IP Library Granted Patent US 10,432,635
Granted Patent B2
US 10,432,635 · App. 16/042,983 · Granted Oct 1, 2019

Inter-application management of user credential data

Inventors: John Simone (San Francisco, CA); Fiaz Hossain (San Francisco, CA)
Assignee: salesforce.com, inc.
H04L63/10G06F8/20G06F16/951G06F21/41H04L63/08H04L67/42H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,432,635
App. No.
16/042,983
Granted
Oct 1, 2019
Kind
B2
Abstract

A system and apparatus for enhancing the functionality and utility of an authentication process for web applications is disclosed.

Claims (28)

1. A method, comprising:

providing, with a hardware computing device, at least one of two security framework configurations, wherein a first configuration utilizes a cookie and a second configuration utilizes server-side storage;

performing user authorization, with the hardware computing device, using at least one of the two security framework configurations, wherein performing the user authorization with the server-side storage includes storing developer-defined user information (DDUI) in a shared session cache;

wherein either the user is recognized because a cookie or a session context containing a security token was provided, or the user is not recognized and diverted to a security handshake, or a token request is utilized to obtain a session identifier, API endpoint and authentication token;

wherein when using the server-side storage, the hardware computing device is configured to not write locally to an application memory, but instead to access a shared session cache, where each of a plurality of servers are to be given access to a specific session cache; and

wherein performing the user authorization is done through a client web application executed by a hardware computing device to allow access to an on-demand database service.

2. The method of claim 1 , wherein a security framework to provide the at least one of two security framework configurations comprises a plurality of generic servlet filters and spring security filters.

3. The method of claim 1 , further comprising a generic servlet filter performs OAuth flow and routes the user to the login page.

4. The method of claim 3 , wherein the generic servlet filter is used within servlet-based web applications that operate without using any specific security framework.

5. The method of claim 1 , further comprising:

facilitating a choice between storing user data in browser cookies or server side sessions, thereby resulting in application instances being completely stateless.

6. A multi-tenant database system, comprising:

a group of hardware computing devices providing a database system to store data for each of multiple tenants;

an application server communicably coupled to the database system and to a network, the application server to provide at least one of two security framework configurations, wherein a first configuration utilizes a cookie and a second configuration utilizes server-side storage, to perform user authorization using at least one of the two security framework configurations, wherein performing the user authorization with the server-side storage includes storing developer-defined user information (DDUI) in a shared session cache, wherein either the user is recognized because a cookie or a session context containing a security token was provided, or the user is not recognized and diverted to a security handshake, or a token request is utilized to obtain a session identifier, API endpoint and authentication token, wherein when using the server-side storage, the hardware computing device is configured to not write locally to an application memory, but instead to access a shared session cache, where each of a plurality of servers are to be given access to a specific session cache, and wherein performing the user authorization is done through a client web application executed by a hardware computing device to allow access to an on-demand database service.

7. The multi-tenant database system of claim 6 , wherein a security framework to provide the at least one of two security framework configurations comprises a plurality of generic servlet filters and spring security filters.

8. The multi-tenant database system of claim 6 , further comprising a generic servlet filter performs OAuth flow and routes the user to the login page.

9. The multi-tenant database system of claim 8 , wherein the generic servlet filter is used within servlet-based web applications that operate without using any specific security framework.

10. The multi-tenant database system of claim 6 , further comprising:

facilitating a choice between storing user data in browser cookies or server side sessions, thereby resulting in application instances being completely stateless.

11. A non-transitory machine-readable medium carrying one or more sequences of instructions for implementing a method for providing an interface for object relationships, comprising:

performing user authorization, with the hardware computing device, using at least one of the two security framework configurations, wherein performing the user authorization with the server-side storage includes storing developer-defined user information (DDUI) in a shared session cache;

wherein either the user is recognized because a cookie or a session context containing a security token was provided, or the user is not recognized and diverted to a security handshake, or a token request is utilized to obtain a session identifier, API endpoint and authentication token;

wherein when using the server-side storage, the hardware computing device is configured to not write locally to an application memory, but instead to access a shared session cache, where each of a plurality of servers are to be given access to a specific session cache; and

wherein performing the user authorization is done through a client web application executed by a hardware computing device to allow access to an on-demand database service.

12. The non-transitory machine-readable medium of claim 11 , wherein a security framework to provide the at least one of two security framework configurations comprises a plurality of generic servlet filters and spring security filters.

13. The non-transitory machine-readable medium of claim 11 , wherein a generic servlet filter performs OAuth flow and routes the user to the login page.

14. The non-transitory machine-readable medium of claim 13 , wherein the generic servlet filter is used within servlet-based web applications that operate without using any specific security framework.

15. The method of claim 11 , further comprising: facilitating a choice between storing user data in browser cookies or server side sessions, thereby resulting in application instances being completely stateless.

Assignments (2)
CHANGE OF NAME Recorded Dec 18, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069717/0353 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2018
From: SIMONE, JOHN; HOSSAIN, FIAZ
To: SALESFORCE.COM, INC.
Reel/Frame 046827/0410 →
Continuity (4)
Continuation 15197728 · Jun 29, 2016
Continuation 13178511 · Jul 8, 2011
Provisional Application 61474538 · Apr 12, 2011
Related Publication 20190089707A1 · Mar 21, 2019
Cited By (2)
US 12,495,035 US 12,549,555