IP Library › Granted Patent US 11,748,499
Granted Patent B2
US 11,748,499 · App. 17/030,025 · Granted Sep 5, 2023

Asynchronous authorization of application access to resources

Inventors: Jeffrey Thomas Sakowicz (Seattle, WA); Adam James Steenwyk (Redmond, WA); Zawad Chowdhury (Seattle, WA); Philippe Signoret (Auvergne-Rhône-Alpes, FR); Luis Carlos Leon Plata (Seattle, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06F21/62G06F9/5027
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,748,499
App. No.
17/030,025
Granted
Sep 5, 2023
Kind
B2
Abstract

According to examples, an apparatus may include a processor that may access a request for access by an application to a resource and may record the request in a data store. The processor may also identify an authorized entity to evaluate the request and output a notification to the authorized entity to evaluate the request, in which the authorized entity is to evaluate the request asynchronously with submission of the request by the application. In addition, the processor may determine whether a response is received from the authorized entity and, based on a determination that the response is received, may reject or grant the request based on the response and clear the record of the request from the data store.

Claims (86)

1. An apparatus comprising:

a processor; and

a memory on which is stored machine-readable instructions that cause the processor to:

access a request for access by an application to a resource;

record the request in a data store;

identify an authorized entity to evaluate the request;

output a notification to the authorized entity to evaluate the request, wherein the authorized entity is to evaluate the request asynchronously with submission of the request by the application;

receive an indication from the authorized entity that the request is granted; and

based on a determination that the request is granted,

submit an authorization grant for the application to access the resource to an authorization server that is to respond with an access token;

forward the access token to the resource to the application, wherein the application is to submit the access token to a resource server to access the resource; and

clear the record of the request from the data store.

2. The apparatus of claim 1 , wherein the instructions cause the processor to:

initiate a timer set to a predefined duration responsive to the output of the notification;

determine whether the response is received prior to expiration of the predefined duration; and

based on a determination that the response is not received prior to expiration of the predefined duration, output a reminder notification to the authorized entity.

3. The apparatus of claim 2 , wherein the instructions cause the processor to:

initiate a second timer set to a second predefined duration responsive to the output of the reminder notification;

determine whether the response is received prior to expiration of the second predefined duration; and

based on a determination that the response is not received prior to expiration of the second predefined duration,

reject the request for access by the application to the resource; and

clear the record of the request from the data store.

4. The apparatus of claim 1 , wherein the instructions cause the processor to:

send a message to a user of the application regarding whether the user would like to seek approval for the request; and

output the notification to the authorized entity based on receipt of an instruction from the user to seek approval for the request.

5. The apparatus of claim 4 , wherein the instructions cause the processor to:

based on the receipt of the instruction from the user to not seek approval for the request,

reject the request for access by the application to the resource; and

clear the record of the request from the data store.

6. The apparatus of claim 1 , wherein, to identify the authorized entity, the instructions cause the processor to:

select the authorized entity from a list of authorized entities.

7. The apparatus of claim 1 , wherein the notification comprises:

a push notification to a device of the authorized entity;

an email message to the authorized entity; and/or

an entry in a queue of pending requests displayed in a dedicated web portal or a mobile application.

8. A method comprising:

recording, by a processor, in a data store, a request by an application to access a resource;

outputting, by the processor, a notification for an authorized entity to evaluate the request, wherein the authorized entity is to evaluate the request asynchronously with submission of the request by the application;

receiving, by the processor, an indication from the authorized entity that the request is granted; and

based on a determination that the request is granted,

submitting, by the processor, an authorization grant for the application to access the resource to an authorization server that is to respond with an access token;

forwarding, by the processor, the access token to the resource to the application, wherein the application is to submit the access token to a resource server to access the resource; and

clearing, by the processor, the record of the request from the data store.

9. The method of claim 8 , further comprising:

initiating a timer set to a predefined duration responsive to the output of the notification;

determining whether the response is received prior to expiration of the predefined duration; and

based on a determination that the response is not received prior to expiration of the predefined duration, outputting a reminder notification to the authorized entity.

10. The method of claim 9 , further comprising:

initiating a second timer set to a second predefined duration responsive to the output of the reminder notification;

determining whether the response is received prior to expiration of the second predefined duration; and

based on a determination that the response is not received prior to expiration of the second predefined duration,

rejecting the request for access by the application to the resource; and

clearing the record of the request from the data store.

11. The method of claim 8 , further comprising:

sending a message to a user of the application regarding whether the user would like to seek approval for the request; and

outputting the notification to the authorized entity based on receipt of an instruction from the user to seek approval for the request.

12. The method of claim 11 , further comprising:

based on receipt of an instruction from the user to not seek approval for the request,

rejecting the request for access by the application to the resource; and

clearing the record of the request from the data store.

13. The method of claim 8 , further comprising:

identifying the authorized entity by selecting the authorized entity from a list of authorized entities.

14. The method of claim 8 , wherein the notification comprises:

a push notification to a device of the authorized entity;

an email message to the authorized entity; and/or

an entry in a queue of pending requests displayed in a dedicated web portal or a mobile application.

15. A non-transitory computer-readable medium on which is stored computer-readable instructions that when executed by a processor, cause the processor to:

record, in a data store, a request for access by an application to a resource;

output a notification to an authorized entity, wherein the authorized entity is to evaluate the request asynchronously with submission by the application of the request and the authorized entity is to return a response as to whether the request is rejected or granted;

receive an indication from the authorized entity that the request is granted; and

based on a determination that the request is granted,

submit an authorization grant for the application to access the resource to an authorization server that is to respond with an access token;

forward the access token to the resource to the application, wherein the application is to submit the access token to a resource server to access the resource; and

clear the record of the request from the data store.

16. The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the processor to:

initiate a timer set to a predefined duration responsive to the output of the notification;

determine whether the response is received prior to expiration of the predefined duration; and

based on a determination that the response is not received prior to expiration of the predefined duration,

output a reminder notification to the authorized entity; or

reject the request.

17. The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the processor to:

send a message to a user of the application regarding whether the user would like to seek approval for the request;

based on receipt of an instruction from the user to seek approval for the request, output the notification to the authorized entity; and

based on receipt of an instruction from the user to not seek approval for the request,

reject the request for access by the application to the resource; and

clear the record of the request from the data store.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2020
From: SAKOWICZ, JEFFREY THOMAS; STEENWYK, ADAM JAMES; CHOWDHURY, ZAWAD; SIGNORET, PHILIPPE; LEON PLATA, LUIS CARLOS
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 054209/0468 →
Continuity (1)
Related Publication 20220092197A1 · Mar 24, 2022