IP Library › Granted Patent US 12,107,843
Granted Patent B2
US 12,107,843 · App. 17/533,315 · Granted Oct 1, 2024

Accessing cloud data providers with user-impersonation

Inventors: Sathya G (Kerala, IN); Sateesh Babu Chilamakuri (Tirupati, IN)
Assignee: SAP SE
H04L63/0815H04L63/083H04L63/0876H04L63/102H04L63/105H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,107,843
App. No.
17/533,315
Granted
Oct 1, 2024
Kind
B2
Abstract

Disclosed herein are system, method, and computer-readable medium embodiments for securely accessing cloud data providers with user-impersonation. An embodiment operates by receiving an initial logon request for a cloud data provider. The embodiment authenticates the request using a cluster unique identifier (CUID) of the cloud data provider. The embodiment then authorizes the request by exchanging an authorization code for an identifier token and a refresh token issued by the cloud data provider. The embodiment then validates the tokens, and stores the refresh token for subsequent user-impersonation logons. Subsequently, the embodiment receives a user-impersonation logon request for the cloud data provider. The embodiment exchanges the refresh token for an access token issued by the cloud data provider, and uses the access token to gain access to the cloud data provider without a user directly having to complete authentication and authorization processes.

Claims (81)

1. A computer implemented method for accessing a cloud data provider with user-impersonation, comprising:

retrieving a cluster unique identifier (CUID) from a database in response to receiving an initial logon request from a server, wherein the CUID represents a configuration of the cloud data provider;

sending the initial logon request to the server based on the CUID, thereby performing a first logon to the cloud data provider using a first user identity associated with a first user;

retrieving an authorization code from the cloud data provider in response to sending the initial logon request to the server;

exchanging the authorization code for an identifier token and a refresh token issued by the cloud data provider;

validating the identifier token and the refresh token based on the CUID and a token length threshold;

storing the refresh token in the database based on the CUID in response to validating the identifier token and the refresh token;

receiving a user-impersonation logon request from a second user identity associated with a second user;

in response to receiving the user-impersonation logon request from the second user, retrieving the refresh token from the database based on the CUID;

exchanging, based on the CUID, the refresh token for an access token issued by the cloud data provider; and

sending the user-impersonation logon request for the second user and the access token received in exchange for the refresh token, to the server, thereby performing a second logon to the cloud data provider using the second user identity, wherein the second logon impersonates the first logon,

wherein at least one of the retrieving a CUID, sending the initial logon request, retrieving an authorization code, exchanging the authorization code, validating, storing, retrieving the refresh token, exchanging the refresh token, and sending the user-impersonation logon request are performed by one or more computers.

2. The computer implemented method of claim 1 , further comprising:

generating a uniform resource identifier (URI) based on the CUID.

3. The computer implemented method of claim 1 , the validating further comprising:

comparing an issuer uniform resource identifier (URI) or a token expiry value of the identifier token to the CUID.

4. The computer implemented method of claim 1 , the validating further comprising:

applying a hashing algorithm to the identifier token, thereby generating a hash value; and

comparing the hash value to the CUID.

5. The computer implemented method of claim 1 , the validating further comprising:

determining that the refresh token is less than or equal to the token length threshold.

6. The computer implemented method of claim 1 , the validating further comprising:

determining that an email identifier of the cloud data provider corresponds to the first user identity.

7. The computer implemented method of claim 1 , further comprising:

receiving, from the server, a logon request for a second cloud data provider;

retrieving a second refresh token from the database based on a second CUID;

exchanging the second refresh token for a second access token issued by the second cloud data provider; and

sending the logon request and the second access token to the server, thereby performing a logon to the second cloud data provider using the second user identity and storing processed data, wherein the logon impersonates an earlier logon to the second cloud data provider and the processed data was received by the server in the earlier logon and was processed by a report server.

8. The computer implemented method of claim 1 , wherein the refresh token has a lifetime longer than a lifetime of the access token.

