IP Library Granted Patent US 10,868,811
Granted Patent B2
US 10,868,811 · App. 16/181,146 · Granted Dec 15, 2020

Secure user credential access system

Inventors: Anurag Kahol (Los Gatos, CA); Anoop Kumar Bhattacharjya (Campbell, CA); Balas Natarajan Kausik (Los Gatos, CA)
Assignee: Bitglass, Inc.
H04L63/0869G06F16/958G06F21/305G06F21/602G06F21/6227H04L41/0893H04L63/0428H04L63/0471H04L63/08H04L63/0823H04L63/0884G06F2221/2107G06F2221/2115H04L63/0272H04L63/0281H04L63/105H04L67/28
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,868,811
App. No.
16/181,146
Granted
Dec 15, 2020
Kind
B2
Abstract

A proxy server mitigates security risks of user credentials sent across a network in clear text. The proxy server encrypts user credentials within a client application request destined for an application server. The proxy server forwards the client application request to the application server. The application server sends the encrypted user credentials to the proxy server where the proxy server decrypts the user credentials and authenticates the user credentials with an authentication server.

Claims (53)

1. A method of operation of a proxy server, comprising:

receiving a third-party application access request and authentication credentials from a corporate client device, the third-party application residing on an application server hosted by a third-party, the application server configured to validate authentication credentials at the proxy server;

encrypting the authentication credentials, the encrypted authentication credentials are encrypted such that the encrypted authentication credentials are only decryptable by the proxy server;

sending the encrypted authentication credentials and the third-party application access request to the application server;

receiving the encrypted authentication credentials back from the application server in an authentication request;

validating decrypted authentication credentials against a corporate directory; and

sending the application server results of validating the decrypted authentication credentials.

2. The method as recited in claim 1 , wherein the application access request requests access to a resource managed by the application server.

3. The method as recited in claim 1 , wherein the application access request requests access to application specific data stored on the application server.

4. The method as recited in claim 1 , wherein prior to the encrypting the authentication credentials:

receiving a digitally signed certificate from the corporate client device;

validating the digitally signed certificate by using a public key of the corporate client device to decrypt the digitally signed certificate;

upon successful decryption of the digitally signed certificate, performing the encrypting the authentication credentials.

5. The method as recited in claim 1 , wherein the authentication credentials from the corporate client device are received in clear-text.

6. The method as recited in claim 1 , further comprising:

receiving a response to the results of validating the decrypted authentication credentials from the application server;

forwarding the response to the corporate client device.

7. One or more non-transitory computer-readable storage media, storing one or more sequences of instructions for operation of a proxy server, which when executed by one or more processors cause performance of:

receiving a third-party application access request and authentication credentials from a corporate client device, the third-party application residing on an application server hosted by a third-party, the application server configured to validate authentication credentials at the proxy server;

encrypting the authentication credentials, the encrypted authentication credentials are encrypted such that the encrypted authentication credentials are only decryptable by the proxy server;

sending the encrypted authentication credentials and the third-party application access request to the application server;

receiving the encrypted authentication credentials back from the application server in an authentication request;

validating decrypted authentication credentials against a corporate directory; and

sending the application server results of validating the decrypted authentication credentials.

8. The one or more non-transitory computer-readable storage media as recited in claim 7 , wherein the application access request requests access to a resource managed by the application server.

9. The one or more non-transitory computer-readable storage media as recited in claim 7 , wherein the application access request requests access to application specific data stored on the application server.

10. The one or more non-transitory computer-readable storage media as recited in claim 7 , wherein prior to the encrypting the authentication credentials:

receiving a digitally signed certificate from the corporate client device;

validating the digitally signed certificate by using a public key of the corporate client device to decrypt the digitally signed certificate;

upon successful decryption of the digitally signed certificate, performing the encrypting the authentication credentials.

11. The one or more non-transitory computer-readable storage media as recited in claim 7 , wherein the authentication credentials from the corporate client device are received in clear-text.

12. The one or more non-transitory computer-readable storage media as recited in claim 7 , wherein the one or more sequences of instructions, which when executed by the one or more processors cause further performance of:

receiving a response to the results of validating the decrypted authentication credentials from the application server;

forwarding the response to the corporate client device.

13. A proxy server, comprising:

one or more processors; and

a memory storing instructions, which when executed by the one or more processors, cause the one or more processors to:

receive a third-party application access request and authentication credentials from a corporate client device, the third-party application residing on an application server hosted by a third-party, the application server configured to validate authentication credentials at the proxy server;

encrypt the authentication credentials, the encrypted authentication credentials are encrypted such that the encrypted authentication credentials are only decryptable by the proxy server;

send the encrypted authentication credentials and the third-party application access request to the application server;

receive the encrypted authentication credentials back from the application server in an authentication request;

validate decrypted authentication credentials against a corporate directory; and

send the application server results of validating the decrypted authentication credentials.

14. The proxy server as recited in claim 13 , wherein the application access request requests access to a resource managed by the application server.

15. The proxy server as recited in claim 13 , wherein the application access request requests access to application specific data stored on the application server.

16. The proxy server as recited in claim 13 , wherein prior to the encrypting the authentication credentials:

receive a digitally signed certificate from the corporate client device;

validate the digitally signed certificate by using a public key of the corporate client device to decrypt the digitally signed certificate;

upon successful decryption of the digitally signed certificate, performing the encrypting the authentication credentials.

17. The proxy server as recited in claim 13 , wherein the authentication credentials from the corporate client device are received in clear-text.

18. The proxy server as recited in claim 13 , further comprising:

receive a response to the results of validating the decrypted authentication credentials from the application server;

forward the response to the corporate client device.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
PATENT SECURITY AGREEMENT Recorded Dec 14, 2021
From: BITGLASS, LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 058514/0547 →
CONVERSION FROM A CORPORATION TO A LIMITED LIABILITY COMPANY Recorded Nov 30, 2021
From: BITGLASS, INC.
To: BITGLASS, LLC
Reel/Frame 058919/0164 →
CERTIFICATE OF FORMATION Recorded Nov 22, 2021
From: DEVINE, KIM
To: BITGLASS, LLC
Reel/Frame 058220/0740 →
MERGER Recorded Nov 18, 2021
From: DAYTONA BOBCAT, INC.
To: BITGLASS, INC.
Reel/Frame 058150/0247 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2020
From: KAHOL, ANURAG; BHATTACHARJYA, ANOOP KUMAR; KAUSIK, BALAS NATARAJAN
To: BITGLASS, INC.
Reel/Frame 053537/0244 →
Cited By (1)
US 12,556,536