IP Library › Granted Patent US 10,536,461
Granted Patent B2
US 10,536,461 · App. 15/847,627 · Granted Jan 14, 2020

Service identity propagation between applications and reusable services

Inventors: Martijn de Boer (Heidelberg, DE); Peter Eberlein (Malsch, DE); Florian Tack (Walldorf, DE); Heiko Ettelbrueck (Nussloch, DE)
Assignee: SAP SE
H04L63/10G06F21/335G06F21/41H04L63/08H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,536,461
App. No.
15/847,627
Granted
Jan 14, 2020
Kind
B2
Abstract

A request from a User for a Service is received by an Application. An Open Authorization (OAUTH) Client of the Service is requested from a Service Instance of the Service. A copy OAUTH Client of the Service specific to the User is provided based on a clone OAUTH Client associated with the Service Instance. A Token is obtained to access the Service by providing the copy OAUTH Client to a User Account and Authorization (UAA) entity. Access to the Service is obtained by providing the Token.

Claims (36)

1. A computer-implemented method, comprising:

receiving, by one or more processors, at a computer Application, a request for a Service from a User;

requesting, by the one or more processors and from a Service Instance created by a first Service Broker of the Service, a Master Open Authorization (OAUTH) Client of the Service;

receiving, by the one or more processors and from the Service Instance, a copy OAUTH Client based on a clone of the Master OAUTH Client, the clone being associated with the Service Instance, the copy OAUTH Client being specific to the User;

providing the copy OAUTH Client to a User Account and Authorization (UAA) entity to obtain a service-specific Token, wherein the UAA entity generates the Token in response to authenticating the User based on the copy OAUTH Client; and

obtaining, by the one or more processors, access to the Service by providing the service-specific Token.

2. The computer-implemented method of claim 1 , wherein the clone is specific to the Service Instance.

3. The computer-implemented method of claim 1 , wherein the clone is provided according to a UAA Service Instance created by a UAA service broker.

4. The computer-implemented method of claim 3 , wherein the UAA Service Instance is used by the first Service Broker specifically to create the clone for the Service Instance of the Service.

5. The computer-implemented method of claim 1 , wherein the clone is specific to the Application.

6. The computer-implemented method of claim 1 , wherein the Service Instance is created specifically for the Application.

7. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving, at a computer Application, a request for a Service from a User;

requesting from a Service Instance created by a first Service Broker of the Service, a Master Open Authorization (OAUTH) Client of the Service;

receiving from the Service Instance, a copy OAUTH Client based on a clone of the Master OAUTH Client, the clone being associated with the Service Instance, the copy OAUTH Client being specific to the User;

providing the copy OAUTH Client to a User Account and Authorization (UAA) entity to obtain a service-specific Token, wherein the UAA entity generates the Token in response to authenticating the User based on the copy OAUTH Client; and

obtaining, access to the Service by providing the service-specific Token.

8. The non-transitory, computer readable medium of claim 7 , wherein the clone is specific to the Service Instance.

9. The non-transitory, computer readable medium of claim 7 , wherein the clone is provided according to a UAA Service Instance created by a UAA service broker.

10. The non-transitory, computer readable medium of claim 9 , wherein the UAA Service Instance is used by the first Service Broker specifically to create the clone for the Service Instance of the Service.

11. The non-transitory, computer readable medium of claim 7 , wherein the clone is specific to the Application.

12. The non-transitory, computer readable medium of claim 7 , wherein the Service Instance is created specifically for the Application.

13. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

receiving, at a computer Application, a request for a Service from a User;

requesting from a Service Instance created by a first Service Broker of the Service, a Master Open Authorization (OAUTH) Client of the Service;

receiving from the Service Instance, a copy OAUTH Client based on a clone of the Master OAUTH Client, the clone being associated with the Service Instance, the copy OAUTH Client being specific to the User;

providing the copy OAUTH Client to a User Account and Authorization (UAA) entity to obtain a service-specific Token, wherein the UAA entity generates the Token in response to authenticating the User based on the copy OAUTH Client; and

obtaining, access to the Service by providing the service-specific Token.

14. The computer-implemented system of claim 13 , wherein the clone is specific to the Service Instance.

15. The computer-implemented system of claim 13 , wherein the clone is provided according to a UAA Service Instance created by a UAA service broker.

16. The computer-implemented system of claim 15 , wherein the UAA Service Instance is used by the first Service Broker specifically to create the clone for the Service Instance of the Service.

17. The computer-implemented system of claim 13 , wherein:

the clone is specific to the Application; and

the Service Instance is created specifically for the Application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2018
From: DE BOER, MARTIJN; EBERLEIN, PETER; TACK, FLORIAN; ETTELBRUECK, HEIKO
To: SAP SE
Reel/Frame 044739/0872 →
Continuity (1)
Related Publication 20190190912A1 · Jun 20, 2019
Cited By (4)
US 12,499,116 US 12,541,616 US 12,561,225 US 12,689,626