IP Library Granted Patent US 10,104,077
Granted Patent B1
US 10,104,077 · App. 15/727,476 · Granted Oct 16, 2018

Enabling multitenant data access on a single industrial network

Inventors: Susanto Junaidi Irwan (San Francisco, CA); Ganesh B. Jampani (Gilroy, CA); Andy Sugiarto (Moraga, CA)
Assignee: XAGE SECURITY, INC.
H04L63/0869G06F21/445G06F21/602H04L9/0637H04L9/30H04L67/10H04W4/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,104,077
App. No.
15/727,476
Granted
Oct 16, 2018
Kind
B1
Abstract

In an embodiment, a computer-implemented method comprises receiving a first authentication request from one or more first computing devices; in response to receiving the first authentication request, performing a first authentication service for the one or more first computing devices on behalf of a second computing device using a first set of identity information; in response to performing the first authentication service, generating and queuing a first set of one or more transactions corresponding to at least one of the one or more first computing devices; receiving a second authentication request from the second computing device configured to access the first set of one or more transactions; in response to receiving the second authentication request, performing a second authentication service for the second computing device on behalf of a third computing device using a second set of identity information; in response to performing the second authentication service, encrypting and sending the first set of one or more transactions to the second computing device.

Claims (54)

1. A computer-implemented method comprising:

using a gateway, receiving a first authentication request from one or more first computing devices;

using the gateway, in response to receiving the first authentication request, performing a first authentication service for the one or more first computing devices by authenticating to one or more of the first computing devices on behalf of a first client device using a first set of identity information that is associated with and stored in the gateway;

in response to performing the first authentication service, using the gateway, generating and queuing a first set of one or more transactions corresponding to at least one of the one or more first computing devices;

using the gateway, receiving a second authentication request from the first client device configured to access the first set of one or more transactions;

in response to receiving the second authentication request, using the gateway, performing a second authentication service for the first client device on behalf of a second computing device using a second set of identity information that is associated with the first client device and that is stored in the gateway;

in response to performing the second authentication service, encrypting and sending, using the gateway, the first set of one or more transactions to the first client device.

2. The method of claim 1 , further comprising:

in response to performing the first authentication service, using the gateway, generating and queuing a second set of one or more transactions corresponding to at least one of the one or more first computing devices;

using the gateway, receiving a third authentication request from a second client device configured to access the second set of one or more transactions;

in response to receiving the third authentication request, performing, using the gateway, a third authentication service for the second client device on behalf of the second computing device using a third set of identity information that is associated with second client device and that is stored in the gateway; and

in response to performing the third authentication service, encrypting and sending the second set of one or more transactions to the second client device.

3. The method of claim 1 , wherein the one or more first computing devices are one or more Internet of Things (IoT) devices, and wherein performing the first authentication service for the one or more first computing devices comprises performing the first authentication service for the one or more IoT devices.

4. The method of claim 1 , wherein performing the second authentication service comprises authenticating an application.

5. The method of claim 1 , wherein encrypting comprises using a public key encryption.

6. The method of claim 1 , wherein the first set of one or more transactions comprises a first set of one or more timestamp-value pairs.

7. The method of claim 2 , wherein the second set of one or more transactions comprises a second set of one or more timestamp-value pairs.

8. One or more non-transitory computer-readable storage media storing one or more sequences of program instructions which, when executed by one or more computing devices, cause performing:

using a gateway, receiving a first authentication request from one or more first computing devices;

using the gateway, in response to receiving the first authentication request, performing a first authentication service for the one or more first computing devices by authenticating to one or more of the first computing devices on behalf of a first client device using a first set of identity information that is associated with and stored in the gateway;

in response to performing the first authentication service, using the gateway, generating and queuing a first set of one or more transactions corresponding to at least one of the one or more first computing devices;

using the gateway, receiving a second authentication request from the first client device configured to access the first set of one or more transactions;

in response to receiving the second authentication request, using the gateway, performing a second authentication service for the first client device on behalf of a second computing device using a second set of identity information that is associated with the first client device and that is stored in the gateway;

in response to performing the second authentication service, encrypting and sending, using the gateway, the first set of one or more transactions to the first client device.

