IP Library Granted Patent US 11,588,806
Granted Patent B2
US 11,588,806 · App. 17/106,878 · Granted Feb 21, 2023

Authentication service

Inventors: David Shaw (Buford, GA); Daniel E. Zeck (Roswell, GA); Robert Worsnop (Dunwoody, GA)
Assignee: VMware, Inc.
H04L63/0815H04L9/0894H04L9/3213H04L9/3228H04L43/10H04L63/0807H04L67/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,588,806
App. No.
17/106,878
Granted
Feb 21, 2023
Kind
B2
Abstract

Disclosed are various approaches for relaying and caching authentication credentials. A single sign-on (SSO) token is received, the SSO token representing a user account authenticated with an identity manager. An authentication request is then sent to a service that is federated with the identity manager in response to receipt of the SSO token, the authentication request including the SSO token. An access token is received in response to the authentication request, the access token providing access to the service for the user account authenticated with the identity manager for a predefined period of time. The access token and a link between the access token and the SSO token are then cached.

Claims (43)

1. A system for relaying authentication credentials, comprising:

a computing device comprising a processor and a memory; and

machine-readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

send an authentication request to a federated service, the authentication request comprising an SSO token associated with a user account;

receive an access token, the access token providing access to the federated service for the user account;

receive a request for the access token from a polling service executing on the computing device, the access token being cached in a data store of the computing device; and

provide the access token to the polling service.

2. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least:

receive a refresh token together with the access token;

send the refresh token to the federated service in response to an expiration of the access token; and

receive a second access token, the second access token providing access to the federated service for the user account.

3. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least determine whether the request for the access token is valid based at least in part on whether the polling service is authorized to access the access token.

4. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least determine that a user associated with the user account is authorized to access the federated service based at least in part on one or more access permissions.

5. The system of claim 1 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least receive the SSO token and an identifier corresponding to the user account.

6. The system of claim 1 , wherein the request for the access token comprises a user identifier corresponding to the user account.

7. The system of claim 1 , wherein the request for the access token comprises an identifier corresponding to the federated service.

8. A method for relaying authentication credentials, comprising:

sending, by a computing device, an authentication request to a federated service, the authentication request comprising an SSO token associated with a user account;

receiving, by the computing device, an access token, the access token providing access to the federated service for the user account;

receiving, by the computing device, a request for the access token from a polling service executing on the computing device, the access token being cached in a data store of the computing device; and

providing, by the computing device, the access token to the polling service.

9. The method of claim 8 , further comprising:

receiving, by the computing device, a refresh token together with the access token;

sending, by the computing device, the refresh token to the federated service in response to an expiration of the access token; and

receiving, by the computing device, a second access token, the second access token providing access to the federated service for the user account.

10. The method of claim 8 , further comprising determining, by the computing device, whether the request for the access token is valid based at least in part on whether the polling service is authorized to access the access token.

11. The method of claim 8 , further comprising determining, by the computing device, that a user associated with the user account is authorized to access the federated service based at least in part on one or more access permissions.

12. The method of claim 8 , further comprising receiving, by the computing device, the SSO token and an identifier corresponding to the user account.

13. The method of claim 8 , wherein the request for the access token comprises a user identifier corresponding to the user account.

14. The method of claim 8 , wherein the request for the access token comprises an identifier corresponding to the federated service.

15. A non-transitory computer-readable medium for relaying authentication credentials, the non-transitory computer-readable medium comprising machine-readable instructions that, when executed by a processor, cause a computing device to at least:

send an authentication request to a federated service, the authentication request comprising an SSO token associated with a user account;

receive an access token, the access token providing access to the federated service for the user account;

receive a request for the access token from a polling service executing on the computing device, the access token being cached in a data store of the computing device; and

provide the access token to the polling service.

16. The non-transitory computer-readable medium of claim 15 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least:

receive a refresh token together with the access token;

send the refresh token to the federated service in response to an expiration of the access token; and

receive a second access token, the second access token providing access to the federated service for the user account.

17. The non-transitory computer-readable medium of claim 15 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least determine whether the request for the access token is valid based at least in part whether the polling service is authorized to access the access token.

18. The non-transitory computer-readable medium of claim 15 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least determine that a user associated with the user account is authorized to access the federated service based at least in part on one or more access permissions.

19. The non-transitory computer-readable medium of claim 15 , wherein the machine-readable instructions, when executed by the processor, further cause the computing device to at least receive the SSO token and an identifier corresponding to the user account.

20. The non-transitory computer-readable medium of claim 15 , wherein the request for the access token comprises at least one of a user identifier corresponding to the user account and an identifier corresponding to the federated service.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
Continuity (2)
Continuation 15970020 · May 3, 2018
Related Publication 20210084026A1 · Mar 18, 2021