IP Library › Granted Patent US 12,273,343
Granted Patent B2
US 12,273,343 · App. 18/048,710 · Granted Apr 8, 2025

Techniques for dynamically assigning client credentials to an application

Inventors: Gregg Alan Wilson (Austin, TX); Venkata Subbarao Evani (Fremont, CA); Martinus Petrus Lambertus van den Dungen (Snohomish, WA); Girish Nagaraja (Sammamish, WA); Gary Philip Cole (Redwood Shores, CA)
Assignee: Oracle International Corporation
H04L63/0876H04L63/0807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,343
App. No.
18/048,710
Granted
Apr 8, 2025
Kind
B2
Abstract

An identity management and authorization system (IMAS) receives a request to download an application to a user device associated with a user. The IMAS downloads, to the user device, a template application instance corresponding to the requested application, the template application instance having a reduced functionality than the requested application. The IMAS receives, from the user device, a request to register to the downloaded template. Responsive to receiving the request to register the application, the IMAS causes the template application instance on the user device to transition to an application instance of the application with full functionality, generates an application instance-specific credential for the application instance, associates the generated application instance-specific credential with the application instance, and stores the application instance-specific credential in association with (1) an application identifier identifying the application instance, (2) a user identifier identifying the user, and (3) a user device identifier identifying the user device.

Claims (80)

1. A method comprising:

receiving, by an identity management and authorization system (IMAS), a request to download an application to a user device associated with a user, the IMAS implemented using one or more computing systems;

downloading, to the user device, a template application instance corresponding to the requested application, the template application instance having a reduced functionality than the requested application;

receiving, by the IMAS and from the user device, a request to register to the downloaded template application;

responsive to receiving the request to register the application:

causing the template application instance on the user device to transition to an application instance of the application with full functionality;

generating an application instance-specific credential for the application instance; and

associating the generated application instance-specific credential with the application instance; and

storing, by the IMAS, the application instance-specific credential in association with (1) an application identifier identifying the application instance, (2) a user identifier identifying the user, and (3) a user device identifier identifying the user device.

2. The method of claim 1 , further comprising:

using the application instance-specific credential in a access workflow initiated in response to a request by the application instance to access a protected resource.

3. The method of claim 2 , wherein using the application instance-specific credential in the access workflow comprises:

receiving, from the application instance, the application instance-specific credential and a request for an access token;

responsive to verifying the application instance-specific credential, generating the access token; and

transmitting, to the instance, the access token, wherein the application instance can use the access token to request or otherwise access data from a third party system.

4. The method of claim 3 , wherein the request for the access token includes scope information identifying a scope of data requested from the third party system, wherein the generated access token comprises the scope information, and wherein the application instance can use the access token to request or otherwise access the scope of data from the third party system.

5. The method of claim 1 , further comprising,

receiving, from a computing system, an application instance identifier and a request to deactivate the application instance;

identifying, in a memory based on the received application instance identifier, the application instance-specific credential; and

deleting the stored application instance-specific credential from the memory.

6. The method of claim 5 , further comprising,

receiving, from the application instance, an access request including the application instance-specific credential; and

responsive to not identifying the application instance-specific credential in the memory, ceasing a communication with the application instance.

7. The method of claim 1 , further comprising,

receiving, from a computing system, the application identifier and a request to disable all application instances associated with the application identifier; and

responsive to receiving the request, deleting, from a memory, the application identifier.

8. The method of claim 1 , wherein a memory stores other application instance-specific credentials of one or more other application instances associated with the user, the application instance-specific credentials of each of the one or more other application instances stored in the memory in association with the user identifier identifying the user, and further comprising,

receiving, from a computing system, the user identifier and a request to disable all application instances associated with the user identifier; and

responsive to receiving the request, deleting, from the memory and based on the user identifier, the application instance specific credentials of the instance and the other application instance specific credentials of each of the one or more other application instances.

