IP Library › Granted Patent US 12,074,861
Granted Patent B2
US 12,074,861 · App. 17/566,466 · Granted Aug 27, 2024

Systems and methods for identity and access management with extended trust

Inventors: Edward Wrenbeck (Ira, MI); Gopalakrishnan Brijesh (Novi, MI); Apurva Tiwari (Farmington Hills, MI); Dileep Kunnath Madathil (Troy, MI); Gaspare Bastone (Macomb, MI)
Assignee: OPEN TEXT HOLDINGS, INC.
H04L63/0815H04L63/0884H04L63/102H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,074,861
App. No.
17/566,466
Granted
Aug 27, 2024
Kind
B2
Abstract

An identity and access management (IAM) extended trust server (ETS) can work with a cloud-based IAM platform to authorize a user in a home zone to access a resource such as an enterprise application in an enterprise computing network. The IAM ETS receives a request from the user to access another resource, determines that other resource resides in a geographical zone that is different from the home zone, checks with the cloud-based IAM platform on whether the user is authorized to access the resource in the geographical zone, and responsive to an indication from the cloud-based IAM platform that the user is authorized to access the resource in the geographical zone, redirects a browser on the user device to the resource in the geographical zone without initiating a new session for the user, thereby providing the user with seamless access across multiple zones in a single global session.

Claims (68)

1. A method for identity and access management (IAM) with extended trust, the method comprising:

receiving, by an IAM extended trust server (ETS) operating in an enterprise computing network, a request from a user device of a user to access a first resource in the enterprise computing network;

verifying, by the IAM ETS with a cloud-based IAM platform, whether the user is authorized to access the first resource, wherein, once authorized, the cloud-based IAM platform generates an authentication token, starts a global session, and communicates the authentication token to the IAM ETS;

parsing, by the IAM ETS, the authentication token generated by the cloud-based IAM platform;

determining, by the IAM ETS from the authentication token, a home zone for the user where the user is provisioned in the cloud-based IAM platform so that the user's identity is known to the cloud-based IAM platform;

fetching, by the IAM ETS from the cloud-based IAM platform, user-specific session information;

authorizing, by the IAM ETS, access by the user to the first resource in the home zone in the enterprise computing network;

directing, by the IAM ETS, a browser on the user device to the first resource in the enterprise computing network;

providing, by the IAM ETS, the user-specific session information to the first resource in the enterprise computing network such that the user is able to access the first resource in the global session;

receiving, by the IAM ETS, a second request from the user device to access a second resource;

determining, by the IAM ETS, that the second resource resides in a geographical zone that is different from the home zone;

checking, by the IAM ETS communicating with the cloud-based IAM platform, whether the user is authorized to access the second resource in the geographical zone; and

responsive to an indication from the cloud-based IAM platform that the user is authorized to access the second resource in the geographical zone, redirecting the browser on the user device to the second resource in the geographical zone during the global session and without initiating a new session for the user.

2. The method according to claim 1 , further comprising:

in response to receiving the request from the user device, verifying, by the IAM ETS, whether the request contains a valid authentication token generated by the cloud-based IAM platform.

3. The method according to claim 2 , further comprising:

in response to a determination that the request does not contain a valid authentication token generated by the cloud-based IAM platform, directing, by the IAM ETS, the browser on the user device to a login page with input fields for entering credential information of the user.

4. The method according to claim 1 , further comprising:

checking, by the IAM ETS with the cloud-based IAM platform, whether a change affecting the global session has occurred.

5. The method according to claim 4 , wherein the change is a policy change or a user entitlement change.

6. The method according to claim 4 , wherein the IAM ETS continuously performs the checking on a configurable time interval.

7. The method according to claim 1 , wherein the authentication token contains claims, wherein the claims includes a reference to a token identifier for the authentication token, wherein the token identifier is utilized in looking up the global session for the user in a global session store of the cloud-based IAM platform.

8. A system for identity and access management (IAM) with extended trust, the system comprising:

a processor;

a non-transitory computer-readable medium; and

stored instructions translatable by the processor for implementing an IAM extended trust server (ETS) in an enterprise computing network, wherein the IAM ETS is operable to perform:

receiving a request from a user device of a user to access a first resource in the enterprise computing network;

verifying, with a cloud-based IAM platform, whether the user is authorized to access the first resource, wherein, once authorized, the cloud-based IAM platform generates an authentication token, starts a global session, and communicates the authentication token to the IAM ETS;

parsing the authentication token generated by the cloud-based IAM platform;

determining, from the authentication token, a home zone for the user where the user is provisioned in the cloud-based IAM platform so that the user's identity is known to the cloud-based IAM platform;

fetching, from the cloud-based IAM platform, user-specific session information;

authorizing access by the user to the first resource in the home zone in the enterprise computing network;

directing a browser on the user device to the first resource in the enterprise computing network;

providing the user-specific session information to the first resource in the enterprise computing network such that the user is able to access the first resource in the global session;

receiving a second request from the user device to access a second resource;

determining that the second resource resides in a geographical zone that is different from the home zone;

checking, by communicating with the cloud-based IAM platform, whether the user is authorized to access the second resource in the geographical zone; and

responsive to an indication from the cloud-based IAM platform that the user is authorized to access the second resource in the geographical zone, redirecting the browser on the user device to the second resource in the geographical zone during the global session and without initiating a new session for the user.