9. The one or more non-transitory machine-readable media of claim 8 , storing one or more further sequences of program instructions which, when executed by the one or more computing devices, further cause performing:

in response to performing the first authentication service, using the gateway, generating and queuing a second set of one or more transactions corresponding to at least one of the one or more first computing devices;

using the gateway, receiving a third authentication request from a second client device configured to access the second set of one or more transactions;

in response to receiving the third authentication request, performing, using the gateway, a third authentication service for the second client device on behalf of the second computing device using a third set of identity information that is associated with second client device and that is stored in the gateway; and

in response to performing the third authentication service, encrypting and sending the second set of one or more transactions to the second client device.

10. The one or more non-transitory machine-readable media of claim 8 , wherein the one or more first computing devices are one or more Internet of Things (IoT) devices, and wherein performing the first authentication service for the one or more first computing devices comprises performing the first authentication service for the one or more IoT devices.

11. The one or more non-transitory machine-readable media of claim 8 , wherein performing the second authentication service comprises granting access to the first set of one or more transactions.

12. The one or more non-transitory machine-readable media of claim 9 , wherein performing the third authentication service comprises granting access to the second set of one or more transactions.

13. The one or more non-transitory machine-readable media of claim 9 , wherein the first set of one or more transactions comprises a first set of one or more timestamp-value pairs, and wherein the second set of one or more transactions comprises a second set of one or more timestamp-value pairs.

14. The one or more non-transitory machine-readable media of claim 9 , wherein encrypting the first set of one or more transactions and the second set of one or more transactions comprises using a public key encryption.

15. A computer system comprising:

one or more processors;

a computer-readable storage media coupled to the one or more processors;

a memory coupled to the computer readable storage media and storing instructions which, when executed by the one or more processors cause a gateway to:

receive a first authentication request from one or more first computing devices;

in response to receiving the first authentication request, perform a first authentication service for the one or more first computing devices by authenticating to one or more of the first computing devices on behalf of a first client device using a first set of identity information that is associated with and stored in the gateway;

in response to performing the first authentication service, generate and queue a first set of one or more transactions corresponding to at least one of the one or more first computing devices;

receive a second authentication request from the first client device configured to access the first set of one or more transactions;

in response to receiving the second authentication request, perform a second authentication service for the first client device on behalf of a second computing device using a second set of identity information that is associated with the first client device and that is stored in the gateway;

in response to performing the second authentication service, encrypt and send the first set of one or more transactions to the first client device.

16. The computer system of claim 15 , wherein the memory stores further instructions which, when executed by the one or more processors causes the gateway to:

in response to performing the first authentication service, generate and queue a second set of one or more transactions corresponding to at least one of the one or more first computing devices;

receive a third authentication request from a second client device configured to access the second set of one or more transactions;

in response to receiving the third authentication request, perform a third authentication service for the second client device on behalf of the second computing device using a third set of identity information that is associated with second client device and that is stored in the gateway; and

in response to performing the third authentication service, encrypt and send the second set of one or more transactions to the second client device.

17. The computer system of claim 16 , wherein the one or more first computing devices are one or more Internet of Things (IoT) devices, and wherein performing the first authentication service for the one or more first computing devices comprises performing the first authentication service for the one or more IoT devices.

18. The computer system of claim 17 , wherein the first set of one or more transactions comprises a first set of one or more timestamp-value pairs.

19. The computer system of claim 18 , wherein the second set of one or more transactions comprises a second set of one or more timestamp-value pairs.

20. The computer system of claim 19 , wherein performing the second authentication service comprises granting access to the first set of one or more transactions and not the second set of one or more transactions.

21. The computer system of claim 20 , wherein performing the third authentication service comprises granting access to the second set of one or more transactions and not the first set of one or more transactions.

Assignments (2)
CHANGE OF NAME Recorded Jan 22, 2018
From: SENSIFY SECURITY, INC.
To: XAGE SECURITY, INC.
Reel/Frame 045112/0115 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2017
From: IRWAN, SUSANTO JUNAIDI; JAMPANI, GANESH B.; SUGIARTO, ANDY
To: SENSIFY SECURITY, INC.
Reel/Frame 043854/0216 →
Cited By (4)
US 12,200,046 US 12,265,644 US 12,401,601 US 12,483,556