Entity authentication for pre-authenticated links
US-2024396898-A1 · Nov 28, 2024 · US
US2020074067A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2020074067-A1 |
| Application number | US-201916548771-A |
| Country | US |
| Kind code | A1 |
| Filing date | Aug 22, 2019 |
| Priority date | Aug 31, 2018 |
| Publication date | Mar 5, 2020 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Various embodiments set forth techniques for managing access to a resource at a device. In one aspect, a method includes receiving a request by an application to access a resource, determining that an application permission associated with the application and the resource grants the application access to the resource, where the application permission includes a signature of a permission review entity associated with the resource, and granting the request to access the resource based on the application permission. The permission review entity associated with the resource may be authorized through device permissions specified by an implementer or provider of the device.
Opening claim text (preview).
What is claimed is: 1 . A computer-implemented method for managing access to a resource at a device, comprising: receiving a first request by a first application to access a resource; determining that a first application permission associated with the first application and the resource grants the first application access to the resource, wherein the first application permission includes a first signature of a first permission review entity associated with the resource; and granting the first request to access the resource based on the first application permission. 2 . The method of claim 1 , further comprising: receiving a second request by a second application to access the resource; determining that a second application permission associated with the second application and the resource denies the second application access to the resource; and rejecting the second request to access the resource based on the second application permission. 3 . The method of claim 2 , wherein the second application permission includes a second signature of the first permission review entity. 4 . The method of claim 2 , wherein the second application permission includes a second signature of a second permission review entity associated with the resource, wherein the second permission review entity is distinct from the first permission review entity. 5 . The method of claim 1 , wherein the first application permission is associated with one or more access conditions, and wherein determining that the first application permission grants the first application access to the resource comprises determining that the one or more access conditions are satisfied. 6 . The method of claim 1 , further comprising: obtaining first device permission information; and based on determining that the first device permission information includes a signature of a system provider entity associated with the device: determining that the first device permission information is valid, and storing the first device permission information in a memory of the device. 7 . The method of claim 6 , further comprising: obtaining second device permission information; and based on determining that the second device permission information does not include a signature of the system provider entity associated with the device, determining that the second device permission information is invalid. 8 . The method of claim 6 , wherein the first device permission information specifies a set of one or more permission review entities associated with the resource. 9 . The method of claim 8 , further comprising, based on determining that the first permission review entity is included in the set of one or more permission review entities, determining that the first application permission is valid. 10 . One or more non-transitory computer-readable storage media storing instructions, that, when executed by one or more processors, cause the one or more processors to perform the steps of: obtaining a first application permission associated with a first application and a first resource; based on determining that the first application permission includes a signature of a first permission review entity included in a set of one or more permission review entities associated with the first resource, determining that the first application permission is valid; and granting the first application access to the first resource based on the first application permission. 11 . The one or more computer-readable storage media of claim 10 , wherein the first application permission is associated with one or more access conditions, and wherein granting the first application access to the resource comprises granting the first application access based on determining that the one or more access conditions are satisfied. 12 . The one or more computer-readable storage media of claim 10 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to perform the steps of: obtaining a second application permission associated with the first application and a second resource; and based on determining that the second application permission includes a signature of a second permission review entity not included in a set of one or more permission review entities associated with the second resource, determining that the second application permission is invalid. 13 . The one or more computer-readable storage media of claim 10 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to perform the steps of: obtaining device permission information; determining that the device permission information includes a signature of a system provider entity associated with the device; and based on the determination that the device permission information includes the signature of the system provider entity: determining that the device permission information is valid, and storing the device permission information in a memory of the device. 14 . The one or more computer-readable storage media of claim 13 , wherein the set of one or more permission review entities associated with the first resource are included in the device permission information. 15 . The one or more computer-readable storage media of claim 13 , wherein the device permission information is obtained via the system provider entity. 16 . The one or more computer-readable storage media of claim 10 , wherein the first application permission is obtained via an application provider entity associated with the first application. 17 . The one or more computer-readable storage media of claim 10 , wherein the first application permission is obtained via the first permission review entity. 18 . A system, comprising: a memory storing instructions; and at least one processor coupled to the memory and, when executing the instructions, is configured to: receive a first request by a first application to access a resource; determine that a first application permission associated with the first application and the resource grants the first application access to the resource, wherein the first application permission includes a first signature of a first permission review entity associated with the resource; and grant the first request to access the resource based on the first application permission. 19 . The system of claim 18 , wherein the at least one processor, when executing the instructions, is further configured to: obtain device permission information; and based on determining that the device permission information includes a signature of a system provider entity associated with the device: determine that the device permission information is valid, and store the device permission information in the memory; wherein the set of one or more permission review entities associated with the first resource are included in the device permission information. 20 . The system of claim 18 , wherein the at least one processor, when executing the instructions, is further configured to determine that the first application permission is valid based on the first signature of the first permission review entity.
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
to a system of files or objects, e.g. local or distributed file system or database · CPC title
Access rights, e.g. capability lists, access control lists, access tables, access matrices · CPC title
using a third party · CPC title
for controlling access to devices or network resources · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.