IP Library Granted Patent US 12,003,602
Granted Patent B2
US 12,003,602 · App. 18/060,528 · Granted Jun 4, 2024

Method and system for universal security services abstraction

Inventors: Scott Glaser (Dublin, CA); Abhinav Bagul (Dallas, TX); Kerry Fleming (Plano, TX); Matthew R. Kunkel (San Francisco, CA); Derek Spiner (El Cerrito, CA)
Assignee: Salesforce, Inc.
H04L67/566H04L63/10H04L63/168H04L67/561H04L67/564
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,003,602
App. No.
18/060,528
Granted
Jun 4, 2024
Kind
B2
Abstract

A method for providing interoperability between a plurality of security services and target applications by an interoperability service. The method includes receiving a request from one of the plurality of security services to perform a task on a target application, preparing a unified data model for interaction with the target application, determining and organizing data connections to perform the task on the target application, generating a set of requests using the unified data model based on the task and utilizing business logic of the interoperability service for the data connections with the target application, transforming the set of requests into commands and data structures specific to the target application, and sending the set of requests on respective data connections with the target application.

Claims (50)

1. A method for providing interoperability between a plurality of security services and target applications by an interoperability service, wherein the interoperability service includes a first, second, and third abstraction layer, the method comprising:

receiving, at a first abstraction layer, a request from one of the plurality of security services to perform a task on a target application;

preparing a unified data model for interaction with the target application;

routing the request to a second abstraction layer based on the unified data model, and a set of actions for the task;

determining and organizing data connections to perform the task on the target application;

generating a set of requests using the unified data model based on the task and utilizing business logic of the second abstraction layer for the data connections with the target application;

routing the set of requests to a third abstraction layer based on the unified data model, and the set of actions for the task;

transforming the set of requests into commands and data structures specific to the target application; and

sending the commands and data structures on respective data connections with the target application.

2. The method of claim 1 , further comprising:

determining a permitted set of actions for the task, the target application, and the one of the plurality of security services.

3. The method of claim 1 , further comprising:

managing the data connections with the target application.

4. The method of claim 1 , further comprising:

receiving a response from the target application;

transforming the response into a form consistent with the unified data model;

combining the response into the unified data model; and

returning data to the one of the plurality of security services.

5. The method of claim 4 , further comprising:

filtering data of the unified data model prior to returning the data to the one of the plurality of security services.

6. The method of claim 4 , wherein the first abstraction layer is an experience layer, the second abstraction layer is a process layer, and the third abstraction layer is a system layer.

7. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor, will cause said processor to perform operations of a method for providing interoperability between a plurality of security services and target applications by an interoperability service, wherein the interoperability service includes a first, second, and third abstraction layer, the operations comprising:

receiving, at a first abstraction layer, a request from one of the plurality of security services to perform a task on a target application;

preparing a unified data model for interaction with the target application;

routing the request to a second abstraction layer based on the unified data model, and a set of actions for the task;

determining and organizing data connections to perform the task on the target application;

generating a set of requests using the unified data model based on the task and utilizing business logic of the second abstraction layer for the data connections with the target application;

routing the set of requests to a third abstraction layer based on the unified data model, and the set of actions for the task;

transforming the set of requests into commands and data structures specific to the target application; and

sending the commands and data structures on respective data connections with the target application.

8. The non-transitory machine-readable storage medium of claim 7 , further comprising:

determining a permitted set of actions for the task, the target application, and the one of the plurality of security services.

9. The non-transitory machine-readable storage medium of claim 7 , further comprising:

managing the data connections with the target application.

10. The non-transitory machine-readable storage medium of claim 7 , further comprising:

receiving a response from the target application;

transforming the response into a form consistent with the unified data model;

combining the response into the unified data model; and

returning data to the one of the plurality of security services.

11. The non-transitory machine-readable storage medium of claim 10 , further comprising:

filtering data of the unified data model prior to returning the data to the one of the plurality of security services.

12. The non-transitory machine-readable storage medium of claim 10 , wherein the first abstraction layer is an experience layer, the second abstraction layer is a process layer, and the third abstraction layer is a system layer.

13. A computing device to execute an interoperability service between a plurality of security services and applications, wherein the interoperability service includes a first, second, and third abstraction layer, the computing device comprising:

a non-transitory machine-readable medium having stored therein the interoperability services; and

a processor coupled to the non-transitory machine-readable medium, the processor to execute the interoperability service, the interoperability service to receive, at a first abstraction layer, a request from one of the plurality of security services to perform a task on a target application, prepare unified data model for interaction with the target application, route the request to a second abstraction layer based on the unified data model, and a set of actions for the task, determine and organize data connections to perform the task on the target application, generate a set of requests using the unified data model based on the task and utilize business logic of the second abstraction layer for the data connections with the target application, route the set of requests to a third abstraction layer based on the unified data model, and the set of actions for the task, transform the set of requests into commands and data structures specific to the target application, and send the commands and data structures on respective data connections with the target application.

14. The computing device of claim 13 , wherein the interoperability service is further to determine a permitted set of actions for the task, the target application, and the one of the plurality of security services.

15. The computing device of claim 13 , wherein the interoperability service is further to manage the data connections with the target application.

16. The computing device of claim 13 , wherein the interoperability service is further to receive a response from target application, transform the response into a form consistent with the unified data model, combine the response into the unified data model, and return data to the one of the plurality of security services.

17. The computing device of claim 16 , wherein the interoperability service is further to filter data of the unified data model prior to returning the data to the one of the plurality of security services.

18. The computing device of claim 16 , wherein the first abstraction layer is an experience layer, the second abstraction layer is a process layer, and the third abstraction layer is a system layer.

Assignments (2)
CHANGE OF NAME Recorded Feb 17, 2023
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 062794/0656 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2022
From: GLASER, SCOTT; BAGUL, ABHINAV; FLEMING, KERRY; KUNKEL, MATTHEW R.; SPINER, DEREK
To: SALESFORCE.COM, INC.
Reel/Frame 061930/0294 →
Continuity (2)
Continuation 17204880 · Mar 17, 2021
Related Publication 20230145705A1 · May 11, 2023