IP Library Granted Patent US 11,153,296
Granted Patent B2
US 11,153,296 · App. 16/671,820 · Granted Oct 19, 2021

Privacy-aware ID gateway

Inventors: Miki Ishikawa (Kanagawa-ken, JP); Yuji Watanabe (Tokyo, JP)
Assignee: International Business Machines Corporation
H04L63/0815H04L63/102G06F21/30G06F21/31G06F21/41G06F21/445
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,296
App. No.
16/671,820
Granted
Oct 19, 2021
Kind
B2
Abstract

A method includes, for a first user having been authenticated on a first application with a first user identification (ID) using a first ID federation between the first application and a federation server, determining that the first user is authorized to access information of a second user on a second application based on the first user ID, the second user being associated with a second user ID, and sending a second authentication request for authenticating the first user to the second application with the second user ID using a second ID federation between the federation server and the second application.

Claims (46)

1. A method comprising:

for a first user having been authenticated on a first application with a first user identification (ID) using a first ID federation between the first application and a federation server, determining that the first user is authorized to access information of a second user on a second application based on the first user ID, the second user being different from the first user and being associated with a second user ID obtained based on the first user ID; and

sending a second authentication request for authenticating the first user to the second application with the second user ID using a second ID federation between the federation server and the second application.

2. The method according to claim 1 , wherein:

receiving the first authentication request further includes receiving an identification of the second application with the first authentication request; and

sending the second authentication request further includes sending authority information of the first user ID.

3. The method according to claim 1 , wherein the first user ID includes at least one of a user ID of the first user, and an identification of the first application.

4. The method according to claim 1 , wherein determining that the first user is authorized to access the information on the second user further includes:

obtaining condition information defining a condition; and

determining that the first user ID, the second application, and the second user ID satisfy the condition.

5. The method according to claim 4 , wherein the condition information includes at least one of a time when the information of the second user ID is recorded on the second application, and a record of the information of the second user ID on the second application.

6. The method according to claim 4 , further comprising:

receiving an authorization of the second user from a client computer of the second user; and

updating the condition information to reflect the authorization of the second user.

7. The method according to claim 6 , wherein the first authentication request is received from the first application.

8. The method according to claim 1 , further comprising receiving an authorization of the second user from the first application.

9. The method according to claim 8 , wherein the authorization of the second user includes a password input by the second user.

10. A method comprising:

receiving, from a first application, a first authentication request for authenticating a first user, the first user having been authenticated on the first application with a first user identification (ID) using a first ID federation between the first application and a federation server;

determining that the first user is authorized to access information of a second user on a second application based on the first user ID, the second user being different from the first user and being associated with a second user ID obtained based on the first user ID; and

sending a second authentication request for authenticating the first user to the second application with the second user ID using a second ID federation between the federation server and the second application.

11. The method according to claim 10 , wherein:

receiving the first authentication request further includes receiving an identification of the second application with the first authentication request; and

sending the second authentication request further includes sending authority information of the first user ID.

12. The method according to claim 10 , wherein the first user ID includes at least one of a user ID of the first user, and an identification of the first application.

13. The method according to claim 10 , wherein determining that the first user is authorized to access the information on the second user further includes:

obtaining condition information defining a condition; and

determining that the first user ID, the second application, and the second user ID satisfy the condition.

14. The method according to claim 13 , wherein the condition information includes at least one of a time when the information of the second user ID is recorded on the second application, and a record of the information of the second user ID on the second application.

15. The method according to claim 13 , further comprising:

receiving an authorization of the second user including a password input by the second user, the authorization being received from a client computer of the second user or the first application; and

updating the condition information to reflect the authorization of the second user.

16. A method comprising:

receiving, from a first application, a first authentication request for authenticating a first user, the first user having been authenticated on the first application with a first user identification (ID) using a first ID federation between the first application and a federation server;

determining that the first user is authorized to access information of a second user on a second application based on the first user ID, the second user being different from the first user and being associated with a second user ID obtained based on the first user ID, including:

obtaining condition information defining a condition; and

determining that the first user ID, the second application and the second user ID satisfy the condition; and

sending a second authentication request for authenticating the first user to the second application with the second user ID using a second ID federation between the federation server and the second application.

17. The method according to claim 16 , wherein:

receiving the first authentication request further includes receiving an identification of the second application with the first authentication request; and

sending the second authentication request further includes sending authority information of the first user ID.

18. The method according to claim 16 , wherein the first user ID includes at least one of a user ID of the first user, and an identification of the first application.

19. The method according to claim 16 , wherein the condition information includes at least one of a time when the information of the second user ID is recorded on the second application, and a record of the information of the second user ID on the second application.

20. The method according to claim 16 , further comprising:

receiving an authorization of the second user including a password input by the second user, the authorization being received from a client computer of the second user or the first application; and

updating the condition information to reflect the authorization of the second user.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2022
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GREEN MARKET SQUARE LIMITED
Reel/Frame 058888/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2019
From: ISHIKAWA, MIKI; WATANABE, YUJI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 050892/0188 →