IP Library › Granted Patent US 11,870,766
Granted Patent B2
US 11,870,766 · App. 17/123,622 · Granted Jan 9, 2024

Integration of legacy authentication with cloud-based authentication

Inventors: Avraham Carmon (Redmond, WA); Joseph Isenhour (Redmond, WA); Aakashi Kapoor (Seattle, WA); Young Moon Ko (Sammamish, WA); Sagar Bholanath Saha (Renton, WA); Steven Syfuhs (Seattle, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC.
H04L63/0807H04L63/0236H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,870,766
App. No.
17/123,622
Granted
Jan 9, 2024
Kind
B2
Abstract

An identity provider of a cloud computing service provides authentication for on-premise applications that is subject to a legacy authentication protocol that differs from the cloud-based network authentication protocol used by the identity provider. The identity provider generates a security ticket for use to gain access to the on-premise application. The security ticket is embedded in a security token associated with a cloud-based network authentication protocol. A client application seeking access to the on-premise application extracts the embedded security ticket from the security token which is then used to access the on-premise application via a legacy authentication protocol.

Claims (39)

1. A system, comprising:

at least one processor; and

a memory that stores one or more programs that are configured to be executed by the one or more processors, the one or more programs including instructions to perform actions that:

transmit, from a client application, a first request to authenticate the client application to access an on-premise application, the first request sent to an identity provider of a cloud computing service, the first request made through a cloud-based network authentication protocol, the on-premise application subject to a Kerberos authentication protocol, the cloud-based network authentication protocol incompatible with the Kerberos authentication protocol;

in response to a successful authentication of the client application, obtain, at the client application, a security token including at least one claim, wherein the at least one claim includes a Kerberos security ticket of the Kerberos authentication protocol, wherein a claim identifies a granted permission to a resource, the Kerberos security ticket generated by a Kerberos Key Distribution Center included in the identity provider of the cloud computing service, the security token associated with the cloud-based network authentication protocol;

extract, at the client application, the Kerberos security ticket from the security token;

transmit, from the client application, a Kerberos authentication request using the Kerberos authentication protocol to a second Kerberos Key Distribution Center comprising a Kerberos authorization server of the on-premise application, the Kerberos authentication request including the Kerberos security ticket; and

in response to a successful validation of the Kerberos security ticket, obtain, by the client application, access to the on-premise application.

2. The system of claim 1 , wherein the cloud-based network authentication protocol comprises Security Assertion Markup Language (SAML) protocol.

3. The system of claim 1 , wherein the on-premise application is part of a private domain directory service.

4. The system of claim 1 , wherein the security token is a JavaScript Object Notation (JSON) web token.

5. The system of claim 1 , wherein the cloud-based network authentication protocol comprises the Web Services Federation protocol.

6. The system of claim 1 , wherein the client application communicates with the cloud computing service through Representational State Transfer (REST) Application Programming Interfaces (APIs).

7. The system of claim 1 , wherein the cloud-based network authentication protocol is based on OpenId Connect.

8. A computer-implemented method, comprising:

requesting, from a client application, authentication to access an on-premise application from a cloud computing service using a cloud-based authentication protocol, wherein the on-premise application adheres to a Kerberos authentication protocol, the cloud-based authentication protocol adheres to a cloud-based authentication protocol, the Kerberos authentication protocol differs from the cloud-based authentication protocol;

upon successful authentication of the client application, receiving, at the client application, a security token including at least one claim, wherein the at least one claim represents a granted permission to a resource, wherein the at least one claim includes a Kerberos security ticket of the Kerberos authentication protocol, the Kerberos security ticket generated by a Kerberos Key Distribution Center included in an identity provider of the cloud computing service, the security token associated with the cloud-based network authentication protocol;

extracting, at the client application, the Kerberos security ticket from the security token;

transmitting, from the client application, an authentication request using the Kerberos authentication protocol to a second Kerberos Key Distribution Center comprising a Kerberos authorization server of the on-premise application, the Kerberos authentication request including the Kerberos security ticket; and

in response to a successful validation of the Kerberos security ticket, obtaining by the client application, access to the on-premise application.

9. The method of claim 8 , wherein the client application communicates with the cloud computing service through Representational State Transfer (REST) Application Programming Interfaces (APIs).

10. The method of claim 8 , wherein the on-premise application resides in a domain directory service outside of the cloud computing service.

11. The method of claim 8 , wherein the security token is a JavaScript Object Notation (JSON) web token.

12. The method of claim 8 , wherein the cloud-based authentication protocol is based on Oauth/OpenIDConnect (OIDC) protocol.

13. The method of claim 8 , wherein the cloud-based authentication protocol is based on a Security Assertion Markup Language (SAML) protocol or a Web Services Federation protocol.

14. The method of claim 8 , wherein the cloud-based network authentication protocol is based on OpenId Connect.

15. A device, comprising:

at least one processor and a memory;

wherein the at least one processor is configured to perform actions that:

receive an authentication request, at a cloud computing service, for access to an on-premise application, the authentication request associated with a cloud-based authentication protocol from a client application, the on-premise application associated with a Kerberos authentication protocol, the cloud-based authentication protocol differs from the Kerberos authentication protocol; and

upon successful verification of the authentication request:

generate a Kerberos security ticket of the Kerberos authentication protocol from a Kerberos Key Distribution Center included in the identity provider of the cloud computing service and generate an authentication token, wherein the authentication token is of the cloud-based authentication protocol and includes a plurality of claims, wherein at least one claim identifies a granted permission to a resource, wherein the at least one claim includes the Kerberos security ticket; and

provide the authentication token to the client application, wherein the client application authenticates to the on-premise application through the Kerberos authentication protocol by extracting the Kerberos security ticket from the authentication token, and providing the Kerberos security ticket to a second Kerberos Key Distribution Center comprising a Kerberos authentication server of the on-premise application, wherein the client application obtains access to the on-premise application in response to a successful validation of the Kerberos security ticket.

16. The device of claim 15 , wherein the on-premise application resides in a domain outside of the cloud computing service.

17. The device of claim 15 , wherein the at least one processor is further configured to perform actions that:

configure the cloud computing service with on-premise data of the on-premise application, the on-premise data specifying the Kerberos authentication protocol of the on-premise application.

18. The device of claim 15 , wherein the cloud-based network authentication protocol comprises Security Assertion Markup Language (SAML) protocol.

19. The device of claim 15 , wherein the cloud-based authentication protocol is based on Oauth/OpenIDConnect (OIDC) protocol.

20. The device of claim 15 , wherein the Kerberos security token comprises a JavaScript Object Notation (JSON) web token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2020
From: SAHA, SAGAR BHOLANATH; ISENHOUR, JOSEPH; SYFUHS, STEVEN; KO, YOUNG MOON; CARMON, AVRAHAM; KAPOOR, AAKASHI
To: MICROSOFT TECHNOLOGY LICENSING, LLC.
Reel/Frame 054732/0868 →
Continuity (1)
Related Publication 20220191185A1 · Jun 16, 2022