IP Library › Granted Patent US 12,273,347
Granted Patent B2
US 12,273,347 · App. 17/238,180 · Granted Apr 8, 2025

Techniques and architectures for sharing remote resources among a trusted group of users

Inventors: Jayanth Parayil Kumarji (San Francisco, CA); Priyadarshini Mitra (San Francisco, CA); Kevin Terusaki (Oakland, CA); Zhidong Ke (Milpitas, CA); Yifeng Liu (Palo Alto, CA); Utsavi Benani (Fremont, CA); Heng Zhang (San Jose, CA); Evan Jiang (San Francisco, CA); Birva Joshi (San Francisco, CA); Yogesh Patel (Dublin, CA)
Assignee: Salesforce, Inc.
H04L63/102H04L63/0807H04L63/104H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,347
App. No.
17/238,180
Granted
Apr 8, 2025
Kind
B2
Abstract

Various techniques and mechanisms for sharing remote resources among a trusted group are disclosed. A credential management agent utilizes a resource credential for a first user to access a secure resource corresponding to the first user for a second user by at least validating a second user and validating a consent of the first user to allow the second user to access the secure resource using the resource credential for the first user. The secure resource resides on a remote server system accessible via one or more application program interfaces (APIs). A platform management agent provides an interface for shared resource-agnostic credential sharing. The platform management agent validates credentials for the second user as belonging to a trusted group and forwards a request for access to the secure resource for the second user to the credential management agent. In response to receiving the resource credential for the first user to access the secure resource, the platform management agent accesses the secure resource on behalf of the second user to allow the second user to utilize the secure resource.

Claims (37)

1. A system comprising one or more servers, the one or more servers being configured to:

determine that a first user has opted in to a trusted group to share a remote secure resource with members of the trusted group, the trusted group including a second user, wherein users can be dynamically added to and removed from the trusted group, any member of which can access the secure resource utilizing the first user's credentials;

receive, from a platform application server, a request from the first user to access the remote secure resource that is hosted in a computing environment that is distinct from a local computing environment in which the request is made, the platform application server managing meeting and recording metadata;

validate, with a resource activity application server, credentials for the first user to access the local computing environment, the resource activity application server managing user platform credentials;

forward the request to a resource activity application server upon successful validation of the credentials for the first user, wherein the forwarded request for access to the secure resource comprises at least a server-to-server token associated with the request;

utilize credentials of the second user; and

receive information to allow access to the remote secure resource by the first user providing access to the remote secure resource utilizing the credentials for the second user through a user interface of the local computing environment.

2. The system of claim 1 wherein the first user and the second user are both members of the trusted group, any member of which can access the secure resource utilizing the first user's credentials.

3. The system of claim 1 wherein the platform management agent interface provides the second user access to platform services and to the secure resource.

4. The system of claim 1 wherein the first user, as a member of the trusted group, opts in to share the resource with members of the trusted group.

5. Non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, are configurable to cause the one or more processors to:

determine that a first user has opted in to a trusted group to share a remote secure resource with members of the trusted group, the trusted group including a second user, wherein users can be dynamically added to and removed from the trusted group, any member of which can access the secure resource utilizing the first user's credentials;

receive, from a platform application server, a request from the first user to access the remote secure resource that is hosted in a computing environment that is distinct from a local computing environment in which the request is made, the platform application server managing meeting and recording metadata;

validate, with a resource activity application server, credentials for the first user to access the local computing environment, the resource activity application server managing user platform credentials;

forward the request to a resource activity application server upon successful validation of the credentials for the first user, wherein the forwarded request for access to the secure resource comprises at least a server-to-server token associated with the request;

receive information to allow access to the remote secure resource by the first user utilizing credentials of the second user; and

provide access to the remote secure resource utilizing the credentials for the second user through a user interface of the local computing environment.