9. The system of claim 8 , wherein the IAM ETS is operable to further perform:

in response to receiving the request from the user device, verifying whether the request contains a valid authentication token generated by the cloud-based IAM platform.

10. The system of claim 9 , wherein the IAM ETS is operable to further perform:

in response to a determination that the request does not contain a valid authentication token generated by the cloud-based IAM platform, directing the browser on the user device to a login page with input fields for entering credential information of the user.

11. The system of claim 8 , wherein the IAM ETS is operable to further perform:

checking, with the cloud-based IAM platform, whether a change affecting the global session has occurred.

12. The system of claim 11 , wherein the change is a policy change or a user entitlement change.

13. The system of claim 11 , wherein the IAM ETS continuously performs the checking on a configurable time interval.

14. The system of claim 8 , wherein the authentication token contains claims, wherein the claims includes a reference to a token identifier for the authentication token, wherein the token identifier is utilized in looking up the global session for the user in a global session store of the cloud-based IAM platform.

15. A computer program product for identity and access management (IAM) with extended trust, the computer program product comprising a non-transitory computer-readable medium storing instructions translatable by an IAM extended trust server (ETS) in an enterprise computing network for:

receiving a request from a user device of a user to access a first resource in the enterprise computing network;

verifying, with a cloud-based IAM platform, whether the user is authorized to access the first resource, wherein, once authorized, the cloud-based IAM platform generates an authentication token, starts a global session, and communicates the authentication token to the IAM ETS;

parsing the authentication token generated by the cloud-based IAM platform;

determining, from the authentication token, a home zone for the user where the user is provisioned in the cloud-based IAM platform so that the user's identity is known to the cloud-based IAM platform;

fetching, from the cloud-based IAM platform, user-specific session information;

authorizing access by the user to the first resource in the home zone in the enterprise computing network;

directing a browser on the user device to the first resource in the enterprise computing network;

providing the user-specific session information to the first resource in the enterprise computing network such that the user is able to access the first resource in the global session;

receiving a second request from the user device to access a second resource;

determining that the second resource resides in a geographical zone that is different from the home zone;

checking, by communicating with the cloud-based IAM platform, whether the user is authorized to access the second resource in the geographical zone; and

responsive to an indication from the cloud-based IAM platform that the user is authorized to access the second resource in the geographical zone, redirecting the browser on the user device to the second resource in the geographical zone without initiating a new session for the user.

16. The computer program product of claim 15 , wherein the instructions are further translatable by the IAM ETS for:

in response to receiving the request from the user device, verifying whether the request contains a valid authentication token generated by the cloud-based IAM platform.

17. The computer program product of claim 16 , wherein the instructions are further translatable by the IAM ETS for:

in response to a determination that the request does not contain a valid authentication token generated by the cloud-based IAM platform, directing the browser on the user device to a login page with input fields for entering credential information of the user.

18. The computer program product of claim 15 , wherein the instructions are further translatable by the IAM ETS for:

checking, with the cloud-based IAM platform, whether a change affecting the global session has occurred.

19. The computer program product of claim 18 , wherein the change is a policy change or a user entitlement change.

20. The computer program product of claim 18 , wherein the IAM ETS continuously performs the checking on a configurable time interval.

Assignments (4)
MERGER Recorded Feb 13, 2026
From: OPEN TEXT HOLDINGS, INC.
To: OPEN TEXT INC.
Reel/Frame 073779/0839 →
EMPLOYEE RESTRICTIVE COVENANT AND INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Mar 10, 2025
From: WRENBECK, EDWARD
To: OPEN TEXT HOLDINGS, INC.
Reel/Frame 070458/0732 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2023
From: BASTONE, GASPARE
To: OPEN TEXT HOLDINGS, INC.
Reel/Frame 063421/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2022
From: BRIJESH, GOPALAKRISHNAN; TIWARI, APURVA; MADATHIL, DILEEP KUNNATH
To: OPEN TEXT HOLDINGS, INC.
Reel/Frame 061618/0807 →
Continuity (2)
Provisional Application 63132340 · Dec 30, 2020
Related Publication 20220210145A1 · Jun 30, 2022