IP Library › Granted Patent US 12,750,365
Granted Patent B2
US 12,750,365 · App. 18/610,076 · Granted Sep 29, 2026

Hybrid authentication systems and methods

Inventors: Sachin Gopaldas Totale (Pleasanton, CA); Muneer Ahmed (Dublin, CA); Harish Rawat (San Jose, CA); Rajakumar Thiruvasagam (Bangalore, IN); Lakshmi Narayana Prasad Kakumani (Northborough, MA)
Assignee: Open Text Corporation
H04L63/0884G06F21/33G06F21/41H04L9/3213H04L9/3228H04L9/3247H04L63/0272H04L63/029H04L63/0807H04L63/0815H04L63/083H04L63/102G06F21/31H04L2209/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,750,365
App. No.
18/610,076
Granted
Sep 29, 2026
Kind
B2
Abstract

Disclosed are hybrid authentication systems and methods that enable users to seamlessly sign-on between cloud-based services and on-premises systems. A cloud-based authentication service receives login credentials from a user and delegates authentication to an on-premises authentication service proxy. The login credentials can be passed by the cloud-based authentication service to the on-premises authentication service proxy, for instance, as an access token in an authentication header. The access token can be a JavaScript Object Notation (JSON) Web Token (JWT) token that is digitally signed using JSON Web Signature. Some embodiments utilize a tunnel connection through which the cloud-based authentication service communicates with the on-premises authentication service proxy. Some embodiments leverage an on-premises identity management system for user management and authentication. In this way, there is no need for a cloud-based system to separately maintain and manage a user identity management system and/or having to sync with an on-premises identity management system.

Claims (41)

1 . A system for hybrid authentication, the system comprising:

a hardware server machine comprising a hardware processor and a non-transitory computer-readable medium storing instructions executable by the hardware processor, the hardware server machine being configured to host a cloud-based authentication service and operating in a cloud computing environment, the cloud computing environment having a cloud-based application; and

a hardware proxy server of the cloud-based authentication service, the hardware proxy server comprising a second hardware processor and a second non-transitory computer-readable medium storing instructions executable by the second hardware processor and deployed on an enterprise network, the enterprise network having an on-premises application;

wherein the cloud-based authentication service, when executed by the hardware processor, is configured for:

in connection with a request to access the on-premises application, receiving credentials of a user from a browser application on a user device;

invoking the hardware proxy server to authenticate the credentials, wherein the hardware proxy server provides a profile of the user once the credentials are authenticated;

generating an authentication code using the profile provided by the hardware proxy server;

providing the authentication code to the browser application;

directing the browser application to the cloud-based application, wherein the browser application provides the authentication code to the cloud-based application for obtaining an access token for accessing the on-premises application; and

providing the access token to the cloud-based application responsive to a message from the cloud-based application containing the authentication code, wherein the cloud-based application sends the access token to the hardware proxy server and wherein the hardware proxy server verifies the access token and processes the request by calling the on-premises application using an impersonated session.

2 . The system of claim 1 , wherein the access token comprises a JavaScript object notation (JSON) Web Token (JWT) token, wherein the JWT token comprises a HyperText Transfer Protocol (HTTP) authentication header, wherein the HTTP authentication header contains a user context, and wherein the impersonated session is established using the user context from the HTTP authentication header.

3 . The system of claim 1 , wherein the enterprise network further comprises a repository and wherein the on-premises application comprises a hardware content server configured for managing content stored in the repository.

4 . The system of claim 3 , wherein the cloud-based authentication service is further configured for determining whether hybrid authentication is enabled for the cloud-based application to connect to the repository.

5 . The system of claim 1 , wherein the enterprise network further comprises an active directory or a key distribution center (KDC) server.

6 . The system of claim 5 , wherein the proxy authenticates the credentials by checking the active directory or obtaining a ticket granting ticket from the KDC server.

7 . The system of claim 1 , wherein the user belongs to multiple groups authorized to access the cloud-based application and wherein the credentials are shared among the multiple groups.

8 . A method for hybrid authentication, the method comprising:

in connection with a request to access an on-premises application in an enterprise network, receiving, by a cloud-based authentication service, credentials of a user from a browser application on a user device, the cloud-based authentication service provided by a server machine operating in a cloud computing environment, the cloud computing environment having a cloud-based application;

invoking, by the cloud-based authentication service, a proxy of the cloud-based authentication service to authenticate the credentials, wherein the proxy of the cloud-based authentication service is deployed on the enterprise network and wherein the proxy provides a profile of the user once the credentials are authenticated;

generating, by the cloud-based authentication service, an authentication code using the profile provided by the proxy;

providing, by the cloud-based authentication service, the authentication code to the browser application;

directing, by the cloud-based authentication service, the browser application to the cloud-based application, wherein the browser application provides the authentication code to the cloud-based application for obtaining an access token for accessing the on-premises application; and

providing, by the cloud-based authentication service, the access token to the cloud-based application responsive to a message from the cloud-based application containing the authentication code, wherein the cloud-based application sends the access token to the proxy and wherein the proxy verifies the access token and processes the request by calling the on-premises application using an impersonated session.

