US2017012962A1PendingUtilityA1

System, method and computer program product for enabling access to a resource utilizing a token

Assignee: SALESFORCE COM INCPriority: Sep 12, 2008Filed: Sep 19, 2016Published: Jan 12, 2017
Est. expirySep 12, 2028(~2.1 yrs left)· nominal 20-yr term from priority
G06F 21/335H04L 63/10H04L 63/083H04L 67/146H04L 63/0838G06F 16/176G06F 16/13G06F 21/6227G06F 16/951G06F 16/22G06F 16/11G06F 2221/2141G06F 2221/2119H04L 45/20G06F 21/6218G06F 2221/2117G06F 21/62
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In accordance with embodiments, there are provided mechanisms and methods for enabling access to a resource of a multi-tenant on-demand database service utilizing a token. These mechanisms and methods for enabling access to a resource of a multi-tenant on-demand database service utilizing a token can be utilized to prevent identification of a user attempting to access the resource, and thus unwanted use of the user's identity.

Claims

exact text as granted — not AI-modified
1 .- 11 . (canceled) 
     
     
         12 . A method, comprising:
 receiving, at a first server system, a first request to access a resource;   in response to the first request, generating, by the first server system, an access token;   the first server system storing the access token in a memory;   sending, by the first server system to a browser executed on a device of a user, information that includes the access token, wherein the information is usable by a second server system to provide computer code that is executable, in conjunction with the information, to provide access to the resource; and   providing access to the resource based on the access token.   
     
     
         13 . The method of  claim 12 , further comprising:
 the first server system redirecting the user to the second server system in response to the first request.   
     
     
         14 . The method of  claim 12 , wherein the token is usable by the second server system to permit access to the resource without receiving a session identifier. 
     
     
         15 . The method of  claim 12 , further comprising the first server system receiving login information to authenticate the user. 
     
     
         16 . The method of  claim 12 , further comprising storing a time-to-live value associated with the token, wherein the token is not usable to access the resource after expiration of an interval specified by the time-to-live value. 
     
     
         17 . The method of  claim 12 , further comprising:
 the first server system sending, to the device of the user, the token and an instruction to transmit the token to the second server system.   
     
     
         18 . The method of  claim 12 , wherein the resource is stored in a multi-tenant database system. 
     
     
         19 . A non-transitory computer-readable medium having computer instructions stored thereon that are capable, when executed by at least a first server system, of causing operations comprising:
 receiving a first request to access a resource;   in response to the first request, generating an access token;   storing the access token in a memory;   sending, to a browser executed on a device of a user, information that includes the access token, wherein the information is usable by a second server system to provide computer code that is executable, in conjunction with the information, to provide access to the resource; and   providing access to the resource based on the access token.   
     
     
         20 . The non-transitory computer-readable medium of  claim 19 , wherein the operations further comprise redirecting the user to the second server system in response to the first request. 
     
     
         21 . The non-transitory computer-readable medium of  claim 19 , wherein the token is usable by the second server system to permit access to the resource without receiving a session identifier. 
     
     
         22 . The non-transitory computer-readable medium of  claim 19 , wherein the operations further comprise receiving login information to authenticate the user. 
     
     
         23 . The non-transitory computer-readable medium of  claim 19 , wherein the operations further comprise storing a time-to-live value associated with the token, wherein the token is not usable to access the resource after expiration of an interval specified by the time-to-live value. 
     
     
         24 . The non-transitory computer-readable medium of  claim 19 , wherein the operations further comprise sending, to the device of the user, the token and an instruction to transmit the token to the second server system. 
     
     
         25 . The non-transitory computer-readable medium of  claim 19 , wherein the resource is stored in a multi-tenant database system. 
     
     
         26 . An apparatus, comprising:
 one or more processing elements; and   one or more memories having program instructions stored thereon that are executable by the one or more processing elements to perform operations comprising:
 receiving a first request to access a resource; 
 in response to the first request, generating an access token; 
 storing the access token in a memory; 
 sending, to a browser executed on a device of a user, information that includes the access token, wherein the information is usable by a second server system to provide computer code that is executable, in conjunction with the information, to provide access to the resource; and 
 providing access to the resource based on the access token. 
   
     
     
         27 . The apparatus of  claim 26 , wherein the operations further comprise redirecting the user to the second server system in response to the first request. 
     
     
         28 . The apparatus of  claim 26 , wherein the token is usable by the second server system to permit access to the resource without receiving a session identifier. 
     
     
         29 . The apparatus of  claim 26 , wherein the operations further comprise receiving login information to authenticate the user. 
     
     
         30 . The apparatus of  claim 26 , wherein the operations further comprise storing a time-to-live value associated with the token, wherein the token is not usable to access the resource after expiration of an interval specified by the time-to-live value. 
     
     
         31 . The apparatus of  claim 26 , wherein the operations further comprise sending, to the device of the user, the token and an instruction to transmit the token to the second server system.

Join the waitlist — get patent alerts

Track US2017012962A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.