6. A method comprising:

determining that a first user has opted in to a trusted group to share a remote secure resource with members of the sharing group, the trusted group including a second user, wherein users can be dynamically added to and removed from the sharing group, any member of which can access the secure resource utilizing the first user's credentials;

receiving, from a platform application server, a request from the first user to access the remote secure resource that is hosted in a computing environment that is distinct from a local computing environment in which the request is made, the platform application server managing meeting and recording metadata;

validating, with a resource activity application server, credentials for the first user to access the local computing environment, the resource activity application server managing user platform credentials;

forwarding the request to a resource activity application server upon successful validation of the credentials for the first user, wherein the forwarded request for access to the secure resource comprises at least a server-to-server token associated with the request;

utilizing credentials of the second user; and

receiving information to allow access to the remote secure resource by the first user;

providing access to the remote secure resource utilizing the credentials for the second user through a user interface of the local computing environment.

7. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, are configurable to cause the one or more processors to:

determine that a first user has opted in to a trusted group to share a remote secure resource with members of the trusted group, the trusted group including a second user, wherein users can be dynamically added to and removed from the trusted group, any member of which can access the secure resource utilizing the first user's credentials;

receive, from a platform application server, a request on behalf of the first user to access a remote secure resource that is hosted in a computing environment that is distinct from a local computing environment in which the request is made, wherein the remote secure resource is owned by the second user, wherein the received request for access to the secure resource comprises at least a server-to-server token associated with the request;

validate, with a resource activity application server, credentials for the first user and consent from a second user for the first user to access the remote secure resource, the resource activity application server managing user platform credentials;

request access to the remote secure resource utilizing credentials for the second user, if the credentials for the first user and the consent are validated; and

send, to the platform application server, information to allow access to the remote secure resource by the first user utilizing credentials of a second user, the platform application server managing meeting and recording metadata.

8. A method comprising:

determining that a first user has opted in to a trusted group to share a remote secure resource with members of the trusted group, the trusted group including a second user, wherein users can be dynamically added to and removed from the sharing group, any member of which can access the secure resource utilizing the first user's credentials;

receiving, from a platform application server, a request on behalf of the first user to access the remote secure resource that is hosted in a computing environment that is distinct from a local computing environment in which the request is made, wherein the remote secure resource is owned by the second user, wherein the received request for access to the secure resource comprises at least a server-to-server token associated with the request;

validating, with a resource activity application server, credentials for the first user and consent from the second user for the first user to access the remote secure resource, the resource activity application server managing user platform credentials;

requesting access to the remote secure resource utilizing credentials for the second user, if the credentials for the first user and the consent are validated; and

