IP Library › Granted Patent US 12,265,635
Granted Patent B2
US 12,265,635 · App. 17/927,675 · Granted Apr 1, 2025

Selective security augmentation in source control environments

Inventors: Filip Sebesta (Seattle, WA); Yu Lin Sie (Suzhou, CN); Yi Zeng (Bothell, WA); Lingxia Chen (Suzhou, CN)
Assignee: Microsoft Technology Licensing, LLC
G06F21/6209G06F21/31G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,635
App. No.
17/927,675
Granted
Apr 1, 2025
Kind
B2
Abstract

A method enhances authentication requirements to documents of a document repository based, at least in part, on a security policy associated with a branch under which the documents are organized. The method implements an approval service that is identified in a branch policy. The approval service determines whether a user is authorized to modify documents included in the branch. The method further selectively requires multiple authentications from multiple authentication systems in order to access one or more particular branches in a document repository. Further, the multiple authentication systems are based on separate and independent sets of authentication credentials.

Claims (58)

1. A device-implemented method, comprising:

first authenticating, via a first authentication system, an account to access a document repository;

receiving, from the account and in response to a valid authentication, a request to submit a document to the document repository;

decoding, based on the first authenticating being valid, the request;

identifying, based on the decoding, a branch of the document repository to which the document is to be stored, the branch is one of a plurality of branches of the document repository, the branch of the branches including a non-overlapping subset of the document repository;

determining that accessing the branch requires a second authentication in addition to the first authentication;

second authenticating, via a second authentication system, the account in response to determining the branch requires the second authentication; and

submitting, based on the second authenticating being valid, the document to the branch of the document repository.

2. The method of claim 1 , further comprising:

receiving, from the account, a second request to submit a second document to the document repository;

second decoding, based on the first authenticating, the second request;

identifying, based on the second decoding, a second branch of the document repository;

determining a second authentication is not required to access the second branch; and

submitting, based on the first authenticating, the second document to the second branch of the document repository.

3. The method of claim 1 , wherein the first authentication system is configured to associate the account with a first set of credentials and the second authentication system is configured to associate the account with a second set of credentials.

4. The method of claim 1 , wherein the determining that the first branch requires the second authentication comprises identifying a branch policy associated with the first branch, and determining, based on the branch policy, that the first branch requires the second authentication.

5. The method of claim 4 , wherein the second authenticating via the second authentication system comprises querying a web service.

6. The method of claim 5 , further identifying, based on the branch policy, the web service.

7. The method of claim 1 , wherein the first authentication system is configured to control access to enterprise resources, and the second authentication system is configured to control access to a data center.

8. A system, comprising:

hardware processing circuitry; and

one or more hardware memories storing instructions that when executed, configure the hardware processing circuitry to perform operations comprising:

first authenticating, via a first authentication system, an account to access a document repository;

receiving, from the account and in response to a valid authentication, a request to submit a document to the document repository;

decoding, based on the first authenticating being valid, the request;

identifying, based on the decoding, a branch of the document repository to which the document is to be stored, the branch is one of a plurality of branches of the document repository, the branch of the branches including a non-overlapping subset of the document repository;

determining that accessing the branch requires a second authentication in addition to the first authentication;

second authenticating, via a second authentication system, the account in response to determining the branch requires the second authentication; and

submitting, based on the second authenticating being valid, the document to the branch of the document repository.

9. The system of claim 8 , the operations further comprising:

receiving, from the account, a second request to submit a second document to the document repository;

second decoding, based on the first authenticating, the second request;

identifying, based on the second decoding, a second branch of the document repository;

determining a second authentication is not required to access the second branch; and

submitting, based on the first authenticating, the second document to the second branch of the document repository.

10. The system of claim 8 , wherein the first authentication system is configured to associate the account with a first set of credentials and the second authentication system is configured to associate the account with a second set of credentials.

11. The system of claim 8 , wherein the determining that the first branch requires the second authentication comprises identifying a branch policy associated with the first branch, and determining, based on the branch policy, that the first branch requires the second authentication.

12. The system of claim 11 , wherein the second authenticating via the second authentication system comprises querying a web service.

13. The system of claim 12 , the operations further comprising further identifying, based on the branch policy, the web service.

14. The system of claim 8 , wherein the first authentication system is configured to control access to enterprise resources, and the second authentication system is configured to control access to a data center.