9 . The method according to claim 8 , wherein the access token comprises a JavaScript object notation (JSON) Web Token (JWT) token, wherein the JWT token comprises a HyperText Transfer Protocol (HTTP) authentication header, wherein the HTTP authentication header contains a user context, and wherein the impersonated session is established using the user context from the HTTP authentication header.

10 . The method according to claim 8 , wherein the enterprise network further comprises a repository and wherein the on-premises application comprises a content server configured for managing content stored in the repository.

11 . The method according to claim 10 , wherein the cloud-based authentication service is further configured for determining whether hybrid authentication is enabled for the cloud- based application to connect to the repository.

12 . The method according to claim 8 , wherein the enterprise network further comprises an active directory or a key distribution center (KDC) server.

13 . The method according to claim 12 , wherein the proxy authenticates the credentials by checking the active directory or obtaining a ticket granting ticket from the KDC server.

14 . The method according to claim 8 , wherein the user belongs to multiple groups authorized to access the cloud-based application and wherein the credentials are shared among the multiple groups.

15 . A computer program product for hybrid authentication, the computer program product comprising a non-transitory computer readable medium storing instructions translatable by a processor to provide a cloud-based authentication service in a cloud computing environment, the cloud computing environment having a cloud-based application, wherein the cloud-based authentication service is adapted for:

in connection with a request to access an on-premises application in an enterprise network, receiving credentials of a user from a browser application on a user device, the cloud-based authentication service provided by a server machine operating in a cloud computing environment, the cloud computing environment having a cloud-based application;

invoking a proxy of the cloud-based authentication service to authenticate the credentials, wherein the proxy of the cloud-based authentication service is deployed on the enterprise network and wherein the proxy provides a profile of the user once the credentials are authenticated;

generating an authentication code using the profile provided by the proxy;

providing the authentication code to the browser application;

directing the browser application to the cloud-based application, wherein the browser application provides the authentication code to the cloud-based application for obtaining an access token for accessing the on-premises application; and

providing the access token to the cloud-based application responsive to a message from the cloud-based application containing the authentication code, wherein the cloud-based application sends the access token to the proxy and wherein the proxy verifies the access token and processes the request by calling the on-premises application using an impersonated session.

16 . The computer program product of claim 15 , wherein the access token comprises a JavaScript object notation (JSON) Web Token (JWT) token, wherein the JWT token comprises a HyperText Transfer Protocol (HTTP) authentication header, wherein the HTTP authentication header contains a user context, and wherein the impersonated session is established using the user context from the HTTP authentication header.

17 . The computer program product of claim 15 , wherein the enterprise network further comprises a repository and wherein the on-premises application comprises a content server configured for managing content stored in the repository.

18 . The computer program product of claim 15 , wherein the cloud-based authentication service is further configured for determining whether hybrid authentication is enabled for the cloud-based application to connect to the repository.

19 . The computer program product of claim 15 , wherein the enterprise network further comprises an active directory or a key distribution center (KDC) server.

