Centralized pluggable authentication and authorization

US2016234196A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016234196-A1
Application numberUS-201514742239-A
CountryUS
Kind codeA1
Filing dateJun 17, 2015
Priority dateFeb 11, 2015
Publication dateAug 11, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In particular embodiments, a first computing device may receive a request from a second computing device to access a first entity of an infrastructure, the second computing device being coupled to the first computing device, then determining an eligibility of the second computing device to access as least the first entity of the infrastructure, and if the second computing device is determined to be eligible to access the first entity, then assigning a second ticket to the second computing device responsive to the received request.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising, by a first computing device of an infrastructure: receiving a request from a second computing device to access a first entity of the infrastructure, the second computing device being coupled to the first computing device, wherein the request comprises a first ticket previously assigned by the first computing device, and wherein the first ticket authenticates and authorizes the second computing device for access to at least a second entity of the infrastructure; determining an eligibility of the second computing device to access at least the first entity of the infrastructure based at least on the first ticket and the first entity; and if the second computing device is determined to be eligible to access the first entity, assigning a second ticket to the second computing device responsive to the received request, wherein the second ticket authenticates and authorizes the second computing device for access to at least the first entity of the infrastructure. 2 . The method of claim 1 , wherein the first computing device comprises a third-party pluggable authentication and authorization (PAA) ticket server. 3 . The method of claim 1 , wherein assigning the second ticket to the second computing device comprises: nullifying the first ticket previously assigned by the first computing device; and sending the second ticket to the second computing device. 4 . The method of claim 1 , wherein an entity comprises one or more of a computing device, a data, or software. 5 . The method of claim 1 , wherein the infrastructure comprises an enterprise infrastructure. 6 . The method of claim 1 , wherein the first computing device is associated with a third-party encryption service, and wherein accessibility of the second computing device to pre-determined entities of the infrastructure is provided by the third-party encryption service. 7 . The method of claim 6 , wherein the assigned second ticket comprises one or more keys for the second computing device to access at least the first entity of the infrastructure, the first entity being associated with the pre-determined entities of the infrastructure. 8 . The method of claim 1 , wherein determining the eligibility of the second computing device to access at least the first entity of the infrastructure comprises determining an eligibility of a user of the second computing device to access at least the first entity of the infrastructure. 9 . The method of claim 1 , wherein the second entity comprises a remote desktop gateway of the infrastructure. 10 . The method of claim 1 , wherein the access to the first entity comprises a modification to the first entity. 11 . One or more computer-readable non-transitory storage media embodying logic that is operable when executed to: by a first computing device of an infrastructure: receiving a request from a second computing device to access a first entity of the infrastructure, the second computing device being coupled to the first computing device, wherein the request comprises a first ticket previously assigned by the first computing device, and wherein the first ticket authenticates and authorizes the second computing device for access to at least a second entity of the infrastructure; determining an eligibility of the second computing device to access at least the first entity of the infrastructure based at least on the first ticket and the first entity; and if the second computing device is determined to be eligible to access the first entity, assigning a second ticket to the second computing device responsive to the received request, wherein the second ticket authenticates and authorizes the second computing device for access to at least the first entity of the infrastructure. 12 . The media of claim 11 , wherein the first computing device comprises a third-party pluggable authentication and authorization (PAA) ticket server. 13 . The media of claim 11 , wherein the first computing device is associated with a third-party encryption service, and wherein accessibility of the second computing device to pre-determined entities of the infrastructure is provided by the third-party encryption service. 14 . The media of claim 13 , wherein the assigned second ticket comprises one or more keys for the second computing device to access at least the first entity of the infrastructure, the first entity being associated with the pre-determined entities of the infrastructure. 15 . The media of claim 11 , wherein the second entity comprises a remote desktop gateway of the infrastructure. 16 . An information handling system comprising: one or more processors; and a memory coupled to the processors comprising instructions executable by the processors, the processors being operable when executing the instructions to: by a first computing device of an infrastructure: receiving a request from a second computing device to access a first entity of the infrastructure, the second computing device being coupled to the first computing device, wherein the request comprises a first ticket previously assigned by the first computing device, and wherein the first ticket authenticates and authorizes the second computing device for access to at least a second entity of the infrastructure; determining an eligibility of the second computing device to access at least the first entity of the infrastructure based at least on the first ticket and the first entity; and if the second computing device is determined to be eligible to access the first entity, assigning a second ticket to the second computing device responsive to the received request, wherein the second ticket authenticates and authorizes the second computing device for access to at least the first entity of the infrastructure. 17 . The information handling system of claim 16 , wherein the first computing device comprises a third-party pluggable authentication and authorization (PAA) ticket server. 18 . The information handling system of claim 16 , wherein the first computing device is associated with a third-party encryption service, and wherein accessibility of the second computing device to pre-determined entities of the infrastructure is provided by the third-party encryption service. 19 . The information handling system of claim 18 , wherein the assigned second ticket comprises one or more keys for the second computing device to access at least the first entity of the infrastructure, the first entity being associated with the pre-determined entities of the infrastructure. 20 . The information handling system of claim 16 , wherein the second entity comprises a remote desktop gateway of the infrastructure.

Assignees

Inventors

Classifications

  • Arrangements for the registration or de-registration of VLAN attribute values, e.g. VLAN identifiers, port VLAN membership · CPC title

  • H04L67/148Primary

    Migration or transfer of sessions · CPC title

  • Entity profiles · CPC title

  • using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title

  • for accessing one among a plurality of replicated servers · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016234196A1 cover?
In particular embodiments, a first computing device may receive a request from a second computing device to access a first entity of an infrastructure, the second computing device being coupled to the first computing device, then determining an eligibility of the second computing device to access as least the first entity of the infrastructure, and if the second computing device is determined t…
Who is the assignee on this patent?
Dell Products Lp
What technology area does this patent fall under?
Primary CPC classification H04L67/148. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Aug 11 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).