Performing a security action with regard to an access token based on clustering of access requests
US-2024406160-A1 · Dec 5, 2024 · US
US9509672B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-9509672-B1 |
| Application number | US-201314076169-A |
| Country | US |
| Kind code | B1 |
| Filing date | Nov 8, 2013 |
| Priority date | Nov 8, 2013 |
| Publication date | Nov 29, 2016 |
| Grant date | Nov 29, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method for providing seamless access to a first account using authentication information associated with a second account includes receiving a first account identifier corresponding to the first account, the first account being a shared account on a computer system. The method also includes receiving submitted authentication information associated with the second account. The method also includes comparing the submitted authentication information with stored authentication information that is associated with a plurality of authorized accounts. The plurality of authorized accounts is associated with clients authorized to access the first account. The method also includes determining whether the second account is an authorized account based on comparing the submitted authentication information with the stored authentication information. The method also includes providing seamless access to the first account in response to determining that the second account is an authorized account.
Opening claim text (preview).
What is claimed is: 1. A method comprising: receiving from a user in a single request: a first account identifier corresponding to a first account, the first account being a shared account on a computer network, and authentication information associated with a second account; comparing the submitted authentication information with stored authentication information, the stored authentication information associated with a plurality of authorized accounts, the plurality of authorized accounts associated with clients authorized to access the first account; determining whether the second account is an authorized account based on comparing the submitted authentication information with the stored authentication information; in response to determining that the second account is not an authorized account: requesting permission to access the first account from an owner of the first account; and receiving the permission to access the first account, and providing seamless access to the first account in response to receiving the permission to access the first account. 2. The method of claim 1 , wherein providing seamless access to the first account comprises sending a positive authentication signal to a computer, wherein the computer is configured to provide seamless access to the first account in response to receiving the positive authentication signal. 3. The method of claim 1 , further comprising: determining a second account identifier corresponding to the second account; obtaining additional account identifiers corresponding to the plurality of authorized accounts; and determining whether the second account identifier matches an account identifier of the additional account identifiers; wherein comparing the submitted authentication information with the stored authentication information comprises verifying the submitted authentication information using the stored authentication information in response to determining that the second account identifier matches an account identifier of the additional account identifiers. 4. The method of claim 3 , wherein determining the second account identifier comprises: identifying a key associated with an owner of the second account, the submitted authentication information comprising the key; and determining the second account identifier using the key. 5. The method of claim 1 , further comprising: detecting an identity change instruction, the identity change instruction comprising an instruction to switch to the first account; and requesting the submitted authentication information, wherein comparing the submitted authentication information with stored authentication information comprises comparing the submitted authentication information with the stored authentication information in response to detecting the identity change instruction. 6. The method of claim 1 , further comprising, in response to determining that the second account is an authorized account, checking out the first account on a shared account management system, wherein the shared account management system controls access to the first account. 7. A system comprising: a receiving device configured to receive from a user in a single request: a first account identifier corresponding to a first account, the first account being a shared account on a computer system, and submitted authentication information associated with a second account; a comparing device configured to compare a secret key of the submitted authentication information with stored authentication information, the stored authentication information associated with a plurality of authorized accounts, the plurality of authorized accounts associated with clients authorized to access the first account; a first determining device configured to determine whether the second account is an authorized account based on comparing the submitted authentication information with the stored authentication information; a permission requesting device configured to request permission to access the first account from an owner of the first account in response to determining that the second account is not an authorized account; and a third receiving device configured to receive the permission to access the first account from the owner of the first account; wherein the access providing device is configured to provide seamless access to the first account in response to receiving the permission to access the first account. 8. The system of claim 7 , wherein the access providing device is configured to send a positive authentication signal to a computer, wherein the computer is configured to provide seamless access to the first account in response to receiving the positive authentication signal. 9. The system of claim 7 , further comprising: a second determining device configured to determine a second account identifier corresponding to the second account; a second obtaining device configured to obtain additional account identifiers corresponding to the plurality of authorized accounts; and a third determining device configured to determine whether the second account identifier matches an account identifier of the additional account identifiers; wherein the comparing device is configured to verify the submitted authentication information using the stored authentication information in response to determining that the second account identifier matches an account identifier of the additional account identifiers. 10. The system of claim 9 , wherein the second determining device comprises: an identifying device configured to identify a key associated with an owner of the second account, the submitted authentication information comprising the key; and a fourth determining device configured to determine the second account identifier using the key. 11. The system of claim 7 , further comprising: a detecting device configured to detect an identity change instruction, the identity change instruction comprising an instruction to switch to the first account; and an authentication information requesting device configured to request the submitted authentication information, wherein the comparing device is configured to compare the submitted authentication information with the stored authentication information in response to detecting the identity change instruction. 12. The system according to claim 7 , further comprising, a checkout device configured to check out the first account on a shared account management system in response to determining that the second account is an authorized account, wherein the shared account management system controls access to the first account. 13. A computer program product comprising: a non-transitory computer readable storage medium having computer readable program code embodied therewith, the computer readable program code comprising: computer readable program code configured to receive, from a user in a single request: a first account identifier corresponding to a first account, the first account being a shared account on a computer system, and authentication information associated with a second account; computer readable program code configured to compare the submitted authentication information with stored authentication information, the stored authentication information associated with a plurality of authorized accounts, the plurality of authorized accounts associated with clients authorized to access the first account; computer readable program code configured to determine whether the second account is an authorized account based on comparing the submitted authentication information with the stored authentication information; computer readable
providing single-sign-on or federations · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.