browser application at the client device or a user account used by the client application to authenticate with the content management system, wherein the association enables the content management system to relay one or more communications between the client application and the website;

when the browser application at the client device is not authenticated with the content management system, receive, by the client application from the content management system via the communication channel, a request for the user account used by the client application to authenticate with the content management system;

receive, by the client application, an instruction to authenticate the browser application with the content management system under the user account; and

send, from the client application to the browser application, a command instructing the browser application to open a web page to verify the browser application is associated with the client device at the content management system, wherein the browser application is authenticated with the content management system under the user account via a communication session between the browser application and the website.

16. The non-transitory computer-readable storage medium of claim 15 , storing additional computer-readable instructions that when executed by the one or more processors, cause the one or more processors to:

obtain, by the client application from the content management system, a uniform resource locator (URL) associated with the web page, wherein the command triggers the browser application to use the URL and the nonce to authenticate with the content management system.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the command triggers a script associated with the web page, wherein the script is configured to instruct the content management system to authenticate the browser application based on the nonce and validate a session associated with the browser application under the user account based on credentials used to authenticate a current session between the client application and the content management system.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the nonce is associated with a client identifier at the content management system, the client identifier being associated with the client application.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the web page comprises a local web page file on the client device generated by the client application.

20. The non-transitory computer-readable storage medium of claim 15 , wherein the request for the user account used by the client application to authenticate with the content management system is received by the client application from the website via the communication channel.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: DROPBOX, INC.
Reel/Frame 069635/0332 →
SECURITY INTEREST Recorded Dec 12, 2024
From: DROPBOX, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069604/0611 →
PATENT SECURITY AGREEMENT Recorded Mar 10, 2021
From: DROPBOX, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 055670/0219 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2018
From: TIAN, SANG; KAPLAN, JOSHUA; AKHAWE, DEVDATTA
To: DROPBOX, INC.
Reel/Frame 046307/0529 →
Continuity (3)
Continuation 14985072 · Dec 30, 2015
Continuation In Part 14634008 · Feb 27, 2015
Related Publication 20180322258A1 · Nov 8, 2018