20 . The computer program product of claim 19 , wherein the proxy authenticates the credentials by checking the active directory or obtaining a ticket granting ticket from the KDC server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2024
From: TOTALE, SACHIN GOPALDAS; AHMED, MUNEER; RAWAT, HARISH; THIRUVASAGAM, RAJAKUMAR; KAKUMANI, LAKSHMI NARAYANA PRASAD
To: OPEN TEXT CORPORATION
Reel/Frame 067003/0814 →
Continuity (5)
Continuation 18182566 · Mar 13, 2023
Continuation 17306686 · May 3, 2021
Continuation 16015420 · Jun 22, 2018
Provisional Application 62527213 · Jun 30, 2017
Related Publication 20250202894A1 · Jun 19, 2025
References Cited (89)
US 6081900A · Subramaniam · 2000 [cited by examiner]
US 7500262B1 · Sanin · 2009 [cited by examiner]
US 8132242B1 · Wu · 2012 [cited by examiner]
US 8464335B1 · Sinha · 2013 [cited by examiner]
US 9210178B1 · Roth · 2015 [cited by examiner]
US 9286465B1 · Jain · 2016 [cited by examiner]
US 9313193B1 · Mehta · 2016 [cited by examiner]
US 9356916B2 · Kravitz · 2016 [cited by examiner]
US 9369433B1 · Paul · 2016 [cited by examiner]
US 9544716B2 · Smereka · 2017 [cited by examiner]
US 9571455B2 · Johnson · 2017 [cited by examiner]
US 9674699B2 · Kanov · 2017 [cited by examiner]
US 9774586B1 · Roche · 2017 [cited by examiner]
US 9992186B1 · Drozd · 2018 [cited by examiner]
US 10009337B1 · Fischer · 2018 [cited by examiner]
US 10025599B1 · Goodson · 2018 [cited by examiner]
US 10044723B1 · Fischer · 2018 [cited by examiner]
US 10057246B1 · Drozd · 2018 [cited by examiner]
US 10205717B1 · Shah · 2019 [cited by examiner]
US 10454931B2 · Hinaman · 2019 [cited by examiner]
US 10484331B1 · Rossman · 2019 [cited by examiner]
US 20020099826A1 · Summers · 2002 [cited by examiner]
US 20040193695A1 · Salo · 2004 [cited by examiner]
US 20050097322A1 · Gustave · 2005 [cited by examiner]
US 20060294196A1 · Feirouz · 2006 [cited by examiner]
US 20070271598A1 · Chen · 2007 [cited by examiner]
US 20080270791A1 · Nystrom · 2008 [cited by examiner]
US 20110023103A1 · Dietrich · 2011 [cited by examiner]
US 20110307947A1 · Kariv · 2011 [cited by examiner]
US 20120005476A1 · Wei · 2012 [cited by examiner]
US 20120096271A1 · Ramarathinam · 2012 [cited by examiner]
US 20120110318A1 · Stone · 2012 [cited by examiner]
US 20120331528A1 · Fu · 2012 [cited by examiner]
US 20130061306A1 · Sinn · 2013 [cited by examiner]
US 20130254847A1 · Adams · 2013 [cited by examiner]
US 20140040999A1 · Zhang · 2014 [cited by examiner]
US 20140047517A1 · Ding · 2014 [cited by examiner]
US 20140237230A1 · Lehnhardt · 2014 [cited by examiner]
US 20140282936A1 · Fitzgerald · 2014 [cited by examiner]
US 20140373092A1 · Hussain · 2014 [cited by examiner]
US 20140373170A1 · Brudnicki · 2014 [cited by examiner]
US 20150012751A1 · Forster · 2015 [cited by examiner]
US 20150096011A1 · Watt · 2015 [cited by examiner]
US 20150156198A1 · Sabin · 2015 [cited by examiner]
US 20150341445A1 · Nikolov · 2015 [cited by examiner]
US 20150372982A1 · Herle · 2015 [cited by examiner]
US 20150381580A1 · Graham, III · 2015 [cited by examiner]
US 20150381596A1 · Johnson · 2015 [cited by examiner]
US 20160036855A1 · Gangadharappa · 2016 [cited by examiner]
US 20160112402A1 · Schwartz · 2016 [cited by examiner]
US 20160117521A1 · Spalka · 2016 [cited by examiner]
US 20160134599A1 · Ross · 2016 [cited by examiner]
US 20160142408A1 · Raepple · 2016 [cited by examiner]
US 20160234186A1 · Leblond · 2016 [cited by examiner]
US 20160241536A1 · Parman · 2016 [cited by examiner]
US 20160261564A1 · Foxhoven · 2016 [cited by examiner]
US 20170104639A1 · Jiang · 2017 [cited by examiner]
US 20170124340A1 · Chiu · 2017 [cited by examiner]
US 20170142094A1 · Doitch · 2017 [cited by examiner]
US 20170169434A1 · Maddocks · 2017 [cited by examiner]
US 20170208038A1 · Hinaman · 2017 [cited by examiner]
US 20170223026A1 · Amiri · 2017 [cited by examiner]
US 20170264640A1 · Narayanaswamy · 2017 [cited by examiner]
US 20170302653A1 · Ortner · 2017 [cited by examiner]
US 20170331812A1 · Lander · 2017 [cited by examiner]
US 20170331815A1 · Pawar · 2017 [cited by examiner]
US 20170331832A1 · Lander · 2017 [cited by examiner]
US 20180013798A1 · Pallas · 2018 [cited by examiner]
US 20180041336A1 · Keshava · 2018 [cited by examiner]
US 20180063077A1 · Tumuluru · 2018 [cited by examiner]
US 20180075231A1 · Subramanian · 2018 [cited by examiner]
US 20180077144A1 · Gangawane · 2018 [cited by examiner]
US 20180081983A1 · Carru · 2018 [cited by examiner]
US 20180131685A1 · Sridhar · 2018 [cited by examiner]
US 20180152300A1 · Rossi · 2018 [cited by examiner]
US 20180159856A1 · Gujarathi · 2018 [cited by examiner]
US 20180191471A1 · Elhaddad · 2018 [cited by examiner]
US 20180288063A1 · Koottayi · 2018 [cited by examiner]
US 20180324172A1 · Unnikrishnan · 2018 [cited by examiner]
US 20180337783A1 · Lu · 2018 [cited by examiner]
US 20180367528A1 · Schwarz · 2018 [cited by examiner]
US 20180373885A1 · Arad · 2018 [cited by examiner]
US 20190018697A1 · Larsson · 2019 [cited by examiner]
US 20190050551A1 · Goldman-Kirst · 2019 [cited by examiner]
US 20190188696A1 · Carpenter · 2019 [cited by examiner]
US 20190207812A1 · Li · 2019 [cited by examiner]
US 20190268332A1 · Wang · 2019 [cited by examiner]
US 20200014659A1 · Chasman · 2020 [cited by examiner]
US 20200195614A1 · Chanak · 2020 [cited by examiner]