IP Library › Granted Patent US 11,451,537
Granted Patent B2
US 11,451,537 · App. 16/848,961 · Granted Sep 20, 2022

Securing identity token forwarding

Inventor: Peter Eberlein (Malsch, DE)
Assignee: SAP SE
H04L63/0853H04L63/0823
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,451,537
App. No.
16/848,961
Granted
Sep 20, 2022
Kind
B2
Abstract

Methods, systems, and computer-readable storage media for receiving, from a first component and by a second component in a cloud platform, a call, a token, and a first client certificate, determining, by the second component, a first client identifier associated with the first component, and determining, by the second component, that the first client identifier is included in a manifest of the token, the manifest defining at least a portion of a communication path between components within the cloud platform, and in response: executing functionality responsive to the call.

Claims (37)

1. A computer-implemented method for secure access token forwarding between components in cloud platforms, the method being executed by one or more processors and comprising:

receiving, from a first component and by a second component in a cloud platform, a first call, a token, and a first client certificate; wherein the token provided to the first component in response to a request from the first component to a central identity and authentication service (IAS) of the cloud platform, and the first client certificate is provided during execution of a process to generate the token;

determining, by the second component, a first client identifier associated with the first component;

determining, by the second component, that the first client identifier is included in a manifest of the token, the manifest defining at least a portion of a communication path between components within the cloud platform, and in response:

executing functionality responsive to the first call;

receiving, from a third component and by the second component, a second call, the token, and a second client certificate;

determining, by the second component, a second client identifier associated with the third component; and

determining, by the second component, that the second client identifier is absent from the manifest of the token, and in response:

transmitting an error to the third component.

2. The method of claim 1 , wherein executing functionality responsive to the first call at least partially comprises transmitting, from the second component and to a third component, a second call with the token.

3. The method of claim 1 , wherein the token is received by the first component from a third component.

4. The method of claim 1 , wherein the token comprises an open authentication (OAuth) client comprising an audience field populated with the manifest, and the first client certificate comprises a X.509 client certificate.

5. A non-transitory computer-readable storage medium coupled to one or more processors and having instructions stored thereon which, when executed by the one or more processors, cause the one or more processors to perform operations for secure access token forwarding between components in cloud platforms, the operations comprising:

receiving, from a first component and by a second component in a cloud platform, a first call, a token, and a first client certificate; wherein the token provided to the first component in response to a request from the first component to a central identity and authentication service (IAS) of the cloud platform, and the first client certificate is provided during execution of a process to generate the token;

determining, by the second component, a first client identifier associated with the first component;

determining, by the second component, that the first client identifier is included in a manifest of the token, the manifest defining at least a portion of a communication path between components within the cloud platform, and in response:

executing functionality responsive to the first call;

receiving, from a third component and by the second component, a second call, the token, and a second client certificate;

determining, by the second component, a second client identifier associated with the third component; and

determining, by the second component, that the second client identifier is absent from the manifest of the token, and in response:

transmitting an error to the third component.

6. The computer-readable storage medium of claim 5 , wherein executing functionality responsive to the first call at least partially comprises transmitting, from the second component and to a third component, a second call with the token.

7. The computer-readable storage medium of claim 5 , wherein the token is received by the first component from a third component.

8. The computer-readable storage medium of claim 5 , wherein the token comprises an open authentication (OAuth) client comprising an audience field populated with the manifest, and the first client certificate comprises a X.509 client certificate.

9. A system, comprising:

a computing device; and

a computer-readable storage device coupled to the computing device and having instructions stored thereon which, when executed by the computing device, cause the computing device to perform operations for natural language explanations for secure access token forwarding between components in cloud platforms, the operations comprising:

receiving, from a first component and by a second component in a cloud platform, a first call, a token, and a first client certificate; wherein the token provided to the first component in response to a request from the first component to a central identity and authentication service (IAS) of the cloud platform, and the first client certificate is provided during execution of a process to generate the token;

determining, by the second component, a first client identifier associated with the first component;

determining, by the second component, that the first client identifier is included in a manifest of the token, the manifest defining at least a portion of a communication path between components within the cloud platform, and in response:

executing functionality responsive to the first call;

receiving, from a third component and by the second component, a second call, the token, and a second client certificate;

determining, by the second component, a second client identifier associated with the third component; and

determining, by the second component, that the second client identifier is absent from the manifest of the token, and in response:

transmitting an error to the third component.

10. The system of claim 9 , wherein executing functionality responsive to the first call at least partially comprises transmitting, from the second component and to a third component, a second call with the token.

11. The system of claim 9 , wherein the token is received by the first component from a third component.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2020
From: EBERLEIN, PETER
To: SAP SE
Reel/Frame 052407/0131 →
Continuity (1)
Related Publication 20210328980A1 · Oct 21, 2021
Cited By (3)
US 12,499,116 US 12,541,616 US 12,689,626