US2013081126A1PendingUtilityA1

System and method for transparent single sign-on

Assignee: ROCKSTAR CONSORTIUM US LPPriority: Sep 25, 2006Filed: Nov 19, 2012Published: Mar 28, 2013
Est. expirySep 25, 2026(~0.1 yrs left)· nominal 20-yr term from priority
H04L 63/0815
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for transparent single sign-on authentication on computers in a networked environment. An embodiment includes receiving an authentication request from an operating system of a first computer, requesting credentials of an application making the authentication request, authenticating the credentials, storing the credentials if the authentication is successful, and transmitting the credentials to a second computer. On subsequent access requests made by the user on the second computer, the credentials can be retrieved from the secure store, eliminating the need to prompt the user to re-enter authentication information.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of providing single sign-on service to a user of a user computing device, the method comprising:
 providing an operating system on the user computing device, the operating system configured between a plurality of applications on the user computing device and a single sign-on provider;   receiving in the operating system respective authentication requests from the plurality of applications; and   forwarding authentication requests corresponding to the received authentication requests from the operating system to the single sign-on provider.   
     
     
         2 . The method of  claim 1 , further comprising providing a single sign-on provider interface between the operating system and the single sign-on provider, wherein forwarding authentication requests corresponding to the received authentication requests from the operating system to the single sign-on provider comprises forwarding the corresponding authentication requests via the single sign-on provider interface. 
     
     
         3 . The method of  claim 2 , wherein receiving in the operating system respective authentication requests from the plurality of applications and forwarding corresponding authentication requests corresponding to the received authentication requests comprises:
 receiving in the operating system, from a first application controlled by the operating system, a first authentication request from the user;   receiving user credentials from the user;   requesting access for the first application using the received credentials via the single sign-on provider interface;   receiving a user token associated with the user via the single sign-on provider interface;   storing the user token associated with the user;   receiving in the operating system, from a second application controlled by the operating system, a second authentication request from the user;   retrieving the stored user token; and   requesting access for the second application using the retrieved user token via the single sign-on provider interface.   
     
     
         4 . The method of  claim 3 , further comprising:
 in response to the first authentication request from the user, determining that a user token associated with the user has not yet been stored; and   in response to determining that a user token associated with the user has not yet been stored, prompting the user to provide user credentials.   
     
     
         5 . The method of  claim 4 , wherein the single sign-on provider interface:
 determines that a user token associated with the user has not yet been stored;   prompts the user to provide user credentials via the operating system;   receives the user credentials via the operating system;   forwards the received credentials to the single sign-on function; and   receives and stores the user token associated with the user.   
     
     
         6 . The method of  claim 3 , wherein retrieving the stored token is responsive to determining that a user token associated with the user has been stored. 
     
     
         7 . The method of  claim 3 , comprising verifying the retrieved user token before requesting access for the second application using the retrieved token. 
     
     
         8 . The method of  claim 7 , wherein verification of the retrieved user token comprises determining whether the user has been idle for a predetermined length of time. 
     
     
         9 . The method of  claim 7 , wherein the single sign-on provider interface verifies the retrieved user token. 
     
     
         10 . The method of  claim 3 , further comprising removing the user token from storage when the user is idle for a predetermined length of time. 
     
     
         11 . The method of  claim 3 , wherein the single sign-on provider interface:
 interface determines that a user token associated with the user has been stored;   retrieves the stored user token; and   requests access for the second application using the retrieved user token.   
     
     
         12 . The method of  claim 1 , wherein the single sign-on provider is implemented on a network server coupled to the user computing device. 
     
     
         13 . The method of  claim 12 , wherein the network server is an authentication server. 
     
     
         14 . The method of  claim 1 , wherein the single sign-on provider is implemented on the user computing device. 
     
     
         15 . The method of  claim 1 , further comprising providing an inter-host single sign-on interface on the user computing device between the operating system and a remote computing device, wherein forwarding authentication requests corresponding to the received authentication requests from the operating system to the single sign-on provider comprises forwarding at least one corresponding authentication request via the inter-host single sign-on interface to the remote computing device to request access to at least one application running on the remote computing device. 
     
     
         16 . The method of  claim 15 , further comprising maintaining, in the remote computing device, a list of networked computing devices from which the remote computing device will accept authentication requests. 
     
     
         17 . The method of  claim 15 , wherein the remote computing device has an inter-host single sign-on interface coupled to the inter-host single sign-on interface of the user computing device, the method further comprising:
 receiving at the inter-host single sign-on interface of the remote computing device an authentication request from the inter-host single sign-on interface of the user computing device, an authentication request comprising a user token; and   verifying the received user token.   
     
     
         18 . The method of  claim 17 , wherein verifying the received user token comprises verifying the received user token by comparison with a user token stored at the remote computing device. 
     
     
         19 . The method of  claim 17 , wherein verifying the received user token comprises verifying the received user token by comparison with a user token stored at the single sign-on provider. 
     
     
         20 . The method of  claim 17 , further comprising storing the verified user token at the remote computing device. 
     
     
         21 . The method of  claim 17 , further comprising providing access of the user computing device to the requested at least one application running on the remote computing device after verifying the user token at the remote computing device.

Join the waitlist — get patent alerts

Track US2013081126A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.