Authorization and access control system for access rights using relationship graphs
US-2024414161-A1 · Dec 12, 2024 · US
US2016205108A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016205108-A1 |
| Application number | US-201514595456-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jan 13, 2015 |
| Priority date | Jan 13, 2015 |
| Publication date | Jul 14, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A system that authorizes access to a resource by a client validates the client and generates a Security Assertion Markup Language (“SAML”) assertion for the valid client. The system then sends an access request with the SAML assertion to a OAuth server. In response, the OAuth server returns an access token for the resource to the client.
Opening claim text (preview).
What is claimed is: 1 . A computer-readable medium having instructions stored thereon that, when executed by a processor, cause the processor to authorize access to a resource by a client, the authorizing comprising: validating the client; generating a Security Assertion Markup Language (SAML) assertion for the valid client; and sending an access request with the SAML assertion to a OAuth server; wherein, in response to the sending, the OAuth server returns an access token for the resource to the client. 2 . The computer-readable medium of claim 1 , wherein the client can access the resource using the access token. 3 . The computer-readable medium of claim 1 , wherein the access request comprises an identity of the client and an identity of the resource. 4 . The computer-readable medium of claim 3 , wherein the access request comprises a Hypertext Transfer Protocol (HTTP) request. 5 . The computer-readable medium of claim 1 , wherein validating the client comprises receiving a single sign-on comprising a password. 6 . The computer-readable medium of claim 1 , wherein the generating the SAML assertion and sending the access request is implemented by a servlet. 7 . The computer-readable medium of claim 1 , wherein the validating the client comprises at least one of signature validation, checking assertion conditions or checking an assertion subject. 8 . A method of authorizing access to a resource by a client, the method comprising: validating the client; generating a Security Assertion Markup Language (SAML) assertion for the valid client; and sending an access request with the SAML assertion to a OAuth server; wherein, in response to the sending, the OAuth server returns an access token for the resource to the client. 9 . The method of claim 8 , wherein the client can access the resource using the access token. 10 . The method of claim 8 , wherein the access request comprises an identity of the client and an identity of the resource. 11 . The method of claim 10 , wherein the access request comprises a Hypertext Transfer Protocol (HTTP) request. 12 . The method of claim 8 , wherein validating the client comprises receiving a single sign-on comprising a password. 13 . The method of claim 8 , wherein the generating the SAML assertion and sending the access request is implemented by a servlet. 14 . The method of claim 8 , wherein the validating the client comprises at least one of signature validation, checking assertion conditions or checking an assertion subject. 15 . A web server comprising: a processor; instructions stored on a memory device that, when executed by the processor generate an authorization servlet that, in response to a request to access a resource by a client, validates the client; generates a Security Assertion Markup Language (SAML) assertion for the valid client; and sends an access request with the SAML assertion to a OAuth server; wherein, in response to the sending, the OAuth server returns an access token for the resource to the client. 16 . The web server of claim 15 , wherein the instructions, when executed by the processor, further generate an Enterprise JavaBeans (EJB) stub that is in communication with an EJB skeleton. 17 . The web server of claim 15 , wherein the instructions, when executed by the processor, further generate a Java Message Service (JMS) listener that is in communication with a JMS publisher. 18 . The web server of claim 15 , wherein the client can access the resource using the access token. 19 . The web server of claim 15 , wherein the access request comprises an identity of the client and an identity of the resource. 20 . The web server of claim 15 , wherein the validating the client comprises at least one of signature validation, checking assertion conditions or checking an assertion subject.
Entity profiles · CPC title
using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title
based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title
providing single-sign-on or federations · CPC title
Protocols · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.