9. The method of claim 1 , wherein a memory stores other application instance-specific credentials of one or more other application instances associated with the user device, the application instance-specific credentials of each of the one or more other application instances stored in the memory in association with the user device identifier, and further comprising,

receiving, from a computing system, the user device identifier and a request to disable all application instances associated with the user device identifier; and

responsive to receiving the request, deleting, from the memory and based on the user device identifier, the application instance specific credentials of the instance and the other application instance specific credentials of each of the one or more other client application instances.

10. A system, comprising:

one or more processors; and

a non-transitory computer-readable storage medium comprising computer-executable instructions that, when executed by the processor, cause the system to perform processing comprising:

receiving a request to download an application to a user device associated with a user;

downloading, to the user device, a template application instance corresponding to the requested application, the template application instance having a reduced functionality than the requested application;

receiving, from the user device, a request to register to the downloaded template application;

responsive to receiving the request to register the application:

causing the template application instance on the user device to transition to an application instance of the application with full functionality;

generating an application instance-specific credential for the application instance; and

associating the generated application instance-specific credential with the application instance; and

storing the application instance-specific credential in association with (1) an application identifier identifying the application instance, (2) a user identifier identifying the user, and (3) a user device identifier identifying the user device.

11. The system of claim 10 , the processing further comprising:

using the application instance-specific credential in a access workflow initiated in response to a request by the application instance to access a protected resource.

12. The system of claim 10 , the processing further comprising,

receiving, from a computing system, an application instance identifier request to deactivate the application instance associated with the application instance identifier;

identifying, in a memory based on the received application instance identifier, the application instance-specific credential; and

deleting the stored application instance-specific credential from the memory.

13. The system of claim 12 , the processing further comprising,

receiving, from the application instance, an access request including the application instance-specific credential; and

responsive to not identifying the application instance-specific credential in the memory, ceasing a communication with the application instance.

14. The system of claim 10 , the processing further comprising,

receiving, from a computing system, the application identifier and a request to disable all application instances associated with the application identifier; and

responsive to receiving the request, deleting, from a memory, the application identifier.

15. The system of claim 10 , wherein a memory stores other application instance-specific credentials of one or more other application instances associated with the user, the application instance-specific credentials of each of the one or more other application instances stored in the memory in association with the user identifier identifying the user, the processing further comprising,

receiving, from a computing system, the user identifier and a request to disable all application instances associated with the user identifier; and

responsive to receiving the request, deleting, from the memory and based on the user identifier, the application instance specific credentials of the instance and the other application instance specific credentials of each of the one or more other application instances.

16. The system of claim 10 , wherein a memory stores other application instance-specific credentials of one or more other application instances associated with the user device, the application instance-specific credentials of each of the one or more other application instances stored in the memory in association with the user device identifier, the processing further comprising,

receiving, from a computing system, the user device identifier and a request to disable all application instances associated with the user device identifier; and

responsive to receiving the request, deleting, from the memory and based on the user device identifier, the application instance specific credentials of the instance and the other application instance specific credentials of each of the one or more other client application instances.

17. A non-transitory computer-readable storage medium comprising computer-executable instructions that when executed by a processor, cause the processor to perform processing comprising:

receiving a request to download an application to a user device associated with a user;

downloading, to the user device, a template application instance corresponding to the requested application, the template application instance having a reduced functionality than the requested application;

receiving, from the user device, a request to register to the downloaded template application;

responsive to receiving the request to register the application:

causing the template application instance on the user device to transition to an application instance of the application with full functionality;

generating an application instance-specific credential for the application instance; and

associating the generated application instance-specific credential with the application instance; and

storing the application instance-specific credential in association with (1) an application identifier identifying the application instance, (2) a user identifier identifying the user, and (3) a user device identifier identifying the user device.

18. The non-transitory computer-readable storage medium of claim 17 , the processing further comprising,

receiving, from a computing system, an application instance identifier request to deactivate the application instance associated with the application instance identifier;

identifying, in a memory based on the received application instance identifier, the application instance-specific credential; and

deleting the stored application instance-specific credential from the memory.

19. The non-transitory computer-readable storage medium of claim 18 , the processing further comprising,

receiving, from the application instance, an access request including the application instance-specific credential; and

responsive to not identifying the application instance-specific credential in the memory, ceasing a communication with the application instance.

