Identity provider discovery service using a publish-subscribe model

US9596123B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9596123-B2
Application numberUS-201313781795-A
CountryUS
Kind codeB2
Filing dateMar 1, 2013
Priority dateDec 3, 2010
Publication dateMar 14, 2017
Grant dateMar 14, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A proxy is integrated within an F-SSO environment and interacts with an external identity provider (IdP) instance discovery service. The proxy proxies IdP instance requests to the discovery service and receives responses that include the IdP instance assignments. The proxy maintains a cache of the instance assignment(s). As new instance requests are received, the cached assignment data is used to provide appropriate responses in lieu of proxying these requests to the discovery service, thereby reducing the time needed to identify the required IdP instance. The proxy dynamically maintains and manages its cache by subscribing to updates from the discovery service. The updates identify IdP instance changes (such as servers being taken offline for maintenance, new services being added, etc.) occurring within the set of geographically-distributed instances that comprise the IdP service. The updates are provided via a publication-subscription model such that the proxy receives change notifications proactively.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for providing identity provider services in association with an identity provider instance discovery service, the method carried out using an apparatus that is distinct from and external to the identity provider instance discovery service, comprising: as requests for identity provider instances are processed by the identity provider instance discovery service, receiving and storing at the apparatus data identifying the identity provider instances assigned by the identity provider instance discovery service; receiving at the apparatus an update concerning a resource associated with the identity provider instance discovery service, the update received at the apparatus from the identity provider instance discovery service via a topic-based publish-subscribe notification service supported on a hardware element; based on the update received at the apparatus, modifying the data; and upon receipt of a new request for an identity provider instance, and in lieu of forwarding the new request from the apparatus to the identity provider instance discovery service for handling, using the modified data to identify an identity provider instance for use in responding to the new request. 2. The method as described in claim 1 wherein the data is assignment data that associates a request and an identity provider instance selected by the identity provider instance discovery service to service the request. 3. The method as described in claim 1 wherein the update is received periodically or asynchronously. 4. The method as described in claim 1 wherein the notification service is a Web service provided by the identity provider instance discovery service. 5. The method as described in claim 1 further including subscribing to the update. 6. The method as described in claim 1 wherein the update includes one of: a load associated with one or more of the identity provider instances, availability of one or more identity provider instances, a performance metric associated with one or more identity provider instances, and an existing binding associated with one or more identity provider instances. 7. The method as described in claim 1 wherein the data is modified according to a policy or business logic.

Assignees

Inventors

Classifications

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • providing single-sign-on or federations · CPC title

  • Electricity · mapped topic

  • H04L41/00Primary

    Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks · CPC title

  • Electricity · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9596123B2 cover?
A proxy is integrated within an F-SSO environment and interacts with an external identity provider (IdP) instance discovery service. The proxy proxies IdP instance requests to the discovery service and receives responses that include the IdP instance assignments. The proxy maintains a cache of the instance assignment(s). As new instance requests are received, the cached assignment data is used …
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L41/00. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 14 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).