9. A system for accessing a cloud data provider with user-impersonation, comprising:

a memory; and

at least one processor coupled to the memory and configured to:

retrieve a cluster unique identifier (CUID) from a database in response to receiving an initial logon request from a server, wherein the CUID represents a configuration of the cloud data provider;

send the initial logon request to the server based on the CUID, thereby performing a first logon to the cloud data provider with use of a first user identity associated with a first user;

retrieve an authorization code from the cloud data provider in response to the initial logon request being sent to the server;

exchange the authorization code for an identifier token and a refresh token issued by the cloud data provider;

validate the identifier token and the refresh token based on the CUID and a token length threshold;

store the refresh token in the database based on the CUID in response to validation of the identifier token and the refresh token;

receive a user-impersonation logon request from a second user identity associated with a second user;

in response to receipt of the user-impersonation logon request from the second user, retrieving the refresh token from the database based on the CUID;

exchange, based on the CUID, the refresh token for an access token issued by the cloud data provider; and

send the user-impersonation logon request for the second user and the access token received in exchange for the refresh token, to the server, thereby performing a second logon to the cloud data provider using the second user identity, wherein the second logon impersonates the first logon.

10. The system of claim 9 , the at least one processor further configured to:

generate a uniform resource identifier (URI) based on the CUID.

11. The system of claim 9 , wherein to validate, the at least one processor is configured to:

compare an issuer uniform resource identifier (URI) or a token expiry value of the identifier token to the CUID.

12. The system of claim 9 , wherein to validate, the at least one processor is configured to:

apply a hashing algorithm to the identifier token, to generate a hash value; and

compare the hash value to the CUID.

13. The system of claim 9 , wherein to validate, the at least one processor is configured to:

determine that the refresh token is less than or equal to the token length threshold.

14. The system of claim 9 , wherein to validate, the at least one processor is configured to:

determine that an email identifier of the cloud data provider corresponds to the first user identity.

15. The system of claim 9 , the at least one processor further configured to:

receive, from the server, a logon request for a second cloud data provider;

retrieve a second refresh token from the database based on a second CUID;

exchange the second refresh token for a second access token issued by the second cloud data provider; and

send the logon request and the second access token to the server, to perform a logon to the second cloud data provider with use of the second user identity and to store processed data, wherein the logon impersonates an earlier logon to the second cloud data provider and the processed data was received by the server in the earlier logon and was processed by a report server.

16. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:

retrieving a cluster unique identifier (CUID) from a database in response to receiving an initial logon request from a server, wherein the CUID represents a configuration of a cloud data provider;

sending the initial logon request to the server based on the CUID, thereby performing a first logon to the cloud data provider using a first user identity associated with a first user;

retrieving an authorization code from the cloud data provider in response to sending the initial logon request to the server;

exchanging the authorization code for an identifier token and a refresh token issued by the cloud data provider;

validating the identifier token and the refresh token based on the CUID and a token length threshold;

storing the refresh token in the database based on the CUID in response to validating the identifier token and the refresh token;

receiving a user-impersonation logon request from a second user identity associated with a second user;

in response to receiving the user-impersonation logon request from the second user, retrieving the refresh token from the database based on the CUID;

exchanging, based on the CUID, the refresh token for an access token issued by the cloud data provider; and

sending the user-impersonation logon request for the second user and the access token received in exchange for the refresh token, to the server, thereby performing a second logon to the cloud data provider using the second user identity, wherein the second logon impersonates the first logon.

17. The non-transitory computer-readable medium of claim 16 , the operations further comprising:

generating a uniform resource identifier (URI) based on the CUID.

18. The non-transitory computer-readable medium of claim 16 , the validating comprising:

applying a hashing algorithm to the identifier token, thereby generating a hash value; and

comparing the hash value to the CUID.

19. The non-transitory computer-readable medium of claim 16 , the validating comprising:

determining that an email identifier of the cloud data provider corresponds to the first user identity.

20. The non-transitory computer-readable medium of claim 16 , the operations further comprising:

receiving, from the server, a logon request for a second cloud data provider;

retrieving a second refresh token from the database based on a second CUID;

exchanging the second refresh token for a second access token issued by the second cloud data provider; and

sending the logon request and the second access token to the server, thereby performing a logon to the second cloud data provider using the second user identity and storing processed data, wherein the logon impersonates an earlier logon to the second cloud data provider and the processed data was received by the server in the earlier logon and was processed by a report server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2023
From: G, SATHYA; CHILAMAKURI, SATEESH BABU
To: SAP SE
Reel/Frame 062638/0646 →
Continuity (1)
Related Publication 20230164131A1 · May 25, 2023