15. A non-transitory computer readable storage medium comprising instructions that when executed configure hardware processing circuitry to perform operations comprising:

first authenticating, via a first authentication system, an account to access a document repository;

receiving, from the account and in response to a valid authentication, a request to submit a document to the document repository;

decoding, based on the first authenticating being valid, the request;

identifying, based on the decoding, a branch of the document repository to which the document is to be stored, the branch is one of a plurality of branches of the document repository, the branch of the branches including a non-overlapping subset of the document repository;

determining that accessing the branch requires a second authentication in addition to the first authentication;

second authenticating, via a second authentication system, the account in response to determining the branch requires the second authentication; and

submitting, based on the second authenticating being valid, the document to the branch of the document repository.

16. The non-transitory computer readable storage medium of claim 15 , the operations further comprising:

receiving, from the account, a second request to submit a second document to the document repository;

second decoding, based on the first authenticating, the second request;

identifying, based on the second decoding, a second branch of the document repository;

determining a second authentication is not required to access the second branch; and

submitting, based on the first authenticating, the second document to the second branch of the document repository.

17. The non-transitory computer readable storage medium of claim 15 , wherein the first authentication system is configured to associate the account with a first set of credentials and the second authentication system is configured to associate the account with a second set of credentials.

18. The non-transitory computer readable storage medium of claim 15 , wherein the determining that the first branch requires the second authentication comprises identifying a branch policy associated with the first branch, and determining, based on the branch policy, that the first branch requires the second authentication.

19. The non-transitory computer readable storage medium of claim 18 , wherein the second authenticating via the second authentication system comprises querying a web service.

20. The non-transitory computer readable storage medium of claim 19 , the operations further comprising further identifying, based on the branch policy, the web service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2022
From: SEBESTA, FILIP; SIE, YU LIN; ZENG, YI; CHEN, LINGXIA
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061975/0377 →
Continuity (1)
Related Publication 20230177184A1 · Jun 8, 2023
References Cited (24)
US 20070061571A1 · Hammes et al. · 2007 [cited by applicant]
US 20110004921A1 · Homer et al. · 2011 [cited by applicant]
US 20140331060A1 · Hayton · 2014 [cited by examiner]
US 20150134600A1 · Eisner · 2015 [cited by applicant]
US 20170099297A1 · Armer · 2017 [cited by applicant]
US 20170337255A1 · Holmes-Higgin · 2017 [cited by examiner]
CN 1579080A · 2005 [cited by applicant]
CN 101833563A · 2010 [cited by applicant]
CN 102571703A · 2012 [cited by applicant]
CN 102771101A · 2012 [cited by applicant]
CN 103650412A · 2014 [cited by applicant]
CN 104937909A · 2015 [cited by applicant]
CN 105830389A · 2016 [cited by applicant]
CN 107431692A · 2017 [cited by applicant]
CN 108287987A · 2018 [cited by applicant]
CN 109274769A · 2019 [cited by applicant]
Extended European search report received in European Patent Application No. 20943253.3, mailed on Jan. 29, 2024, 8 Pages. [cited by applicant]
EPO Communication pursuant to Rules 70(2) and 70a (2) received in European Application No. 209432533, mailed on Feb. 15, 2024, 1 page. [cited by applicant]
Office Action Received for Chinese Application No. 202080063102.1, mailed on Feb. 27, 2024, 15 pages (English Translation Provided). [cited by applicant]
“Source Providers—Get Pull Request”, Retrieved From: https://learn.microsoft.com/en-US/rest/api/azure/devops/build/source-providers/get-pull-request?view=azure-devops-rest-5.1#referencelinks, Retrieved Date: Dec. 13, 20… [cited by applicant]
Kathrynee, et al., “About Security, Authentication, And Authorization”, Retrieved From: https://learn.microsoft.com/en-us/azure/devops/organizations/security/about-security-identity?toc=%2Fazure%2Fdevops%2Forganizations… [cited by applicant]
Machiraju, et al., “About Branches and Branch Policies”, Retrieved From: https://learn.microsoft.com/en-US/azure/devops/repos/git/branch-policies-overview?view=azure-devops, Oct. 5, 2022, 5 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/CN2020/098712”, Mailed Date: Mar. 25, 2021, 10 Pages. [cited by applicant]
Notice of Allowance Received for Chinese Application No. 202080063102.1, mailed on Dec. 29, 2024, 08 Pages (English Translation Provided). [cited by applicant]