sending, to the platform application server, information to allow access to the remote secure resource by the first user utilizing credentials of a second user, the platform application server managing meeting and recording metadata.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2021
From: KUMARJI, JAYANTH PARAYIL; MITRA, PRIYADARSHINI; TERUSAKI, KEVIN; KE, ZHIDONG; LIU, YIFENG; BENANI, UTSAVI; ZHANG, HENG; JIANG, EVAN; JOSHI, BIRVA; PATEL, YOGESH
To: SALESFORCE.COM, INC.
Reel/Frame 056359/0983 →
Continuity (1)
Related Publication 20220345458A1 · Oct 27, 2022
References Cited (124)
US 5577188A · Zhu · 1996 [cited by applicant]
US 5608872A · Schwartz et al. · 1997 [cited by applicant]
US 5649104A · Carleton et al. · 1997 [cited by applicant]
US 5715450A · Ambrose et al. · 1998 [cited by applicant]
US 5761419A · Schwartz et al. · 1998 [cited by applicant]
US 5819038A · Carleton et al. · 1998 [cited by applicant]
US 5821937A · Tonelli et al. · 1998 [cited by applicant]
US 5831610A · Tonelli et al. · 1998 [cited by applicant]
US 5873096A · Lim et al. · 1999 [cited by applicant]
US 5918159A · Fomukong et al. · 1999 [cited by applicant]
US 5963953A · Cram et al. · 1999 [cited by applicant]
US 6092083A · Brodersen et al. · 2000 [cited by applicant]
US 6169534B1 · Raffel et al. · 2001 [cited by applicant]
US 6178425B1 · Brodersen et al. · 2001 [cited by applicant]
US 6189011B1 · Lim et al. · 2001 [cited by applicant]
US 6216135B1 · Brodersen et al. · 2001 [cited by applicant]
US 6233617B1 · Rothwein et al. · 2001 [cited by applicant]
US 6266669B1 · Brodersen et al. · 2001 [cited by applicant]
US 6295530B1 · Ritchie et al. · 2001 [cited by applicant]
US 6324568B1 · Diec · 2001 [cited by applicant]
US 6324693B1 · Brodersen et al. · 2001 [cited by applicant]
US 6336137B1 · Lee et al. · 2002 [cited by applicant]
US D454139S · Feldcamp · 2002 [cited by applicant]
US 6367077B1 · Brodersen et al. · 2002 [cited by applicant]
US 6393605B1 · Loomans · 2002 [cited by applicant]
US 6405220B1 · Brodersen et al. · 2002 [cited by applicant]
US 6434550B1 · Warner et al. · 2002 [cited by applicant]
US 6446089B1 · Brodersen et al. · 2002 [cited by applicant]
US 6535909B1 · Rust · 2003 [cited by applicant]
US 6549908B1 · Loomans · 2003 [cited by applicant]
US 6553563B2 · Ambrose et al. · 2003 [cited by applicant]
US 6560461B1 · Fomukong et al. · 2003 [cited by applicant]
US 6574635B2 · Stauber et al. · 2003 [cited by applicant]
US 6577726B1 · Huang et al. · 2003 [cited by applicant]
US 6601087B1 · Zhu et al. · 2003 [cited by applicant]
US 6604117B2 · Lim et al. · 2003 [cited by applicant]
US 6604128B2 · Diec · 2003 [cited by applicant]
US 6609150B2 · Lee et al. · 2003 [cited by applicant]
US 6621834B1 · Scherpbier et al. · 2003 [cited by applicant]
US 6654032B1 · Zhu et al. · 2003 [cited by applicant]
US 6665648B2 · Brodersen et al. · 2003 [cited by applicant]
US 6665655B1 · Warner et al. · 2003 [cited by applicant]
US 6684438B2 · Brodersen et al. · 2004 [cited by applicant]
US 6711565B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6724399B1 · Katchour et al. · 2004 [cited by applicant]
US 6728702B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6728960B1 · Loomans · 2004 [cited by applicant]
US 6732095B1 · Warshavsky et al. · 2004 [cited by applicant]
US 6732100B1 · Brodersen et al. · 2004 [cited by applicant]
US 6732111B2 · Brodersen et al. · 2004 [cited by applicant]
US 6754681B2 · Brodersen et al. · 2004 [cited by applicant]
US 6763351B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6763501B1 · Zhu et al. · 2004 [cited by applicant]
US 6768904B2 · Kim · 2004 [cited by applicant]
US 6782383B2 · Subramaniam et al. · 2004 [cited by applicant]
US 6804330B1 · Jones et al. · 2004 [cited by applicant]
US 6826565B2 · Ritchie et al. · 2004 [cited by applicant]
US 6826582B1 · Chatterjee et al. · 2004 [cited by applicant]
US 6826745B2 · Coker et al. · 2004 [cited by applicant]
