IP Library Granted Patent US 9,479,503
Granted Patent B2
US 9,479,503 · App. 14/971,104 · Granted Oct 25, 2016

Authenticating cloud computing enabling secure services

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,479,503
App. No.
14/971,104
Granted
Oct 25, 2016
Kind
B2
Abstract

Authenticating cloud computing enabling secure services (ACCESS) offloads “client authentication” activity onto a third-party authenticating cloud computing enabling secure services (ACCESS) node. Instead of having a client device authenticate itself directly to a network server, the client device instead authenticates itself to a third-party authenticating cloud computing enabling secure services (ACCESS) node. The authenticating cloud computing enabling secure services (ACCESS) node then provides credentials that are used by the client device to communicate directly with the server (and utilize the service) without any further authentication being necessary.

Claims (24)

1. A method of pre-authenticating a client device for direct access to a cloud-based secure service, comprising:

receiving a registration message from a client device, at an access node separate from a cloud-based secure service server, said registration message being encrypted using a cryptographic key, wherein said registration message comprises a unique service instance identifier;

passing a pre-authorized authentication token together with a redirect to said client device, said pre-authorized authentication token for provision by said client device directly to said cloud-based secure service server without passage through said access node, wherein said pre-authorized authorization token comprises a set of key-value pairs containing credentials for said client device;

providing a notification, when authenticated, from said access node to said cloud-based secure service server, said notification identifying said client device;

providing said cloud-based secure service server with a list of security items to enforce; and

receiving a request at said access node, from said cloud-based secure service server, to verify validity of said pre-authorized authentication token received by said cloud-based secure service server from said client device;

whereby said client device directly provides said pre-authorized authorization token to said cloud-based secure service server bypassing said access node to directly access said cloud-based secure service server.

2. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein: said request from said cloud-based secure service server requests additional information regarding authentication of said client device to access a cloud-based secure service on said cloud-based secure service server.

3. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein: said access node is a third-party with respect to said cloud-based secure service server.

4. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein: all communications between said client device and said cloud-based secure service server involves encrypted transport.

5. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said credentials comprise: passwords.

6. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said credentials comprise: biometric data about an authorized user of said client device.

7. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said credentials comprise: a current location of said client device.

8. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said credentials comprise: a direction of travel of said client device.

9. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said credentials comprise: previous locations of said client device.

10. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said credentials comprise: historical records regarding previous successful authentications by said client device.

11. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said credentials comprise: a seeded pseudorandom number generator.

12. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said security items comprise: a set of secret cryptographic keys.

13. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said security items comprise: a set of secret cryptographic certificates.

14. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said security items comprise: a list of users, roles and principals.

15. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said security items comprise: resources to be utilized and protected.

16. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein said registration message further comprises: a service identifier status.

17. The method of pre-authenticating a client device for direct access to a cloud-based secure service according to claim 16 , wherein said registration message further comprises: a notification method.

18. The method at pre-authenticating a client device for direct access to a cloud-based secure service according to claim 1 , wherein: said cryptographic key is exchanged between said cloud-based secure service and said client device out-of-band.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 048104/FRAME 0080 Recorded Jun 19, 2024
From: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
To: COMTECH TELECOMMUNICATIONS CORP.; COMTECH EF DATA CORP.; COMTECH MOBILE DATACOM LLC; COMTECH SATELLITE NETWORK TECHNOLOGIES, INC.; COMTECH SYSTEMS, INC.; COMTECH XICOM TECHNOLOGY, INC.; MAPLE ACQUISITION LLC; TELECOMMUNICATION SYSTEMS, INC.
Reel/Frame 067780/0444 →
SECURITY INTEREST Recorded Jun 18, 2024
From: TELECOMMUNICATION SYSTEMS, INC.
To: TCW ASSET MANAGEMENT COMPANY LLC, AS AGENT
Reel/Frame 067776/0309 →
SECURITY INTEREST Recorded Nov 16, 2018
From: COMTECH TELECOMMUNICATIONS CORP.; COMTECH EF DATA CORP.; COMTECH XICOM TECHNOLOGY, INC.; COMTECH SYSTEMS, INC.; COMTECH PST CORP.; COMTECH MOBILE DATACOM CORPORATION; ANGELS ACQUISITION CORP.; ARMER COMMUNICATIONS ENGINEERING SERVICES, INC.; COMTECH AEROASTRO, INC.; COMTECH ANTENNA SYSTEMS, INC.; COMTECH COMMUNICATIONS CORP.; COMTECH COMSTREAM, INC.; COMTECH SYSTEMS INTERNATIONAL, INC.; COMTECH TOLT TECHNOLOGIES, INC.; TIERNAN RADYNE COMSTREAM, INC.; COMTECH CPI ELECTRON DEVICES CORP.; COMTECH CPI MICROWAVE CORP.; TELECOMMUNICATION SYSTEMS, INC.; NETWORKS IN MOTION, INC.; SOLVERN INNOVATIONS, INC.; MICRODATA, LLC; MICRODATA GIS, INC.; MAPLE ACQUISITION LLC; NEXTGEN COMMUNICATIONS, INC., A CORPORATION OF MARYLAND; NEXTGEN COMMUNICATIONS, INC., A CORPORATION OF VIRGINIA; OLIVE ACQUISITION LLC
To: CITIBANK, N.A.
Reel/Frame 048104/0080 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2015
From: GRIFFIN, JOHN L.; MCFARLAND, KEITH A.; WELLS, WILLIAM P.
To: TELECOMMUNICATION SYSTEMS, INC.
Reel/Frame 037305/0892 →