Patent · US2024070257A1 · A1 · US
Assume user identity authentication flow
- (11) Publication number
- US2024070257A1
- (21) Application number
- 17/897,575
- (22) Filing date
- 2022-08-29
- (30) Priority date
- 2022-08-29
- (43) Publication date
- 2024-02-29
- (51) IPC
- G06F 21/33; G06F 21/44
- (52) CPC
- G06F Electric digital data processing: 21/44, 21/33, 21/335
- (73) Assignee
- UiPath Inc
- (72) Inventors
- Arabela Elena Paslaru; Calin Popa; Radu OANCEA; Sriram Vasudevan; Raja Charu Vikram Kakumani; Zawad CHOWDHURY
- (54) Title
- Assume user identity authentication flow
- (57) Abstract
A method is implemented by a controller executed on at least one processor. The method provides pre-authorized access to a robotic process automation for a resource associated with a job. The method includes causing, by the controller, the robotic process automation to assume a user identity during an authentication flow to enable access by the robotic process automation to a resource. The method includes issuing, by the controller, tokens to the robotic process automation during the authentication flow. The method includes enabling, by the controller via the tokens, the identity service that governs the resource to participate in operations of the controller to provide the pre-authorized access to the robotic process automation.
- Full text
- View on Google Patents
Claims (1)
- A method implemented by a controller executed on at least one processor, the method providing pre-authorized access to a robotic process automation for a resource associated with a job, the method comprising: causing, by the controller, the robotic process automation to assume a user identity during an authentication flow to enable access by the robotic process automation to a resource; issuing, by the controller, one or more tokens to the robotic process automation during the authentication flow; and enabling, by the controller via the one or more tokens, the identity service that governs the resource to participate in operations of the controller to provide the pre-authorized access to the robotic process automation. 2. The method of claim 1, wherein the job comprises a considered unit of work executed by the robotic process automation. 3. The method of claim 1, wherein the controller comprises a robot controller includes a framework of policies and technologies to manage, automatically execute, and operate the robotic process automation. 4. The method of claim 1, wherein the robotic process automation comprises agent software. 5. The method of claim 1, wherein the identity service comprises a framework of policies and identity and access management technologies to ensure that the user identity has appropriate access to the resource. 6. The method of claim 1, wherein the identity service confirms pre-authorized privileges for the controller. 7. The method of claim 1, wherein the controller confirms pre-authorized privileges for the robotic process automation. 8. The method of claim 1, wherein the controller confirms pre-authorized privileges for the job. 9. The method of claim 1, wherein the controller points the robotic process automation to a credential vault to procure credentials. 10. The method of claim 1, wherein the resource comprises a server, a database, or a filed system known by the identity service. 11. A system providing pre-authorized access to a robotic process automation for a resource associated with a job, the system comprising at least one processor executing a controller configured to: cause the robotic process automation to assume a user identity during an authentication flow to enable access by the robotic process automation to a resource; issue one or more tokens to the robotic process automation during the authentication flow; and enable, via the one or more tokens, the identity service that governs the resource to participate in operations of the controller to provide the pre-authorized access to the robotic process automation. 12. The system of claim 11, wherein the job comprises a considered unit of work executed by the robotic process automation. 13. The system of claim 11, wherein the controller comprises a robot controller includes a framework of policies and technologies to manage, automatically execute, and operate the robotic process automation. 14. The system of claim 11, wherein the robotic process automation comprises agent software. 15. The system of claim 11, wherein the identity service comprises a framework of policies and identity and access management technologies to ensure that the user identity has appropriate access to the resource. 16. The system of claim 11, wherein the identity service confirms pre-authorized privileges for the controller. 17. The system of claim 11, wherein the controller confirms pre-authorized privileges for the robotic process automation. 18. The system of claim 11, wherein the controller confirms pre-authorized privileges for the job. 19. The system of claim 11, wherein the controller points the robotic process automation to a credential vault to procure credentials. 20. The system of claim 11, wherein the resource comprises a server, a database, or a filed system known by the identity service.
Description
This disclosure generally relates to automation, and more specifically, to pre-authorized access by robotic process automation (RPA).
Generally, conventional computer systems can implement authorization and authentication protocols. Further, an identity layer or a compact Uniform Resource Locator (URL)-safe means of representing claims to be transferred between two parties, like OpenID Connect 1.0 (OIDC) token or JavaScript Object Notation (JSON) Web Token (JWT), can be used by conventional computer systems on top such authorization and authentication protocols.
Yet, RPAs that use OIDC tokens and JWTs to authenticate are presently limited to one robot identity, which makes it impossible for conventional computer systems to identify which RPAs access what resources. More particularly, problems exist whenever RPAs (e.g., automation jobs) have to execute periodically, and the RPAs require authorization to access external systems. By way of example, when the RPAs need to interact with external systems, credential artifacts would have to be included in the RPAs, or at a controller that asks the RPAs to be executed. Further, including the credential artifacts in RPAs or at the controller creates issues respective to managing credential expirations, compliant handling of the secrets against attacks, etc.
Thus, delegation flows (such as with OAuth 2.0 protocol) within conventional computer systems do not work where there is no user present at authentication of RPAs.
According to one or more embodiments, a method is implemented by a controller executed on at least one processor.
