IP Library Granted Patent US 11,265,304
Granted Patent B2
US 11,265,304 · App. 16/432,086 · Granted Mar 1, 2022

Seamless authentication for an application development platform

Inventor: Matthew D. Wood (Leeds, GB)
Assignee: FinancialForce.com, Inc.
H04L63/08G06F8/30G06F21/44G06Q50/01H04L63/0815H04L63/166H04L67/02H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,265,304
App. No.
16/432,086
Granted
Mar 1, 2022
Kind
B2
Abstract

Various embodiments concern mechanisms for facilitating communication between network-accessible platforms for developing, hosting, or running hybrid applications that utilize resources hosted across multiple platforms. Hybrid applications cause messages or “calls” to be passed between the platforms that must be authenticated. For example, when a call is placed by a Heroku platform to a Force.com platform, the call must be authenticated for security purposes. If Heroku has not already been authenticated when the call is submitted, an authentication process is invoked. An event listener can be used to register details regarding the initial callout task, and then register or “fire” an event when the authentication process is successfully completed. Registration of the initial callout task completely separates the authentication process from the resource being invoked. Requests can be completed without requiring further user input using at least some of the details registered by the event listener.

Claims (45)

1. A computer-implemented method comprising:

receiving, by a development platform, a call from an application for a resource hosted by an external service accessible to the development platform across a network;

registering, by the development platform, information regarding the call using an event listener;

determining, by the development platform, that the external service is not a registered client of the development platform;

passing, by the development platform, at least some of the information regarding the call through an authentication process;

causing, by the development platform, the event listener to register an event when the authentication process is successfully completed; and

completing, by the development platform; the call for the resource using the information registered by the event listener.

2. The computer-implemented method of claim 1 , wherein the call is placed in accordance with the Hypertext Transfer Protocol (HTTP).

3. The computer-implemented method of claim 1 , wherein the event listener is programmed in Java.

4. The computer-implemented method of claim 1 , wherein the external service is a Force.com platform, and wherein the authentication process is an OAuth 2.0 web server authentication process facilitated by the Force.com platform.

5. The computer-implemented method of claim 1 , wherein the resource is data hosted by the external service or a process to be executed by the external service.

6. The computer-implemented method of claim 1 , wherein the information includes a description of the resource, a username, an identifier that identifies the application responsible for placing the call, or any combination thereof.

7. The computer-implemented method of claim 6 , wherein the at least some information passed through the authentication process includes the username, the identifier, or both.

8. The computer-implemented method of claim 1 , further comprising:

receiving, by the development platform from the external service, an address of an application programming interface (API) to be used for making subsequent calls to the external service.

9. The computer-implemented method of claim 8 , wherein the API allows the development platform to gain programmatic access to resources of the external service without further authentication.

10. The computer-implemented method of claim 8 , wherein the subsequent calls are made directly by the development platform to the API.

11. A computer-implemented method comprising:

receiving, by a development platform, a call from an application for a resource hosted by a service accessible to the development platform across a network;

determining, by the development platform, that the service is not a registered client of the development platform;

passing, by the development platform, information regarding the call through an authentication process;

causing, by the development platform, an event listener to register an event when the authentication process is successfully completed; and

completing, by the development platform in response to the event being registered, the call for the resource.

12. The computer-implemented method of claim 11 , further comprising: registering, by the development platform, the information regarding the call using the event listener.

13. The computer-implemented method of claim 12 , wherein said completing is performed using the information registered by the event listener.

14. The computer-implemented method of claim 11 , wherein the call is completed responsive to the event being registered without requiring further input from the application.

15. The computer-implemented method of claim 12 , wherein said registering causes the authentication process to be performed by the development platform independent of handling the call for the resource.

16. The computer-implemented method of claim 11 , further comprising:

receiving, by the development platform, a token from the service in response to successfully completing the authentication process; and

using, by the development platform, the token to make a subsequent call to the service without further authentication.

17. The computer-implemented method of claim 11 , further comprising:

receiving, by the development platform from the service, an address of an application programming interface (API) to be used for making subsequent calls to the external service.

18. The computer-implemented method of claim 17 , wherein the API allows the development platform to gain programmatic access to resources of the service without further authentication.

19. A non-transitory computer-readable medium with instructions stored thereon that, when executed, cause a development platform to perform operations comprising:

receiving a call from an application for a resource hosted by a service accessible to the development platform across a network;

determining that the service is not a registered client of the development platform;

passing information regarding the call through an authentication process;

receiving a token from the service in response to the authentication process being successfully completed; and

completing the call for the resource using the token provided by the service.

20. A non-transitory computer-readable medium with instructions stored thereon that, when executed, cause a development platform to perform operations comprising:

receiving a call from an application for a resource hosted by a service accessible to the development platform across a network;

determining that the service is not a registered client of the development platform;

passing information regarding the call through an authentication process;

receiving an address for an application programming interface (API) from the service in response to the authentication process being successfully completed; and

completing the call for the resource using the address for the API provided by the service.

Assignments (8)
CHANGE OF ADDRESS Recorded Sep 12, 2024
From: CERTINIA INC.
To: CERTINIA INC.
Reel/Frame 068948/0361 →
SECURITY INTEREST Recorded Aug 7, 2023
From: CERTINIA INC.
To: BLUE OWL CREDIT INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 064510/0495 →
RELEASE OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Aug 4, 2023
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: CERTINIA, INC.
Reel/Frame 064502/0117 →
CHANGE OF NAME Recorded Jun 20, 2023
From: FINANCIALFORCE.COM, INC.
To: CERTINIA INC.
Reel/Frame 064042/0206 →
RELEASE OF SECURITY INTEREST Recorded Mar 24, 2022
From: OBSIDIAN AGENCY SERVICES, INC.
To: FINANCIALFORCE.COM, INC.
Reel/Frame 059389/0501 →
SECURITY INTEREST Recorded Feb 21, 2022
From: FINANCIALFORCE.COM, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 059204/0323 →
SECURITY INTEREST Recorded Jul 15, 2021
From: FINANCIALFORCE.COM, INC.
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 056872/0236 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2019
From: WOOD, MATTHEW D
To: FINANCIALFORCE.COM, INC.
Reel/Frame 050279/0879 →
Continuity (3)
Continuation 15869451 · Jan 12, 2018
Continuation 15189218 · Jun 22, 2016
Related Publication 20190288994A1 · Sep 19, 2019
Cited By (1)
US 12,399,877