20. The non-transitory computer-readable storage medium of claim 17 , the processing further comprising,

receiving, from a computing system, the application identifier and a request to disable all application instances associated with the application identifier; and

responsive to receiving the request, deleting, from a memory, the application identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2022
From: WILSON, GREGG ALAN; EVANI, VENKATA SUBBARAO; VAN DEN DUNGEN, MARTINUS PETRUS LAMBERTUS; NAGARAJA, GIRISH; COLE, GARY PHILIP
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 061525/0844 →
Continuity (2)
Provisional Application 63275613 · Nov 4, 2021
Related Publication 20230132934A1 · May 4, 2023
References Cited (93)
US 8856905B2 · Lundblade · 2014 [cited by applicant]
US 9225532B2 · Counterman · 2015 [cited by applicant]
US 9305000B1 · Bandopadhyay · 2016 [cited by examiner]
US 9781122B1 · Wilson et al. · 2017 [cited by applicant]
US 9787665B2 · Korat et al. · 2017 [cited by applicant]
US 9838376B1 · Lander et al. · 2017 [cited by applicant]
US 9838377B1 · Lander et al. · 2017 [cited by applicant]
US 10044695B1 · Cahill · 2018 [cited by examiner]
US 10200358B2 · Lander et al. · 2019 [cited by applicant]
US 10218705B2 · Wilson et al. · 2019 [cited by applicant]
US 10255061B2 · Lander et al. · 2019 [cited by applicant]
US 10261836B2 · Bansal et al. · 2019 [cited by applicant]
US 10263947B2 · Vats et al. · 2019 [cited by applicant]
US 10341410B2 · Lander et al. · 2019 [cited by applicant]
US 10348858B2 · Theebaprakasam et al. · 2019 [cited by applicant]
US 10425386B2 · Wardell et al. · 2019 [cited by applicant]
US 10445395B2 · Carru et al. · 2019 [cited by applicant]
US 10454915B2 · Mohamad Abdul et al. · 2019 [cited by applicant]
US 10454940B2 · Lander et al. · 2019 [cited by applicant]
US 10484243B2 · Cole et al. · 2019 [cited by applicant]
US 10484382B2 · Wilson et al. · 2019 [cited by applicant]
US 10505941B2 · Vats et al. · 2019 [cited by applicant]
US 10511589B2 · Gangawane et al. · 2019 [cited by applicant]
US 10516672B2 · Gupta et al. · 2019 [cited by applicant]
US 10530578B2 · Keshava et al. · 2020 [cited by applicant]
US 10567364B2 · Vats et al. · 2020 [cited by applicant]
US 10579367B2 · Lander et al. · 2020 [cited by applicant]
US 10581820B2 · Keshava et al. · 2020 [cited by applicant]
US 10585682B2 · Jain et al. · 2020 [cited by applicant]
US 10594684B2 · Bansal et al. · 2020 [cited by applicant]
US 10616224B2 · Subramanian et al. · 2020 [cited by applicant]
US 10693861B2 · Lander et al. · 2020 [cited by applicant]
US 10715564B2 · Mohamad Abdul et al. · 2020 [cited by applicant]
US 10721237B2 · Vats et al. · 2020 [cited by applicant]
US 10735394B2 · Gupta et al. · 2020 [cited by applicant]
US 10764273B2 · Mohamad Abdul et al. · 2020 [cited by applicant]
US 10791087B2 · Medam et al. · 2020 [cited by applicant]
US 10798165B2 · Srinivasan et al. · 2020 [cited by applicant]
US 10831789B2 · Srinivasan et al. · 2020 [cited by applicant]
US 10834137B2 · Pitre et al. · 2020 [cited by applicant]
US 10846390B2 · Subramanian et al. · 2020 [cited by applicant]
US 10848543B2 · Lander et al. · 2020 [cited by applicant]
US 10878079B2 · Vepa et al. · 2020 [cited by applicant]
US 10904074B2 · Wilson et al. · 2021 [cited by applicant]
US 10931656B2 · Carru et al. · 2021 [cited by applicant]
US 11023555B2 · Carru et al. · 2021 [cited by applicant]
