IP Library › Granted Patent US 11,509,641
Granted Patent B2
US 11,509,641 · App. 17/146,255 · Granted Nov 22, 2022

Accessing client credential sets using a key

Inventors: Kyle Edward Heldman (Greenwood, IN); Douglas Christopher Wilson (Indianapolis, IN); Jackson Gregory Reed (Indianapolis, IN); Kyle Warren Apple (Fishers, IN); Jacob Andrew Richwine (Richmond, IN)
Assignee: salesforce.com, inc.
H04L63/062G06F8/61G06F9/547G06F21/41G06Q10/06G06Q10/06316H04L63/0815H04L63/0876H04L65/1063H04W12/084
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,641
App. No.
17/146,255
Granted
Nov 22, 2022
Kind
B2
Abstract

Techniques are disclosed relating to a computer system accessing a client credential set to authenticate with a destination computer system. A computer system may, subsequent to receiving an indication to make available an application for a particular user, retrieve configuration data specifying a reference to a key value. The computer system may maintain a data object that includes a client credential set for the particular user. In response to an occurrence of an event associated with the application, the computer system may access the client credential set of the particular user from the data object using the key value and an indication of the particular user. The computer system may then send a request including the client credential set to a destination computer system for authentication with the destination computer system and receive a response indicating whether the computer system has been authenticated.

Claims (66)

1. A method, comprising:

providing, by a computer system, a server-based platform accessible to a plurality of users, wherein the server-based platform permits an application that is developed by one of the plurality of users to be utilized by others of the plurality of users;

maintaining, by the computer system, a client credential set for a first one of the plurality of users;

receiving separately, by the computer system and from a peripheral computer system that is a separate system from the computer system, the application and a key value associated with the application that is usable to look up client credential sets;

installing, by the computer system, the application for the first user; and

in response to an occurrence of an event associated with the application, the computer system:

accessing the client credential set using the key value and an indication of the first user; and

authenticating with a destination computer system using the client credential set.

2. The method of claim 1 , further comprising:

installing, by the computer system, the application for a second one of the plurality of users; and

after installing the application for the second user, the computer system authenticating with the destination computer system using a client credential set of the second user accessed using the key value and an indication of the second user.

3. The method of claim 1 , further comprising:

receiving, by the computer system, a request to add a step to a workflow process associated with the first user, wherein the step corresponds to the application; and

implementing, by the computer system, the workflow process, wherein the occurrence of the event corresponds to the step being reached in the workflow process.

4. The method of claim 1 , further comprising:

receiving, by the computer system, information from the first user that identifies a mapping from the key value to the client credential set; and

storing, by the computer system, the mapping in association with the indication of the first user.

5. The method of claim 4 , further comprising:

receiving, by the computer system, a web page from the peripheral computer system that is associated with the application; and

causing, by the computer system, the web page to be presented to the first user, wherein the information that identifies the mapping is received via the web page.

6. The method of claim 5 , wherein the peripheral computer system is a different system than the destination computer system.

7. The method of claim 1 , further comprising:

before authenticating with the destination computer system, the computer system receiving information from the first user that specifies a uniform resource locator (URL) that corresponds to the destination computer system.

8. The method of claim 1 , wherein the key value is a globally unique identifier specified by a developer of the application.

9. A non-transitory computer-readable medium having program instructions stored thereon that are capable of causing a computer system to perform operations comprising:

providing a server-based platform accessible to a plurality of users, wherein the server-based platform permits an application that is developed by one of the plurality of users to be utilized by others of the plurality of users;

maintaining a client credential set for a first one of the plurality of users;

receiving separately, from a peripheral computer system that is a separate system from the computer system, the application and a key value associated with the application that is usable to look up client credential sets;

installing the application for the first user; and

in response to an occurrence of an event associated with the application:

accessing the client credential set of the first user using the key value and an indication of the first user; and

authenticating with a destination computer system using the client credential set.

10. The medium of claim 9 , wherein the operations further comprise:

making the application available to a second one of the plurality of users; and

authenticating, on behalf of the application for the second user, with a different destination computer system using a client credential set of the second user accessed using the key value and an indication of the second user.

11. The medium of claim 9 , wherein the operations further comprise:

in response to receiving a request to add a step to a process workflow associated with the first user, adding the step to the process workflow; and

upon reaching the step as part of executing the process workflow, executing the application to issue, subsequent to the authenticating, a request to the destination computer system to perform one or more tasks.

12. The medium of claim 11 , wherein adding the step to the process workflow includes:

causing an interface to be presented to the first user for receiving information pertaining to the step; and

receiving, via the interface, a mapping between the key value and the client credential set that permits the client credential set to be accessed using the key value.

13. The medium of claim 9 , wherein the indication of the first user is an account identifier that corresponds to an account under which the client credential set is stored.

14. A system, comprising:

at least one processor; and

memory having program instructions stored thereon that are executable by the at least one processor to perform operations comprising:

providing a server-based platform accessible to a plurality of users, wherein the server-based platform permits an application that is developed by one of the plurality of users to be utilized by others of the plurality of users;

maintaining a client credential set for a first one of the plurality of users;

installing the application for the first user, wherein the application is associated with a key value usable to look up client credential sets;

receiving a web page from a peripheral computer system that is associated with the application;

causing the web page to be presented to the first user;

receiving, from the first user via the web page, information identifying a mapping from the key value to the client credential set;

storing the mapping in association with an indication of the first user; and

in response to an occurrence of an event associated with the application:

accessing the client credential set of the first user using the key value and the indication of the first user; and

authenticating with a destination system using the client credential set.

15. The system of claim 14 , wherein the operations further comprise:

installing the application for a second, different one of the plurality of users, wherein the application is associated with the same key value usable to look up client credential sets; and

authenticating, on behalf of the application for the second user, with the destination system using a different client credential set accessed using the key value and an indication of the second user.

16. The system of claim 14 , wherein the operations further comprise:

incorporating a step into a process workflow of the first user, wherein performing the step involves executing the application and authenticating with the destination system.

17. The system of claim 14 , wherein the operations further comprise:

receiving the application from a different system; and

making the application available to the plurality of users via an application store.

18. The system of claim 14 , wherein the operations further comprise:

implementing a multi-tenant database that stores data for the plurality of users in respective tenant-specific storage areas, wherein the client credential set is stored in a tenant-specific storage area corresponding to the first user.

19. The system of claim 14 , wherein the client credential set includes a client identifier and a client secret, and wherein the authenticating includes receiving, from the destination system, a response having an authentication token that enables the system to make authenticated application programming interface (API) calls to the destination system on behalf of the first user.

Assignments (2)
CHANGE OF NAME Recorded Aug 4, 2026
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 076118/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2021
From: HELDMAN, KYLE EDWARD; WILSON, DOUGLAS CHRISTOPHER; REED, JACKSON GREGORY; APPLE, KYLE WARREN; RICHWINE, JACOB ANDREW
To: SALESFORCE.COM, INC.
Reel/Frame 054880/0802 →
Continuity (2)
Continuation 16022241 · Jun 28, 2018
Related Publication 20210136052A1 · May 6, 2021