IP Library Granted Patent US 9,722,980
Granted Patent B2
US 9,722,980 · App. 15/070,805 · Granted Aug 1, 2017

System and method for securing authentication information in a networked environment

Inventors: Craig Robert William Forster (Austin, TX); Daniel Thomas Greff (Austin, TX); Crandall B. T. Chow (Austin, TX); Phillip Goldenburg (Austin, TX)
Assignee: Sailpoint Technologies, Inc.
H04L63/061G06F21/31H04L9/30H04L63/029H04L63/0428H04L63/08G06F2221/2115H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,722,980
App. No.
15/070,805
Granted
Aug 1, 2017
Kind
B2
Abstract

This disclosure is directed to systems and methods for securely communicating authentication information in a networked environment such as one involving a client device, a cloud based computing platform, and an enterprise computing environment. Some embodiments may include encrypting, by a client device using a public key, authentication information provided by a user. The encrypted authentication information is sent to a cloud based service which then sends it to an on-premises component residing behind a firewall of an enterprise. The on-premises component decrypts the authentication information using a private key, validates the authentication information, and returns the result to the cloud based service over a network. If validated, the cloud based service establishes a secure connection between the client device and the on-premises component such that the user can access the enterprise's content without the enterprise having to share the authentication information with the cloud based service.

Claims (34)

1. A method, comprising:

encrypting, by a client device operated by a first party using a public key, original authentication information provided by the first party at the client device to generate encrypted authentication information, wherein the public key and an instruction for encrypting the authentication information were provided by a remote service operated by a second party in response to an access to the remote service by the client device operated by the first party;

the client device providing the encrypted authentication information to the remote service operated by the second party;

the remote service providing the encrypted authentication information to an on-premises component of an enterprise operated by a third party distinct from the first party and second party;

the on-premises component decrypting the encrypted authentication information using a private key corresponding to the public key provided by the remote service operated by the second party to obtain the original authentication information;

the on-premises component performing a validation on the original authentication information; and

the on-premises component returning a result of the validation to the remote service over a network, wherein the result is signed by the on-premises component using the private key such that the remote service operated by the second party can verify the result was sent by the on-premises component behind a firewall of the enterprise operated by the third party.

2. The method according to claim 1 , wherein performing the validation comprises comparing the original authentication information to authentication information at the on-premises component.

3. The method according to claim 1 , wherein the instruction comprises an application executed at the client device.

4. The method according to claim 3 , wherein the application is a JavaScript application executed by a browser at the client device.

5. The method according to claim 1 , wherein the enterprise is operated by a fourth party distinct from the first party, the second party and the third party.

6. A non-transitory computer readable medium storing instructions translatable by at least one processor to perform:

encrypting, by a client device operated by a first party using a public key, original authentication information provided by the first party at the client device to generate encrypted authentication information, wherein the public key and an instruction for encrypting the authentication information were provided by a remote service operated by a second party in response to an access to the remote service by the client device operated by the first party;

the client device providing the encrypted authentication information to the remote service operated by the second party;

the remote service providing the encrypted authentication information to an on-premises component of an enterprise operated by a third party distinct from the first party and second party;

the on-premises component decrypting the encrypted authentication information using a private key corresponding to the public key provided by the remote service operated by the second party to obtain the original authentication information;

the on-premises component performing a validation on the original authentication information; and

the on-premises component returning a result of the validation to the remote service over a network, wherein the result is signed by the on-premises component using the private key such that the remote service operated by the second party can verify the result was sent by the on-premises component behind a firewall of the enterprise operated by the third party.

7. The non-transitory computer readable medium according to claim 6 , wherein performing the validation comprises comparing the original authentication information to authentication information at the on-premises component.

8. The non-transitory computer readable medium according to claim 6 , wherein the instruction comprises an application executed at the client device.

9. The non-transitory computer readable medium according to claim 8 , wherein the application is a JavaScript application executed by a browser at the client device.

10. The non-transitory computer readable medium according to claim 6 , wherein the enterprise is operated by a fourth party distinct from the first party, the second party and the third party.

11. A system, comprising:

at least one processor: and

at least one non-transitory computer readable medium storing instructions for configuring the at least one processor to perform the steps of:

encrypting, by a client device operated by a first party using a public key, original authentication information provided by the first party at the client device to generate encrypted authentication information, wherein the public key and an instruction for encrypting the authentication information were provided by a remote service operated by a second party in response to an access to the remote service by the client device operated by the first party;

the client device providing the encrypted authentication information to the remote service operated by the second party;

the remote service providing the encrypted authentication information to an on- premises component of an enterprise operated by a third party distinct from the first party and second party;

the on-premises component decrypting the encrypted authentication information using a private key corresponding to the public key provided by the remote service operated by the second party to obtain the original authentication information;

the on-premises component performing a validation on the original authentication information; and the on-premises component returning a result of the validation to the remote service over a network, wherein the result is signed by the on-premises component using the private key such that the remote service operated by the second party can verify the result was sent by the on-premises component behind a firewall of the enterprise operated by the third party.

12. The system according to claim 11 , wherein performing the validation comprises comparing the original authentication information to authentication information at the on-premises component.

13. The system according to claim 11 , wherein the instruction comprises an application executed at the client device.

14. The system according to claim 13 , wherein the application is a JavaScript application executed by a browser at the client device.

15. The system according to claim 11 , wherein the enterprise is operated by a fourth party distinct from the first party, the second party and the third party.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2025
From: GOLUB CAPITAL MARKETS LLC
To: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
Reel/Frame 071776/0411 →
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
SECURITY INTEREST Recorded Aug 17, 2022
From: SAILPOINT TECHNOLOGIES, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 061202/0540 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 048581/0689 Recorded Aug 16, 2022
From: CITIBANK, N.A.
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 061200/0795 →
GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 13, 2019
From: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 048581/0689 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2018
From: GOLDMAN SACHS BANK USA
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 047632/0011 →
CHANGE OF ADDRESS FOR ASSIGNEE Recorded Oct 11, 2018
From: GOLDMAN SACHS BANK USA
To: GOLDMAN SACHS BANK USA
Reel/Frame 047215/0114 →
SECURITY INTEREST Recorded Aug 16, 2016
From: SAILPOINT TECHNOLOGIES, INC., AS GRANTOR
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 039458/0289 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2016
From: FORSTER, CRAIG ROBERT WILLIAM; GREFF, DANIEL THOMAS; CHOW, CRANDALL B.T.; GOLDENBURG, PHILLIP
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 038004/0718 →
Continuity (3)
Continuation 14318133 · Jun 27, 2014
Provisional Application 61842831 · Jul 3, 2013
Related Publication 20160197900A1 · Jul 7, 2016