US 11061929B2 · Xu et al. · 2021 [cited by applicant]
US 11088993B2 · Wardell et al. · 2021 [cited by applicant]
US 11165634B2 · Medam et al. · 2021 [cited by applicant]
US 11308132B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11321343B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11669321B2 · Srinivasan et al. · 2023 [cited by applicant]
US 20090292545A1 · Mohammed · 2009 [cited by examiner]
US 20130254125A1 · Sanders · 2013 [cited by examiner]
US 20140337525A1 · Branton · 2014 [cited by examiner]
US 20170078886A1 · Raleigh · 2017 [cited by examiner]
US 20170150332A1 · Palanisamy · 2017 [cited by examiner]
US 20200084281A1 · Ley · 2020 [cited by examiner]
US 20210081252A1 · Bhargava et al. · 2021 [cited by applicant]
US 20210084031A1 · Lao et al. · 2021 [cited by applicant]
CN 108322471B · 2019 [cited by applicant]
CN 108337260B · 2019 [cited by applicant]
CN 108322472B · 2019 [cited by applicant]
CN 107852417B · 2021 [cited by applicant]
CN 109639687B · 2021 [cited by applicant]
CN 109565505B · 2021 [cited by applicant]
CN 109314704B · 2021 [cited by applicant]
DE 102017003243B4 · 2018 [cited by applicant]
EP 3311548B1 · 2019 [cited by applicant]
EP 3361702B1 · 2019 [cited by applicant]
EP 3528454B1 · 2020 [cited by applicant]
EP 3494683B1 · 2020 [cited by applicant]
EP 3577885B1 · 2021 [cited by applicant]
EP 3361700B1 · 2021 [cited by applicant]
EP 3361701B1 · 2021 [cited by applicant]
JP 6491381B2 · 2019 [cited by applicant]
JP 6491774B2 · 2019 [cited by applicant]
JP 6491796B2 · 2019 [cited by applicant]
JP 6917331B2 · 2021 [cited by applicant]
KR 101871902B1 · 2018 [cited by applicant]
KR 101873941B1 · 2018 [cited by applicant]
KR 101874384B1 · 2018 [cited by applicant]
KR 102041941B1 · 2019 [cited by applicant]
Zhang et al., Security Enforcement Model for Distributed Usage Control, Jun. 13, 2008, IEEE, pp. 10-18. (Year: 2008). [cited by examiner]
Koenen et al., The Long March to Interoperable Digital Rights Management, Jun. 30, 2004, IEEE, pp. 883-897. (Year: 2004). [cited by examiner]
Manage Instance ID Data, Feb. 3, 2022, 4 pages, https://firebase.google.com/support/privacy/manage-iids. [cited by applicant]
Client Credentials Flow, Feb. 3, 2022, 1 page, https://auth0.com/docs/get-started/authentication-and-authorization-flow/client-credentials-flow. [cited by applicant]
Client Credentials, Feb. 3, 2022, 2 pages, https://www.oauth.com/oauth2-servers/access-tokens/clients-credentials/. [cited by applicant]
What is Instance ID?, Feb. 1, 2022, 4 pages. https://developers.google.com/instance-id. [cited by applicant]
Using an IAM role to grant permissions to applications running on Amazon EC2 instances, 2022, 8 pages, https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_switch-role-ec2.html. [cited by applicant]
Ye, et al., How to dynamically generate GCP IAM credentials with a new HashiCorp Vault secrets engine, Apr. 10, 2018, 5 pages, https://cloud.google.com/blog/products/identity-security/how-you-and-wepay-can-use-hashicorp… [cited by applicant]
Dynamic Client Registration API, 2021, 25 pages, https://developer.okta.com/docs/reference/api/oauth-clients/. [cited by applicant]
Farrell, OAuth: Dynamic Client Registration, IBM Security Identity and Access, Jun. 18, 2018, 12 pages, https://www.ibm.com/blogs/security-identity-access/oauth-dynamic-client-registration/. [cited by applicant]