Systems and Methods for Providing Automated Access to Resources of Computer Systems
US-2024430261-A1 · Dec 26, 2024 · US
US9648003B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9648003-B2 |
| Application number | US-201514604509-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jan 23, 2015 |
| Priority date | Nov 5, 2013 |
| Publication date | May 9, 2017 |
| Grant date | May 9, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Delegating authorizations sufficient to access services is contemplate. The authorization may be delegated in the form of a token or other transmissible construct relied upon to authenticate access to services, such as but not necessarily limited to conferring a user identity established via authenticated device for the purposes of enabling an unauthenticated or unsecured device to access a service associated with the user identity.
Opening claim text (preview).
What is claimed is: 1. A method for delegating access tokens relied upon to authenticate access to services, the method comprising: receiving a plurality of access tokens from a plurality of service providers after the plurality of service providers associates each of the plurality of access tokens with at least one of a plurality of users; receiving a first credential from a control device generated in response to the control device interacting with an sink device while the sink device is being engaged to access a first services associated with a first service provider of the plurality of service providers at a first instance in time; identifying a first access token of the plurality of access tokens associated with a first user of the plurality of users as a function of information included within the first credential; and transmitting the first access token to the first service provider at a second instance in time occurring after the first instance in time, the first service provider granting the sink device access to the first service at the second instance in time according to entitlements of the first user if the first access token is valid when received, thereby enabling the sink device to access the first service without providing the first access token to the service provider. 2. The method of claim 1 further comprising determining an address to be used in transmitting the first access token to the first service provider as a function of information included within the first credential. 3. The method of claim 2 further comprising determining at least a portion of the information included in the first credential as a result of the sink device determining an indicator displayed on the control device having an indicia sufficient for identifying the first service provider. 4. The method of claim 3 further comprising instructing an identifier application on the control device to determine the indicia by processing an image of the indicator captured with a camera of the control device. 5. The method of claim 4 further comprising instructing the first user to capture the image by positioning the camera to take a picture of a webpage associated with the first service provider, the webpage displaying the indicator proximate to input fields operable to receive a username and a password sufficient to enable the first user to access the first service without use of the first access token. 6. The method of claim 5 further comprising transmitting a redirect message to a browser operating on the sink device to display the webpage sufficient to automatically direct the browser to a service page used to engage the first service without having to input the username and the password. 7. The method of claim 1 further comprising: updating the first access token after being determined as invalid with a second access token received from the first service provider at a third instance in time occurring after the second instance in time; receiving a second credential from the control device generated in response to the control device interacting with the sink device while the sink device is being engaged to access the first service at a fourth instance in time occurring after the third instance in time; and transmitting the second access token to the first service provider at a fifth instance in time occurring after the fourth instance in time as a function of information included within the second credential, the first service provider granting the sink device access to the first service at the fifth instance in time if the second access token is valid when received, thereby enabling the sink device to access the first service without providing the second access token to the service provider. 8. The method of claim 1 further comprising: receiving a second credential from the control device generated in response to the control device interacting with the sink device while the sink device is being engaged to access the first service at a third instance in time occurring after the second instance in time; determining the second credential to be one of authenticated and unauthenticated at a fourth instance in time occurring after the third instance in time, including determining the second credential to be authenticated if the control device successful completed an authentication process at a fifth instance in time occurring prior to the third instance in time and to be unauthenticated if the control device unsuccessfully completed the authentication process at the fifth instance in time; transmitting the first access token to the first service provider at a sixth instance in time occurring after to the fourth instance in time if the second credential is determined to be authenticated, the first service provider granting the sink device access to the first service at the sixth instance in time if the first access token is valid when received; and instructing the control device to display a login message to the first user in the event the second credential is determined to be unauthenticated, the login message instructing the first user to input a username and a password or other sufficient authentication to a webpage displayed on the sink device to facilitate access to the first service at the sixth instance in time. 9. A non-transitory computer-readable medium having a plurality of non-transitory instructions operable with a processor associated with a service provider to facilitate access to services, the non-transitory instructions being sufficient for: associating a plurality of users with one or more of a plurality of access tokens, each access token authenticating the corresponding user for access to at least one of a plurality of services offered by the service provider; associating at least one of a plurality of indicators with each of the plurality of services, each indicator being sufficient to uniquely identify the service associated therewith; associating a first indicator of the plurality of indicators with a sink device attempting to access the first service, the first indicator uniquely identifying a first service of the plurality of services; and enabling the sink device access to the first service according to a first user of the plurality of users associated with a first access token of the plurality of access tokens, including determining the first access token in response to a control device generating a credential having information sufficient to identify the first user and the first service, the control device identifying the first service after interacting with the first indicator associated with the sink device. 10. The non-transitory computer-readable medium of claim 9 further comprising non-transitory instructions sufficient for transmitting the plurality of access tokens to a server in communication with the control device. 11. The non-transitory computer-readable medium of claim 10 further comprising non-transitory instructions sufficient for enabling the sink device access to the first service following receipt of an access message from the server, the access message being generated according to information included in the credential transmitted from the control device to include the first access token and an address of the sink device. 12. The non-transitory computer-readable medium of claim 11 further comprising non-transitory instructions sufficient for transmitting access instructions to the sink device to access the first service therethrough, including identifying the sink device to receive the access instructions as a function of the address included with the access message. 13. The non-transitory computer readable medium of cla
using tickets or tokens, e.g. Kerberos (network architectures or network communication protocols for entities authentication using tickets in a packet data network H04L63/0807) · CPC title
using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title
based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title
providing single-sign-on or federations · CPC title
for controlling access to devices or network resources · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.