US2011214165A1PendingUtilityA1

Processor Implemented Systems And Methods For Using Identity Maps And Authentication To Provide Restricted Access To Backend Server Processor or Data

Assignee: JEFFREYS DAVID KERRPriority: Feb 26, 2010Filed: Feb 24, 2011Published: Sep 1, 2011
Est. expiryFeb 26, 2030(~3.6 yrs left)· nominal 20-yr term from priority
G06F 16/2471
35
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for providing an application access to an external data source or an external server process via a connection server using an authentication server that has access to an identity map. A credential request is received at the authentication server from the connection server. The credential request includes an identification of the external data source or external server process to be accessed and an account identifier associated with the application or a user of the application. The identity map is searched for a set of credentials associated with both the account identifier and the external data source or external server process. The set of credentials are transmitted from the authentication server to the connection server, for the connection server to establish a connection to the external data source or external server process, where the connection is established without transmitting the set of credentials to the application.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method of providing an application access to an external data source or an external server process via a connection server using an authentication server that has access to an identity map, said method comprising:
 receiving a credential request at the authentication server from the connection server, wherein the credential request includes an identification of the external data source or external server process to be accessed and an account identifier associated with the application or a user of the application;   searching the identity map for a set of credentials associated with both the account identifier and the external data source or external server process; and   transmitting the set of credentials from the authentication server to the connection server, for the connection server to establish a connection to the external data source or external server process, wherein the connection is for providing the application access to the external data source or external server process, wherein the connection is established without transmitting the set of credentials to the application.   
     
     
         2 . The method of  claim 1 , wherein the account identifier further provides a group with which the application or the user of the application is associated;
 wherein searching further includes searching the identity map for a set of credentials associated with both the group with which the application or the user of the application is associated and the external data source or external server process.   
     
     
         3 . The method of  claim 1 , wherein the identity map is modified based on authentication information received from an authentication server administrator;
 wherein the authentication information associates account identifiers and external data sources or external service processes with credentials.   
     
     
         4 . The method of  claim 1 , wherein not transmitting the set of credentials to the application prohibits the application or a user of the application from accessing the external data source or external process without using the connection server. 
     
     
         5 . The method of  claim 1 , wherein a user enters a username and password combination to the application;
 wherein the connection server verifies the username and password combination;   wherein the connection server generates an account identifier from the application based on the verified username and password combination;   wherein the connection server transmits the account identifier to the authentication server.   
     
     
         6 . The method of  claim 1 , wherein the application is provided one of a plurality of levels of access to the external data source or external server process based on the set of credentials provided to the connection server based on the searching the identity map. 
     
     
         7 . The method of  claim 1 , wherein searching the identity map includes determining a group with which the account identifier is associated; and
 searching the identity map for a set of credentials associated with both the group with which the account identifier is associated and the external data source or external server process.   
     
     
         8 . A computer-implemented system for providing an application access to an external data source or an external server process via a connection server using an authentication server that has access to an identity map, said system comprising:
 one or more data processors;   a computer-readable memory encoded with instructions for commanding the one or more data processors to execute a method comprising:
 receiving a credential request at the authentication server from the connection server, wherein the credential request includes an identification of the external data source or external server process to be accessed and an account identifier associated with the application or a user of the application; 
 searching the identity map for a set of credentials associated with both the account identifier and the external data source or external server process; and 
 transmitting the set of credentials from the authentication server to the connection server, for the connection server to establish a connection to the external data source or external server process, wherein the connection is for providing the application access to the external data source or external server process, wherein the connection is established without transmitting the set of credentials to the application. 
   
     
     
         9 . The system of  claim 8 , wherein the account identifier further provides a group with which the application or the user of the application is associated;
 wherein searching further includes searching the identity map for a set of credentials associated with both the group with which the application or the user of the application is associated and the external data source or external server process.   
     
     
         10 . The system of  claim 8 , wherein the identity map is modified based on authentication information received from an authentication server administrator;
 wherein the authentication information associates account identifiers and external data sources or external service processes with credentials.   
     
     
         11 . The system of  claim 8 , wherein not transmitting the set of credentials to the application prohibits the application or a user of the application from accessing the external data source or external process without using the connection server. 
     
     
         12 . The system of  claim 8 , wherein a user enters a username and password combination to the application;
 wherein the application verifies the username and password combination;   wherein the connection server receives an account identifier from the application based on the verified username and password combination;   wherein the connection server transmits the account identifier to the authentication server.   
     
     
         13 . The system of  claim 8  wherein the application is provided one of a plurality of levels of access to the external data source or external server process based on the set of credentials provided to the connection server based on the searching the identity map. 
     
     
         14 . The system of  claim 8 , wherein searching the identity map includes determining a group with which the account identifier is associated; and
 searching the identity map for a set of credentials associated with both the group with which the account identifier is associated and the external data source or external server process.   
     
     
         15 . A computer-readable medium encoded with instructions for commanding one or more data processors to execute a method for providing an application access to an external data source or an external server process via a connection server using an authentication server that has access to an identity map, said method comprising:
 receiving a credential request at the authentication server from the connection server, wherein the credential request includes an identification of the external data source or external server process to be accessed and an account identifier associated with the application or a user of the application;   searching the identity map for a set of credentials associated with both the account identifier and the external data source or external server process; and   transmitting the set of credentials from the authentication server to the connection server, for the connection server to establish a connection to the external data source or external server process, wherein the connection is for providing the application access to the external data source or external server process, wherein the connection is established without transmitting the set of credentials to the application.

Join the waitlist — get patent alerts

Track US2011214165A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.