Techniques for configuring sessions across clients

US10623501B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10623501-B2
Application numberUS-201615356384-A
CountryUS
Kind codeB2
Filing dateNov 18, 2016
Priority dateSep 15, 2016
Publication dateApr 14, 2020
Grant dateApr 14, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques are disclosed for providing users of an access management system the capability to manage the user's active sessions. The system may receive a first request by a user at a first device to modify one or more sessions established for the user. The system may access session information about the one or more sessions that are associated with the user, wherein a session of the one or more sessions provides the user with access to one or more resources. The system may send the session information to the first device, the session information causing the first device to display a graphical interface including the session information about the one or more sessions. The system may receive, from the first device, a second request indicating a modification to the session. The system may modify the session in accordance with the modification indicated in the second request.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving, by a computer system of an access management system, a first request from a first device to manage one or more sessions established for a user; responsive to the receiving, establishing a first session for the user for the first device upon successful authentication of the user, the first session enabling the user to access a session management interface for managing the one or more sessions established for the user; accessing session information about the one or more sessions that are established for the user; sending, by the computer system, the session information to the first device, wherein the first device displays a graphical interface outputting the session information; receiving, from the first device, a second request requesting a modification to an attribute of a second session from the one or more sessions established for the user, the second session established for the user for a second device upon successful authentication of the user, the second request generated using the session management interface; changing the attribute of the second session in accordance with the modification requested in the second request; and sending, by the computer system, to the first device, modified session information about the one or more sessions established for the user, the modified session information indicating the change made to the attribute of the second session, wherein the first device modifies the graphical interface to output the modified session information. 2. The method of claim 1 , wherein the authentication of the user corresponds to a first authentication, and wherein prior to the first request, the method further comprises: determining a second authentication of the user to access one or more resources at the second device; and establishing the second session for the user at the second device. 3. The method of claim 2 , wherein the second device is different from the first device. 4. The method of claim 2 , wherein the second device is the first device. 5. The method of claim 2 , wherein the one or more sessions is a plurality of sessions, and wherein each of the plurality of sessions is created for the user at a different one of a plurality of devices. 6. The method of claim 2 , wherein the first authentication is determined based on a first authentication process and a second authentication process, and wherein the second authentication is determined based on the first authentication process. 7. The method of claim 1 , wherein the first request is by a first user at the first device, and wherein the user corresponds to a second user who is different from the first user. 8. The method of claim 1 , wherein the session information comprises: an Internet protocol (IP) address of the second device; a time period during which the second session is configured to be active; an indication of whether the second session is persistent; an indication of whether the second session is impersonated; an authentication level of the second session; an identifier of the second session; an identifier of the user, or a combination thereof. 9. The method of claim 1 , wherein the one or more sessions is a plurality of sessions, wherein the session information is a first session information, and wherein prior to receiving the second request, the method further comprises: receiving, from the first device, a third request to identify, from amongst the plurality of sessions, a subset of sessions associated with an IP address; searching for the subset of sessions based on the third request; and sending a second session information about the subset of sessions to the first device, wherein the first device displays an indication about the subset of sessions based on the second session information sent to the first device. 10. The method of claim 2 , wherein the one or more resources includes a first resource and a second resource, wherein access to the first resource is based on a first authentication level having a first authentication process, and wherein access to the second resource is based on a second authentication level having a second authentication process, the second authentication process involving additional authentication in addition to the first authentication process; wherein the second session has the second authentication level; and wherein the modification comprises changing an authentication level of the second session from the second authentication level to the first authentication level to revoke the access to the second resource for the second session at the second device. 11. The method of claim 2 , wherein the one or more resources includes a first resource and does not comprise a second resource, wherein access to the first resource is based on a first authentication level having a first authentication process and access to the second resource is based on a second authentication level having a second authentication process, the second authentication process involving additional authentication in addition to the first authentication process; wherein the second session has the first authentication level; and wherein the modification comprises changing an authentication level of the second session from the first authentication level to the second authentication level to provide the access to the second resource for the second session at the second device. 12. The method of claim 1 , wherein the attribute is a time period, wherein the change to the attribute corresponds to extending the time period, and wherein the second session is active for the time period based on the change. 13. A system comprising: one or more processors; and a memory accessible to the one or more processors, the memory storing one or more instructions that, upon execution by the one or more processors, causes the one or more processors to: receive a first request from a first device to manage one or more sessions established for a user; responsive to the receiving, establish a first session for the user for the first device upon successful authentication of the user, the first session enabling the user to access a session management interface for managing the one or more sessions established for the user; access session information about the one or more sessions that are established for the user; send the session information to the first device, wherein the first device displays a graphical interface outputting the session information; receive, from the first device, a second request requesting a modification to an attribute of a second session from the one or more sessions established for the user, the second session established for the user for a second device upon successful authentication of the user, the second request generated using the session management interface; change the attribute of the second session in accordance with the modification requested in the second request; and send, to the first device, modified session information about the one or more sessions the established for the user, wherein the first device modifies the graphical interface to output the modified session information. 14. The system of claim 13 , wherein the authentication of the user corresponds to a first authentication, and wherein the one or more instructions, upon execution by the one or more processors, further causes the one or more processors to: prior to the first request: determine a second authentication of the user to access one or more resources at the second device; and establish the second session for the user at the second device.

Assignees

Inventors

Classifications

  • H04L67/143Primary

    Termination or inactivation of sessions, e.g. event-controlled end of session · CPC title

  • Electricity · mapped topic

  • Protocols · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10623501B2 cover?
Techniques are disclosed for providing users of an access management system the capability to manage the user's active sessions. The system may receive a first request by a user at a first device to modify one or more sessions established for the user. The system may access session information about the one or more sessions that are associated with the user, wherein a session of the one or more…
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification H04L67/143. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 14 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).