Context based conditional access for cloud services

US9749331B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9749331-B1
Application numberUS-201213463672-A
CountryUS
Kind codeB1
Filing dateMay 3, 2012
Priority dateMay 3, 2011
Publication dateAug 29, 2017
Grant dateAug 29, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A cloud service access and information gateway receives a first authentication factor for a user in a single sign-on system. The single sign-on system provides access to a plurality of cloud services. The gateway receives, from a user device, a request to access a cloud service of the plurality of cloud services. The gateway compares a context of the request to an access policy for the single sign-on system and grants conditional access to the cloud service based on the access policy.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: receiving a first authentication factor for a user in a single sign-on system, the single sign-on system to provide access to a plurality of cloud services; receiving, from a user device over a network, a request to access a cloud service of the plurality of cloud services, the user having a plurality of user accounts for the cloud service, wherein each user account has independent access credentials associated with the account; determining a context of the request to include a type of information to be sent to or received from the cloud service as a result of the request; comparing, by a processing device, the context of the request to an access policy for the single sign-on system; automatically determining a first user account of the plurality of user accounts for the cloud service based on the context of the request and the access policy; and granting the user conditional access to the cloud service using the associated access credential for the first user account, wherein granting conditional access comprises requesting a second authentication factor for the user before granting full access to the cloud service. 2. The method of claim 1 , wherein the second authentication factor comprises at least one of a password, a pin, a pattern, a security token, a one-time password, or a biometric. 3. The method of claim 1 , wherein the second authentication factor is requested in response to a request from the user device for confidential information from the cloud service. 4. The method of claim 1 , wherein the plurality of user accounts comprises a personal account and a corporate account, both associated with the user. 5. The method of claim 1 , wherein the context of the request is further determined to comprise an identity of the user, a type of the user device, a type of network over which the request is received, or a type of information requested from the cloud service. 6. The method of claim 1 , wherein a cloud service access and information gateway determines the context of the request and compares the context to the access policy. 7. The method of claim 1 , wherein the access policy specifies whether to request a second authentication factor and which of a plurality of user accounts to use based on the context of the request. 8. A system, comprising: a memory; and a processing device coupled with the memory to: receive a first authentication factor for a user in a single sign-on system, the single sign-on system to provide access to a plurality of cloud services; receive, from a user device over a network, a request to access a cloud service of the plurality of cloud services, the user having a plurality of user accounts for the cloud service, wherein each user account has independent access credentials associated with the account; determine a context of the request to include a type of information to be sent to or received from the cloud service as a result of the request; compare the context of the request to an access policy for the single sign-on system; automatically determine a first user account of the plurality of user accounts for the cloud service based on the context of the request and the access policy; and grant the user conditional access to the cloud service using the associated access credential for the first user account, wherein granting conditional access comprises requesting a second authentication factor for the user before granting full access to the cloud service. 9. The system of claim 8 , wherein the second authentication factor comprises at least one of a password, a pin, a pattern, a security token, a one-time password, or a biometric. 10. The system of claim 8 , wherein the second authentication factor is requested in response to a request from the user device for confidential information from the cloud service. 11. The system of claim 8 , wherein the plurality of user accounts comprises a personal account and a corporate account, both associated with the user. 12. The system of claim 8 , wherein the context of the request is further determined to comprise an identity of the user, a type of the user device, a type of network over which the request is received, or a type of information requested from the cloud service. 13. The system of claim 8 , wherein a cloud service access and information gateway determines the context of the request and compares the context to the access policy. 14. The system of claim 8 , wherein the access policy specifies whether to request a second authentication factor and which of a plurality of user accounts to use based on the context of the request. 15. A non-transitory computer readable storage medium including instructions that, when executed by a processor, cause the processor to perform operations comprising: receiving a first authentication factor for a user in a single sign-on system, the single sign-on system to provide access to a plurality of cloud services; receiving, from a user device over a network, a request to access a cloud service of the plurality of cloud services, the user having a plurality of user accounts for the cloud service, wherein each user account has independent access credentials associated with the account; determining a context of the request to include a type of information to be sent to or received from the cloud service as a result of the request; comparing, by a processing device, the context of the request to an access policy for the single sign-on system; automatically determining a first user account of the plurality of user accounts for the cloud service based on the context of the request and the access policy; and granting the user conditional access to the cloud service using the associated access credential for the first user account, wherein granting conditional access comprises requesting a second authentication factor for the user before granting full access to the cloud service. 16. The non-transitory computer readable storage medium of claim 15 , wherein the second authentication factor comprises at least one of a password, a pin, a pattern, a security token, a one-time password, or a biometric. 17. The non-transitory computer readable storage medium of claim 15 , wherein the second authentication factor is requested in response to a request from the user device for confidential information from the cloud service. 18. The non-transitory computer readable storage medium of claim 15 , wherein the plurality of user accounts comprises a personal account and a corporate account, both associated with the user. 19. The non-transitory computer readable storage medium of claim 15 , wherein the context of the request is further determined to comprise an identity of the user, a type of the user device, a type of network over which the request is received, or a type of information requested from the cloud service. 20. The non-transitory computer readable storage medium of claim 15 , wherein a cloud service access and information gateway determines the context of the request and compares the context to the access policy. 21. The non-transitory computer readable storage medium of claim 15 , wherein the access policy specifies whether to request a second authentication factor and which of a plurality of user accounts to use based on the context of the request.

Assignees

Inventors

Classifications

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

  • H04L41/28Primary

    Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration · CPC title

  • Multivendor or multi-standard integration · CPC title

  • at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9749331B1 cover?
A cloud service access and information gateway receives a first authentication factor for a user in a single sign-on system. The single sign-on system provides access to a plurality of cloud services. The gateway receives, from a user device, a request to access a cloud service of the plurality of cloud services. The gateway compares a context of the request to an access policy for the single s…
Who is the assignee on this patent?
Koeten Robert, Popp Nicolas, Symantec Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 29 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).