Cookie based state propagation for a multi-tenant identity cloud service

US10445395B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10445395-B2
Application numberUS-201715701968-A
CountryUS
Kind codeB2
Filing dateSep 12, 2017
Priority dateSep 16, 2016
Publication dateOct 15, 2019
Grant dateOct 15, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system that provides cloud based identity management, at a first microservice, saves a current state on a cookie that is stored on a browser, where the current state is saved in a format specific to the first microservice. The system performs an operation on the first microservice that generates a first portion of information and a second portion of information. The system stores the first portion of information related to the operation on the cookie, the first portion including the current state. The system provides a second portion of information related to the operation to a second microservice as a query parameter on a redirect Uniform Resource Locator (“URL”), where the second portion is removed from the cookie.

First claim

Opening claim text (preview).

What is claimed is: 1. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to provide cloud based identity management, the providing comprising: at a first microservice, saving a current state on a cookie that is stored on a browser, wherein the current state is saved in a format specific to the first microservice; performing an operation, on the first microservice, that generates a first portion of information and a second portion of information; storing the first portion of information, related to the operation, on the cookie, the first portion comprising the current state; and providing a second portion of information, related to the operation, to a second microservice as a query parameter on a redirect Uniform Resource Locator (URL), wherein the second portion is removed from the cookie. 2. The non-transitory computer readable medium of claim 1 , wherein the first microservice is a Single Sign On (SSO) microservice and the second microservice is a Security Assertion Markup Language (SAML) microservice. 3. The non-transitory computer readable medium of claim 2 , wherein the operation is an authentication function, wherein the second portion of information comprises a result of the authentication function. 4. The non-transitory computer readable medium of claim 3 , wherein the result of the authentication function is provided by the query parameter. 5. The non-transitory computer readable medium of claim 1 , wherein the format specific to the first microservice cannot be read by other microservices. 6. The non-transitory computer readable medium of claim 1 , the providing further comprising a request cookie for authentication requests and a session cookie for microservice states. 7. The non-transitory computer readable medium of claim 6 , wherein the request cookie and the session cookie are each encrypted with keys that are changed on a predetermined time period. 8. A system for providing cloud based identity and access management, comprising: a plurality of tenants; a plurality of microservices; and one or more processors that: at a first microservice, save a current state on a cookie that is stored on a browser, wherein the current state is saved in a format specific to the first microservice; perform an operation, on the first microservice, that generates a first portion of information and a second portion of information; store the first portion of information, related to the operation, on the cookie, the first portion comprising the current state; and provide a second portion of information, related to the operation, to a second microservice as a query parameter on a redirect Uniform Resource Locator (URL), wherein the second portion is removed from the cookie. 9. The system of claim 8 , wherein the first microservice is a Single Sign On (SSO) microservice and the second microservice is a Security Assertion Markup Language (SAML) microservice. 10. The system of claim 9 , wherein the operation is an authentication function, wherein the second portion of information comprises a result of the authentication function. 11. The system of claim 10 , wherein the result of the authentication function is provided by the query parameter. 12. The system of claim 8 , wherein the format specific to the first microservice cannot be read by other microservices. 13. The system of claim 8 , the processors further generating a request cookie for authentication requests and a session cookie for microservice states. 14. The system of claim 13 , wherein the request cookie and the session cookie are each encrypted with keys that are changed on a predetermined time period. 15. A method of providing cloud based identity management, the method comprising: at a first microservice, saving a current state on a cookie that is stored on a browser, wherein the current state is saved in a format specific to the first microservice; performing an operation, on the first microservice, that generates a first portion of information and a second portion of information; storing the first portion of information, related to the operation, on the cookie, the first portion comprising the current state; and providing a second portion of information, related to the operation, to a second microservice as a query parameter on a redirect Uniform Resource Locator (URL), wherein the second portion is removed from the cookie. 16. The method of claim 15 , wherein the first microservice is a Single Sign On (SSO) microservice and the second microservice is a Security Assertion Markup Language (SAML) microservice. 17. The method of claim 16 , wherein the operation is an authentication function, wherein the second portion of information comprises a result of the authentication function. 18. The method of claim 17 , wherein the result of the authentication function is provided by the query parameter. 19. The method of claim 15 , wherein the format specific to the first microservice cannot be read by other microservices. 20. The method of claim 15 , further comprising a request cookie for authentication requests and a session cookie for microservice states.

Assignees

Inventors

Classifications

  • providing single-sign-on or federations · CPC title

  • Browsing optimisation, e.g. caching or content distillation · CPC title

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • of access to content, e.g. by caching · CPC title

  • URL specific, e.g. using aliases, detecting broken or misspelled links · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10445395B2 cover?
A system that provides cloud based identity management, at a first microservice, saves a current state on a cookie that is stored on a browser, where the current state is saved in a format specific to the first microservice. The system performs an operation on the first microservice that generates a first portion of information and a second portion of information. The system stores the first po…
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification G06F16/9574. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Oct 15 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).