US2024037208A1PendingUtilityA1

Determining authentication sub-flow and client authentication based on tests transmitted to server-side software

Assignee: ORACLE INT CORPPriority: Oct 18, 2018Filed: Oct 13, 2023Published: Feb 1, 2024
Est. expiryOct 18, 2038(~12.2 yrs left)· nominal 20-yr term from priority
G06F 21/335H04L 67/02H04L 63/0807G06F 40/18H04L 63/205G06F 9/451G06F 21/31G06F 9/547H04L 63/08G06F 16/958
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Tests are transmitted from a client device to server-side software located on a server device. Results of the tests are received from the server-side software. An authentication sub-flow is selected, based on results of the tests, from a plurality of authentication sub-flows enabling a client-side program to operate on cloud-based data associated with server-side software. Client authentication is facilitated for the client-side program to operate on the cloud-based data using the selected authentication sub-flow. The cloud-based data is operated on from the client-side program using the client-authentication.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A non-transitory processor-readable medium including instructions executable by one or more processors, and when executed operable for:
 transmitting tests from a client device to server-side software located on a server device;   receiving results of the tests from the server-side software;   selecting, based on results of the tests, an authentication sub-flow from a plurality of authentication sub-flows enabling a client-side program on the client device to operate on cloud-based data associated with server-side software;   facilitating client authentication for the client-side program to operate on the cloud-based data using the selected authentication sub-flow; and   operating on the cloud-based data from the client-side program using the client-authentication.   
     
     
         2 . The non-transitory processor-readable medium of  claim 1 , further including instructions executable by the one or more processors and when executed operable for:
 transmitting second tests from the client device to second server-side software;   receiving second results from the second tests from the second server-side software; and   selecting, based on the second results of the second tests, a second authentication sub-flow from the plurality of authentication sub-flows enabling second client-side program on the client device to operate on second cloud-based data associated with the second server-side software.   
     
     
         3 . The non-transitory processor-readable medium of  claim 2 , further including instructions executable by the one or more processors and when executed operable for:
 facilitating second client authentication for the second client-side program to operate on the second cloud-based data using the selected second authentication sub-flow; and   operating on the second cloud-based data from the second client-side program using the second client authentication.   
     
     
         4 . The non-transitory processor-readable medium of  claim 1 , wherein the tests are messages and the transmitting tests from a client device to server-side software further includes:
 transmitting the messages from the client device to the server-side software.   
     
     
         5 . The non-transitory processor-readable medium of  claim 4 , wherein the test results are responses and the receiving of the results of the tests from the server-side software further includes:
 receiving the responses of the messages from the server-side software.   
     
     
         6 . The non-transitory processor-readable medium of  claim 1 , wherein each of the plurality of authentication sub-flows are associated with a different type of authentication. 
     
     
         7 . The non-transitory processor-readable medium of  claim 6 , wherein the types of types of authentication include JSON Web Token (JWT), basic access authentication (BASIC), and Open AUTHorization (OAUTH). 
     
     
         8 . The non-transitory processor-readable medium of  claim 1 , further including instructions executable by the one or more processors and when executed operable for:
 determining a type of authentication used by the server-side software based on the results from the tests.   
     
     
         9 . The non-transitory processor-readable medium of  claim 1 , further including instructions executable by the one or more processors and when executed operable for:
 providing authenticated credentials; and   collecting authentication evidence based on the selected authentication sub-flow.   
     
     
         10 . The non-transitory processor-readable medium of  claim 1 , further including instructions executable by the one or more processors and when executed operable for:
 transmitting the tests from the client device to a copy of the server-side software on a second server device;   receiving second results of the tests from the copy of the server-side software;   selecting, based on second results of the tests, a second authentication sub-flow from the plurality of the authentication sub-flows enabling the client-side program on the client device to operate on second cloud-based data associated with the copy of the server-side software;   facilitating second client authentication for the client-side program to operate on the second cloud-based data using the selected second authentication sub-flow; and   operating on the second cloud-based data from the client-side program using the second client-authentication.   
     
     
         11 . A method for determining authentication sub-flow and client authentication based on tests transmitted to server-side software, the method comprising:
 transmitting tests from a client device to server-side software located on a server device;   receiving results of the tests from the server-side software;   selecting, based on results of the tests, an authentication sub-flow from a plurality of authentication sub-flows enabling a client-side program on the client device to operate on cloud-based data associated with server-side software;   facilitating client authentication for the client-side program to operate on the cloud-based data using the selected authentication sub-flow; and   operating on the cloud-based data from the client-side program using the client-authentication.   
     
     
         12 . The method of  claim 11 , further comprising:
 transmitting second tests from the client device to second server-side software;   receiving second results from the second tests from the second server-side software; and   selecting, based on the second results of the second tests, a second authentication sub-flow from the plurality of the authentication sub-flows enabling second client-side program on the client device to operate on second cloud-based data associated with the second server-side software.   
     
     
         13 . The method of  claim 12 , further comprising:
 facilitating second client authentication for the second client-side program to operate on the second cloud-based data using the selected second authentication sub-flow; and   operating on the second cloud-based data from the second client-side program using the second client authentication.   
     
     
         14 . The method of  claim 11 , wherein the tests are messages and the transmitting tests from the client device to the server-side software further comprises:
 transmitting the messages from the client device to the server-side software.   
     
     
         15 . The method of  claim 14 , wherein the test results are responses and the receiving of the results of the tests from the server-side software further comprises:
 receiving the responses of the messages from the server-side software.   
     
     
         16 . The method of  claim 11 , wherein each of the plurality of authentication sub-flows are associated with a different type of authentication. 
     
     
         17 . The method of  claim 16 , wherein the types of types of authentication include JSON Web Token (JWT), basic access authentication (BASIC), and Open AUTHorization (OAUTH). 
     
     
         18 . The method of  claim 11 , further comprising:
 determining a type of authentication used by the server-side software based on the results from the tests.   
     
     
         19 . The method of  claim 11 , further comprising:
 providing authenticated credentials; and   collecting authentication evidence based on the selected authentication sub-flow.   
     
     
         20 . An apparatus comprising:
 one or more hardware processors; and   logic encoded in one or more non-transitory media for execution by the one or more processors and when executed operable for:   transmitting tests from a client device to server-side software located on a server device;   receiving results of the tests from the server-side software;   selecting, based on results of the tests, an authentication sub-flow from a plurality of authentication sub-flows enabling a client-side program on the client device to operate on cloud-based data associated with server-side software;   facilitating client authentication for the client-side program to operate on the cloud-based data using the selected authentication sub-flow; and   operating on the cloud-based data from the client-side program using the client-authentication.

Join the waitlist — get patent alerts

Track US2024037208A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.