US2022360575A1PendingUtilityA1

Security for diverse computing systems

Assignee: TERADATA US INCPriority: Dec 28, 2017Filed: Jul 13, 2022Published: Nov 10, 2022
Est. expiryDec 28, 2037(~11.4 yrs left)· nominal 20-yr term from priority
H04L 9/3213H04L 63/0815G06F 21/6218H04L 67/02H04L 9/0894G06F 21/41H04L 63/10H04L 67/1097H04L 63/08H04L 63/0884H04L 67/01
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A security mechanism, e.g., a computing system, security server, can effectively serve as a centralized security mechanism, e.g., a computing system, security server, for an ecosystem that can include diverse clients and servers. The security mechanism can obtain redirected requests for services, authenticate credentials of a client and generate a (client-side) token that can be provided by the client to the server for verification of the identity of the client. The security mechanism can also obtain a token from a server that can be similar to a (client-side) token provided to a client and then generate a (server-side) token that can be provided to a server. The server-side token can include authorization information that allows access to one or more services of one or more other servers.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computing system that includes one or more processors configured to execute computer executable code, wherein the one or more processors are further configured to:
 obtain, from a server, a redirected request for service from the server, wherein the redirected request for service is an initial request for service made by a client to the sever for one or more services of the server;   obtain at least authentication credentials of the client, wherein the authentication credentials of the client are needed to verify the identity of the client;   generate a first token based at least on the authentication credentials of the client, wherein the first token includes authentication information associated with the client that indicates that the identity of the client has been verified; and   provide the first token to the client, thereby allowing the client to send the first token to the server to indicate that the identity of the client has been verified at least partly based on the authentication information.   
     
     
         2 . The computing system of  claim 1 , wherein the one or more processors are further configured to:
 verify the identity of the client based on the obtained authentication credentials of the client.   
     
     
         3 . The computing system of  claim 1 , wherein the one or more processors are further configured to:
 obtain a second token, wherein the second token has been provided by the server and requests access to one or more services of one or more other servers, and   generate a third access token, wherein the third access token includes authorization information allowing the server to access one or more other services one or more other servers, thereby allowing the server to send the token to the one or more other servers to indicate that it has been authorized to access the one or more other services from one or more other servers.   
     
     
         4 . The computing system of  claim 3 , wherein the second token includes the first token and identifies the server. 
     
     
         5 . The computing system of  claim 3 , wherein the second token is the first token that is signed by the server. 
     
     
         6 . The computing system of  claim 1 , wherein the one or more processors are further configured to:
 request the authentication credentials from the client, and   send the first token to the client.   
     
     
         7 . The computing system of  claim 1 , wherein the server is a database server configured to provide access to one database services of a database. 
     
     
         8 . A computer-implemented method of providing security in a computing environment that includes at least one client and at least one server configured to provide one or more services, wherein the computer-implemented method is implemented at least partially by one or more physical processers configured to process executable computer code, and wherein the computer-implemented method comprises:
 obtaining, from the server, a redirected request for service, wherein the redirected request for service is an initial request for service made by the client to the sever for one or more services of the server,   obtaining at least authentication credentials of the client, wherein the authentication credentials of the client are needed to verify the identity of the client;   generating a first token based at least on the authentication credentials of the client, wherein the first token includes authentication information associated with the client and indicates that the identity of the client has been verified; and   providing the first token to the client, thereby allowing the client to send the first token to the server to indicate that the identity of the client has been verified.   
     
     
         9 . The computer-implemented method of  claim 8 , wherein the computer-implemented method further comprises:
 verifying the identity of the client based on the obtained authentication credentials of the client.   
     
     
         10 . The computer-implemented method of  claim 8 , wherein the computer-implemented method further comprises:
 obtaining a second token, wherein the second token has been provided by the server and requests access to one or more services of one or more other servers in the computing environment; and   generating a third token, wherein the third token includes authorization information allowing the server to access one or more other services of the one or more other servers, thereby allowing the server to send the third token to the one or more other servers to indicate that it has been authorized to access the one or more other services from one or more other servers.   
     
     
         11 . The computer-implemented method of  claim 10 , wherein the second token includes the first token and identifies the server. 
     
     
         12 . The computer-implemented method of  claim 10 , wherein the second token is the first token that is signed by the server. 
     
     
         13 . The computer-implemented method of  claim 8 , wherein the computer-implemented method further comprises:
 requesting the authentication credentials from the client, and   sending the first token to the client.   
     
     
         14 . The computer-implemented method of  claim 8 , wherein the server is a database server configured to provide access to one database services of a database. 
     
     
         15 . A non-transitory computer readable storage medium storing at least executable code that when executed provides security in a computing environment that includes at least one client and at least one server configured to provide one or more services, and wherein the executable code when executed further:
 obtains, from the server, a redirected request for service, wherein the redirected request for service is an initial request for service made by the client to the sever for one or more services of the server;   obtains at least authentication credentials of the client, wherein the authentication credentials of the client are needed to verify the identity of the client;   generates a first token based at least on the authentication credentials of the client, wherein the first token includes authentication information associated with the client and indicates that the identity of the client has been verified; and   provides the first token to the client, thereby allowing the client to send the first token to the server to indicate that the identity of the client has been verified.   
     
     
         16 . The non-transitory computer readable storage medium of  claim 15 , wherein the executable code when executed further:
 verifies the identity of the client based on the obtained authentication credentials of the client.   
     
     
         17 . The non-transitory computer readable storage medium of  claim 15 , wherein the executable code when executed further:
 obtains a second token, wherein the second token has been provided by the server and requests access to one or more services of one or more other servers in the computing environment; and   generates a third token, wherein the third token includes authorization information allowing the server to access one or more other services of the one or more other servers, thereby allowing the server to send the third token to the one or more other servers to indicate that it has been authorized to access the one or more other services from one or more other servers.   
     
     
         18 . The non-transitory computer readable storage medium of  claim 17 , wherein the second token includes the first token and identifies the server. 
     
     
         19 . The non-transitory computer readable storage medium of  claim 17 , wherein the second token is the first token that is signed by the server. 
     
     
         20 . The non-transitory computer readable storage medium of  claim 17 , wherein the executable code when executed further:
 requests the authentication credentials from the client, and   sends the first token to the client.

Join the waitlist — get patent alerts

Track US2022360575A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.