US 6829655B1 · Huang et al. · 2004 [cited by applicant]
US 6842748B1 · Warner et al. · 2005 [cited by applicant]
US 6850895B2 · Brodersen et al. · 2005 [cited by applicant]
US 6850949B2 · Warner et al. · 2005 [cited by applicant]
US 7289976B2 · Kihneman et al. · 2007 [cited by applicant]
US 7340411B2 · Cook · 2008 [cited by applicant]
US 7620655B2 · Larsson et al. · 2009 [cited by applicant]
US 11632360B1 · Tan · 2023 [cited by examiner]
US 20010044791A1 · Richter et al. · 2001 [cited by applicant]
US 20020022986A1 · Coker et al. · 2002 [cited by applicant]
US 20020029161A1 · Brodersen et al. · 2002 [cited by applicant]
US 20020029376A1 · Ambrose et al. · 2002 [cited by applicant]
US 20020035577A1 · Brodersen et al. · 2002 [cited by applicant]
US 20020042264A1 · Kim · 2002 [cited by applicant]
US 20020042843A1 · Diec · 2002 [cited by applicant]
US 20020072951A1 · Lee et al. · 2002 [cited by applicant]
US 20020082892A1 · Raffel et al. · 2002 [cited by applicant]
US 20020129352A1 · Brodersen et al. · 2002 [cited by applicant]
US 20020140731A1 · Subramaniam et al. · 2002 [cited by applicant]
US 20020143997A1 · Huang et al. · 2002 [cited by applicant]
US 20020152102A1 · Brodersen et al. · 2002 [cited by applicant]
US 20020161734A1 · Stauber et al. · 2002 [cited by applicant]
US 20020162090A1 · Parnell et al. · 2002 [cited by applicant]
US 20020165742A1 · Robins · 2002 [cited by applicant]
US 20030004971A1 · Gong et al. · 2003 [cited by applicant]
US 20030018705A1 · Chen et al. · 2003 [cited by applicant]
US 20030018830A1 · Chen et al. · 2003 [cited by applicant]
US 20030066031A1 · Laane · 2003 [cited by applicant]
US 20030066032A1 · Ramachadran et al. · 2003 [cited by applicant]
US 20030069936A1 · Warner et al. · 2003 [cited by applicant]
US 20030070000A1 · Coker et al. · 2003 [cited by applicant]
US 20030070004A1 · Mukundan et al. · 2003 [cited by applicant]
US 20030070005A1 · Mukundan et al. · 2003 [cited by applicant]
US 20030074418A1 · Coker · 2003 [cited by applicant]
US 20030088545A1 · Subramaniam et al. · 2003 [cited by applicant]
US 20030120675A1 · Stauber et al. · 2003 [cited by applicant]
US 20030151633A1 · George et al. · 2003 [cited by applicant]
US 20030159136A1 · Huang et al. · 2003 [cited by applicant]
US 20030187921A1 · Diec · 2003 [cited by applicant]
US 20030189600A1 · Gune et al. · 2003 [cited by applicant]
US 20030191743A1 · Brodersen et al. · 2003 [cited by applicant]
US 20030204427A1 · Gune et al. · 2003 [cited by applicant]
US 20030206192A1 · Chen et al. · 2003 [cited by applicant]
US 20030225730A1 · Warner et al. · 2003 [cited by applicant]
US 20040001092A1 · Rothwein et al. · 2004 [cited by applicant]
US 20040010489A1 · Rio · 2004 [cited by applicant]
US 20040015981A1 · Coker et al. · 2004 [cited by applicant]
US 20040027388A1 · Berg et al. · 2004 [cited by applicant]
US 20040128001A1 · Levin et al. · 2004 [cited by applicant]
US 20040153655A1 · Rolfe · 2004 [cited by examiner]
US 20040186860A1 · Lee et al. · 2004 [cited by applicant]
US 20040193510A1 · Catahan, Jr. et al. · 2004 [cited by applicant]
US 20040199489A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040199536A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040199543A1 · Braud et al. · 2004 [cited by applicant]
US 20040249854A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040260534A1 · Pak et al. · 2004 [cited by applicant]
US 20040260659A1 · Chan et al. · 2004 [cited by applicant]
US 20040268299A1 · Lei et al. · 2004 [cited by applicant]
US 20050050555A1 · Exley et al. · 2005 [cited by applicant]
US 20050091098A1 · Brodersen et al. · 2005 [cited by applicant]
US 20090177744A1 · Marlow et al. · 2009 [cited by applicant]
US 20140068746A1 · Gonzalez · 2014 [cited by examiner]
US 20220038462A1 · Chauhan · 2022 [cited by examiner]
Building a Zero Trust Architecture Using Kubernetes, D'Silva et al, Apr. 2021 (Year: 2021). [cited by examiner]