Leveraging a persistent connection to access a secured service
Abstract
Leveraging a persistent connection to provide a client access to a secured service may include establishing a persistent connection with a client in response to a first request from the client, and brokering a connection between the client and a secured service based on a second request from the client by leveraging the persistent connection with the client. The brokering may occur before the client attempts to connect to the secured service directly and the connection may be established between the client and the secured service without provision by the client of authentication information duplicative or additional to authentication information provided by the client to establish the persistent connection.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer program stored on a computer readable medium or a propagated signal for leveraging a persistent connection to provide a client access to a secured service, the computer program comprising:
an input code segment that causes a computer to receive input from a client; a persistent connection code segment that causes the computer to establish a persistent connection with the client in response to a first request received through the input code segment from the client; and a broker code segment that causes the computer to broker a connection between the client and a secured service based on a second request received through the input code segment from the client by leveraging the persistent connection with the client.
2 . The computer program of claim 1 wherein:
the persistent connection is established based on keystone authentication information provided by the client; and
the broker code segment comprises a transparent authentication code segment that causes the computer to leverage the keystone authentication to authenticate the client without provision by the client of authentication information duplicative or additional to the keystone authentication information used to establish the persistent connection.
3 . The computer program of claim 1 wherein:
the persistent connection is established based on keystone authentication information provided by the client; and
the broker code segment comprises a transparent authentication code segment that causes the computer to leverage the keystone authentication to authenticate the client without provision by the client of authentication information duplicative of the keystone authentication information used to establish the persistent connection.
4 . The computer program of claim 1 wherein:
the persistent connection is established based on keystone authentication information provided by the client; and
the broker code segment comprises a transparent authentication code segment that causes the computer to leverage the keystone authentication to authenticate the client without provision by the client of authentication information additional to the keystone authentication information used to establish the persistent connection.
5 . The computer program of claim 1 wherein the broker code segment causes the computer to broker the connection between the client and the secured service before the client attempts to connect to the secured service directly.
6 . The computer program of claim 1 wherein the persistent connection code segment comprises:
a receiving code segment that causes the computer to receive keystone authentication information from the client;
a keystone authentication code segment that causes the computer to authenticate the client based on the keystone authentication information and to provide a keystone authentication associated with the persistent connection; and
a connection code segment that causes the computer to establish the persistent connection with the client based on the keystone authentication.
7 . The computer program of claim 6 wherein the broker code segment includes a leveraging code segment that causes the computer to receive the second request from the client for connection to the secured service after the persistent connection to the client is established.
8 . The computer program of claim 7 wherein the leveraging code segment further comprises:
a leveraged authentication code segment that causes the computer to provide a leveraged authentication based on the keystone authentication associated with the persistent connection; and
a leveraged connection code segment that causes the computer to use the leveraged authentication to establish the connection with the secured service.
9 . The computer program of claim 8 wherein the leveraged authentication code segment comprises a transparent authentication code segment that causes the computer to provide the leveraged authentication based on the keystone authentication without provision by the client of authentication information duplicative or additional to the keystone authentication information used to establish the persistent connection.
10 . The computer program of claim 1 wherein:
the persistent connection code segment includes a first partition code segment that causes the computer to establish the persistent connection between the client and a persistent connection service in response to the first request from the client; and
the broker code segment includes a second partition code segment that causes the computer to use a broker service to broker the connection between the client and the secured service based on the second request from the client.
11 . The computer program of claim 10 wherein the second partition code segment comprises a reception code segment that causes the computer to receive from the persistent connection service at a connection request address a communication based on the second request from the client.
12 . The computer program of claim 1 wherein the broker code segment comprises:
a liaison code segment that causes the computer program to communicate as an intermediary with the client and the secured service based on the second request from the client so that the client may obtain authorization information that may be used to establish the connection to the secured service;
a determining code segment that causes the computer to determine the authorization information based on the second request from the client;
a communication code segment that causes the computer to communicate to the secured service an indication that the client desires to connect to the secured service, wherein the indication comprises the authorization information;
a receiving code segment that causes the computer to receive a response from the secured service indicating that the client may be allowed to establish the connection to the secured service by presenting the authorization information to the secured service; and
an authorization code segment that causes the computer to communicate the authorization information to enable the client to present the authorization information to the secured service to establish the connection with the secured service.
13 . The computer program of claim 1 wherein the broker code segment further comprises:
a liaison code segment that causes the computer program to communicate as an intermediary with the client and the secured service based on the second request from the client so that the client may obtain authorization information that may be used to establish the connection to the secured service;
a communication code segment that causes the computer to communicate to the secured service an indication that the client desires to connect to the secured service;
a receiving code segment that causes the computer to receive a response from the secured service indicating that the secured service may accept a connection from the client, wherein the response includes the authorization information;
an authorization code segment that causes the computer to communicate the authorization information to enable the client to present the authorization information to the secured service to establish the connection with the secured service.
14 . The computer program of claim 13 wherein the response received by the computer from the secured service includes authorization information determined by the secured service.
15 . The computer program of claim 1 wherein:
the broker code segment includes a liaison code segment that causes the computer program to communicate as an intermediary with the client and the secured service based on the second request from the client so that the client may obtain authorization information that may be used to establish the connection to the secured service;
the authorization information comprises constraint information; and
the authorization information may be ineffective to establish a connection with the secured service if the connection constraints are not satisfied by the constraint information.
16 . The computer program of claim 15 wherein the connection constraints include a constraint that limits a number of uses for the authorization information to a predetermined threshold number.
17 . The computer program of claim 16 wherein the connection constraints include a one-time-use password.
18 . The computer program of claim 15 wherein the connection constraints include a constraint that the authorization information be used within a predetermined time window.
19 . The computer program of claim 15 wherein the connection constraints include a constraint that the authorization information be presented to the secured service by a client for whom the connection was brokered.
20 . A method of leveraging a persistent connection to provide a client access to a secured service, the method comprising:
receiving a first request from a client; establishing a persistent connection with the client in response to the first request from the client; receiving a second request from the client; and brokering a connection between the client and a secured service based on the second request from the client by leveraging the persistent connection with the client.Join the waitlist — get patent alerts
Track US2014317695A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.