IP Library › Granted Patent US 12,463,811
Granted Patent B2
US 12,463,811 · App. 18/314,292 · Granted Nov 4, 2025

System architecture for secure highly available microservice applications with decentralized authorization and delegated authorization controls in cloud platforms

Inventors: David R. Bowman (Charleston, SC); Preston R. Barbare (Mount Pleasant, SC)
Assignee: THE BOEING COMPANY
H04L9/3213H04L9/3228
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,811
App. No.
18/314,292
Granted
Nov 4, 2025
Kind
B2
Abstract

A device includes one or more processors configured to receive, from a first service, a first access request to request access to a second service on behalf of a user, wherein the first access request includes a user identifier of the user and a first service identifier of the first service. The one or more processors are also configured to, based on determining that the user has granted authorization to the first service to access the second service on behalf of the user, generate a proxy authentication token based on the first access request. The one or more processors are configured to send a second access request to the second service, wherein the second access request includes the first service identifier and the proxy authentication token.

Claims (42)

1 . A device comprising:

one or more processors configured to:

receive, from a first service, a first access request to request access to a second service on behalf of a user, wherein the first access request includes a user identifier of the user and a first service identifier of the first service;

based on determining that the user has granted authorization to the first service to access the second service on behalf of the user, generate a proxy authentication token based on the first access request; and

send a second access request to the second service, wherein the second access request includes the first service identifier and the proxy authentication token.

2 . The device of claim 1 , wherein the one or more processors are configured to generate the proxy authentication token based on determining that the authorization is granted by the user prior to receipt of the first access request.

3 . The device of claim 1 , wherein the one or more processors are configured to generate the proxy authentication token further based on determining that the user is an authorized user of the second service.

4 . The device of claim 1 , wherein the one or more processors are configured to:

send an authorization request to an authorization service, the authorization request indicating the user identifier and a second service identifier of the second service; and

generate the proxy authentication token further based on receiving an authorization response indicating that the user is an authorized user of the second service.

5 . The device of claim 1 , wherein the one or more processors are configured to:

receive data from the second service responsive to the second access request; and

send the data to the first service.

6 . The device of claim 1 , wherein the proxy authentication token indicates the user identifier and the first service identifier.

7 . The device of claim 1 , wherein the one or more processors are further configured to assign an expiration time to the proxy authentication token.

8 . A method comprising:

receiving, from a first service, a first access request to request access to a second service on behalf of a user, wherein the first access request includes a user identifier of the user and a first service identifier of the first service;

based on determining that the user has granted authorization to the first service to access the second service on behalf of the user, generating a proxy authentication token based on the first access request; and

sending a second access request to the second service, wherein the second access request includes the first service identifier and the proxy authentication token.

9 . The method of claim 8 , further comprising determining that the authorization is granted by the user prior to receipt of the first access request.

10 . The method of claim 8 , wherein generating the proxy authentication token is further based on determining that the user is an authorized user of the second service.

11 . The method of claim 8 , further comprising:

sending an authorization request to an authorization service, the authorization request indicating the user identifier and a second service identifier of the second service; and

generating the proxy authentication token further based on receiving an authorization response indicating that the user is an authorized user of the second service.

12 . The method of claim 8 , further comprising:

receiving data from the second service responsive to the second access request, and

sending the data to the first service.

13 . The method of claim 8 , wherein the proxy authentication token indicates the user identifier and the first service identifier.

14 . The method of claim 8 , further comprising assigning an expiration time to the proxy authentication token.

15 . A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

receive, from a first service, a first access request to request access to a second service on behalf of a user, wherein the first access request includes a user identifier of the user and a first service identifier of the first service;

based on determining that the user has granted authorization to the first service to access the second service on behalf of the user, generate a proxy authentication token based on the first access request; and

send a second access request to the second service, wherein the second access request includes the first service identifier and the proxy authentication token.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to generate the proxy authentication token based on determining that the authorization is granted by the user prior to receipt of the first access request.

17 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to generate the proxy authentication token further based on determining that the user is an authorized user of the second service.

18 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to:

send an authorization request to an authorization service, the authorization request indicating the user identifier and a second service identifier of the second service; and

generate the proxy authentication token further based on receiving an authorization response indicating that the user is an authorized user of the second service.

19 . The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the one or more processors to:

receive data from the second service responsive to the second access request; and

send the data to the first service.

20 . The non-transitory computer-readable medium of claim 15 , wherein the proxy authentication token indicates the user identifier and the first service identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2023
From: BOWMAN, DAVID R.; BARBARE, PRESTON R.
To: THE BOEING COMPANY
Reel/Frame 063579/0678 →
Continuity (1)
Related Publication 20240380594A1 · Nov 14, 2024
References Cited (35)
US 8806591B2 · Dallas et al. · 2014 [cited by applicant]
US 8935757B2 · Srinivasan et al. · 2015 [cited by applicant]
US 9800580B2 · Zhang · 2017 [cited by examiner]
US 10084823B2 · Sondhi et al. · 2018 [cited by applicant]
US 10120734B1 · Doraiswamy · 2018 [cited by examiner]
US 10164956B2 · Toomey · 2018 [cited by applicant]
US 10382418B1 · Bar-Menachem et al. · 2019 [cited by applicant]
US 10887301B1 · Vera · 2021 [cited by examiner]
US 10992657B1 · Stevens et al. · 2021 [cited by applicant]
US 11082453B2 · Reddem et al. · 2021 [cited by applicant]
US 11922239B1 · Vasudevan · 2024 [cited by applicant]
US 20080109874A1 · Kulkarni et al. · 2008 [cited by applicant]
US 20090103533A1 · Li et al. · 2009 [cited by applicant]
US 20130263211A1 · Neuman · 2013 [cited by examiner]
US 20130268768A1 · Corlett · 2013 [cited by examiner]
US 20140282972A1 · Fan et al. · 2014 [cited by applicant]
US 20160092297A1 · Mazon · 2016 [cited by examiner]
US 20160259936A1 · Mukherjee et al. · 2016 [cited by applicant]
US 20170142108A1 · Zhang · 2017 [cited by examiner]
US 20170149837A1 · Sondhi et al. · 2017 [cited by applicant]
US 20170257359A1 · Ogawa · 2017 [cited by applicant]
US 20170302451A1 · Wang · 2017 [cited by examiner]
US 20180070233A1 · Soni et al. · 2018 [cited by applicant]
US 20190342280A1 · Shaw et al. · 2019 [cited by applicant]
US 20190386831A1 · Jamkhedkar · 2019 [cited by examiner]
US 20200021574A1 · Pinner et al. · 2020 [cited by applicant]
US 20200382488A1 · Liu · 2020 [cited by examiner]
US 20210021643A1 · Nakagoe · 2021 [cited by examiner]
US 20210042160A1 · Alamouti · 2021 [cited by examiner]
US 20210243198A1 · Naumann zu Koenigsbrueck et al. · 2021 [cited by applicant]
US 20210360034A1 · Olden et al. · 2021 [cited by applicant]
US 20210374747A1 · Ederle et al. · 2021 [cited by applicant]
US 20220131844A1 · Sherlock et al. · 2022 [cited by applicant]
US 20220329584A1 · Sharma · 2022 [cited by examiner]
US 20240089107A1 · Akhter et al. · 2024 [cited by applicant]