Record as JSON
{
"publication_number": "US2024070257A1",
"country": "US",
"kind": "A1",
"title": "Assume user identity authentication flow",
"abstract": "A method is implemented by a controller executed on at least one processor. The method provides pre-authorized access to a robotic process automation for a resource associated with a job. The method includes causing, by the controller, the robotic process automation to assume a user identity during an authentication flow to enable access by the robotic process automation to a resource. The method includes issuing, by the controller, tokens to the robotic process automation during the authentication flow. The method includes enabling, by the controller via the tokens, the identity service that governs the resource to participate in operations of the controller to provide the pre-authorized access to the robotic process automation.",
"claims": [
"1. A method implemented by a controller executed on at least one processor, the method providing pre-authorized access to a robotic process automation for a resource associated with a job, the method comprising: causing, by the controller, the robotic process automation to assume a user identity during an authentication flow to enable access by the robotic process automation to a resource; issuing, by the controller, one or more tokens to the robotic process automation during the authentication flow; and enabling, by the controller via the one or more tokens, the identity service that governs the resource to participate in operations of the controller to provide the pre-authorized access to the robotic process automation. 2. The method of claim 1, wherein the job comprises a considered unit of work executed by the robotic process automation. 3. The method of claim 1, wherein the controller comprises a robot controller includes a framework of policies and technologies to manage, automatically execute, and operate the robotic process automation. 4. The method of claim 1, wherein the robotic process automation comprises agent software. 5. The method of claim 1, wherein the identity service comprises a framework of policies and identity and access management technologies to ensure that the user identity has appropriate access to the resource. 6. The method of claim 1, wherein the identity service confirms pre-authorized privileges for the controller. 7. The method of claim 1, wherein the controller confirms pre-authorized privileges for the robotic process automation. 8. The method of claim 1, wherein the controller confirms pre-authorized privileges for the job. 9. The method of claim 1, wherein the controller points the robotic process automation to a credential vault to procure credentials. 10. The method of claim 1, wherein the resource comprises a server, a database, or a filed system known by the identity service. 11. A system providing pre-authorized access to a robotic process automation for a resource associated with a job, the system comprising at least one processor executing a controller configured to: cause the robotic process automation to assume a user identity during an authentication flow to enable access by the robotic process automation to a resource; issue one or more tokens to the robotic process automation during the authentication flow; and enable, via the one or more tokens, the identity service that governs the resource to participate in operations of the controller to provide the pre-authorized access to the robotic process automation. 12. The system of claim 11, wherein the job comprises a considered unit of work executed by the robotic process automation. 13. The system of claim 11, wherein the controller comprises a robot controller includes a framework of policies and technologies to manage, automatically execute, and operate the robotic process automation. 14. The system of claim 11, wherein the robotic process automation comprises agent software. 15. The system of claim 11, wherein the identity service comprises a framework of policies and identity and access management technologies to ensure that the user identity has appropriate access to the resource. 16. The system of claim 11, wherein the identity service confirms pre-authorized privileges for the controller. 17. The system of claim 11, wherein the controller confirms pre-authorized privileges for the robotic process automation. 18. The system of claim 11, wherein the controller confirms pre-authorized privileges for the job. 19. The system of claim 11, wherein the controller points the robotic process automation to a credential vault to procure credentials. 20. The system of claim 11, wherein the resource comprises a server, a database, or a filed system known by the identity service."
],
"description_excerpt": "This disclosure generally relates to automation, and more specifically, to pre-authorized access by robotic process automation (RPA).\n\nGenerally, conventional computer systems can implement authorization and authentication protocols. Further, an identity layer or a compact Uniform Resource Locator (URL)-safe means of representing claims to be transferred between two parties, like OpenID Connect 1.0 (OIDC) token or JavaScript Object Notation (JSON) Web Token (JWT), can be used by conventional computer systems on top such authorization and authentication protocols.\n\nYet, RPAs that use OIDC tokens and JWTs to authenticate are presently limited to one robot identity, which makes it impossible for conventional computer systems to identify which RPAs access what resources. More particularly, problems exist whenever RPAs (e.g., automation jobs) have to execute periodically, and the RPAs require authorization to access external systems. By way of example, when the RPAs need to interact with external systems, credential artifacts would have to be included in the RPAs, or at a controller that asks the RPAs to be executed. Further, including the credential artifacts in RPAs or at the controller creates issues respective to managing credential expirations, compliant handling of the secrets against attacks, etc.\n\nThus, delegation flows (such as with OAuth 2.0 protocol) within conventional computer systems do not work where there is no user present at authentication of RPAs.\n\nAccording to one or more embodiments, a method is implemented by a controller executed on at least one processor.",
"cpc": [
"G06F 21/44",
"G06F 21/33",
"G06F 21/335"
],
"ipc": [
"G06F 21/33",
"G06F 21/44"
],
"assignees": [
"UiPath Inc"
],
"inventors": [
"Arabela Elena Paslaru",
"Calin Popa",
"Radu OANCEA",
"Sriram Vasudevan",
"Raja Charu Vikram Kakumani",
"Zawad CHOWDHURY"
],
"filing_date": "2022-08-29",
"publication_date": "2024-02-29",
"priority_date": "2022-08-29",
"application_number": "US-202217897575-A",
"family_id": "89996735",
"cited_by_count": 4
}
Record 537 of 8,000 in Patents full text (MLC-0201). Request the full dataset.