System and method for transparent single sign-on
Abstract
A method for transparent single sign-on authentication on computers in a networked environment. An embodiment includes receiving an authentication request from an operating system of a first computer, requesting credentials of an application making the authentication request, authenticating the credentials, storing the credentials if the authentication is successful, and transmitting the credentials to a second computer. On subsequent access requests made by the user on the second computer, the credentials can be retrieved from the secure store, eliminating the need to prompt the user to re-enter authentication information.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of providing single sign-on service to a user of a user computing device, the method comprising:
providing an operating system on the user computing device, the operating system configured between a plurality of applications on the user computing device and a single sign-on provider; receiving in the operating system respective authentication requests from the plurality of applications; and forwarding authentication requests corresponding to the received authentication requests from the operating system to the single sign-on provider.
2 . The method of claim 1 , further comprising providing a single sign-on provider interface between the operating system and the single sign-on provider, wherein forwarding authentication requests corresponding to the received authentication requests from the operating system to the single sign-on provider comprises forwarding the corresponding authentication requests via the single sign-on provider interface.
3 . The method of claim 2 , wherein receiving in the operating system respective authentication requests from the plurality of applications and forwarding corresponding authentication requests corresponding to the received authentication requests comprises:
receiving in the operating system, from a first application controlled by the operating system, a first authentication request from the user; receiving user credentials from the user; requesting access for the first application using the received credentials via the single sign-on provider interface; receiving a user token associated with the user via the single sign-on provider interface; storing the user token associated with the user; receiving in the operating system, from a second application controlled by the operating system, a second authentication request from the user; retrieving the stored user token; and requesting access for the second application using the retrieved user token via the single sign-on provider interface.
4 . The method of claim 3 , further comprising:
in response to the first authentication request from the user, determining that a user token associated with the user has not yet been stored; and in response to determining that a user token associated with the user has not yet been stored, prompting the user to provide user credentials.
5 . The method of claim 4 , wherein the single sign-on provider interface:
determines that a user token associated with the user has not yet been stored; prompts the user to provide user credentials via the operating system; receives the user credentials via the operating system; forwards the received credentials to the single sign-on function; and receives and stores the user token associated with the user.
6 . The method of claim 3 , wherein retrieving the stored token is responsive to determining that a user token associated with the user has been stored.
7 . The method of claim 3 , comprising verifying the retrieved user token before requesting access for the second application using the retrieved token.
8 . The method of claim 7 , wherein verification of the retrieved user token comprises determining whether the user has been idle for a predetermined length of time.
9 . The method of claim 7 , wherein the single sign-on provider interface verifies the retrieved user token.
10 . The method of claim 3 , further comprising removing the user token from storage when the user is idle for a predetermined length of time.
11 . The method of claim 3 , wherein the single sign-on provider interface:
interface determines that a user token associated with the user has been stored; retrieves the stored user token; and requests access for the second application using the retrieved user token.
12 . The method of claim 1 , wherein the single sign-on provider is implemented on a network server coupled to the user computing device.
13 . The method of claim 12 , wherein the network server is an authentication server.
14 . The method of claim 1 , wherein the single sign-on provider is implemented on the user computing device.
15 . The method of claim 1 , further comprising providing an inter-host single sign-on interface on the user computing device between the operating system and a remote computing device, wherein forwarding authentication requests corresponding to the received authentication requests from the operating system to the single sign-on provider comprises forwarding at least one corresponding authentication request via the inter-host single sign-on interface to the remote computing device to request access to at least one application running on the remote computing device.
16 . The method of claim 15 , further comprising maintaining, in the remote computing device, a list of networked computing devices from which the remote computing device will accept authentication requests.
17 . The method of claim 15 , wherein the remote computing device has an inter-host single sign-on interface coupled to the inter-host single sign-on interface of the user computing device, the method further comprising:
receiving at the inter-host single sign-on interface of the remote computing device an authentication request from the inter-host single sign-on interface of the user computing device, an authentication request comprising a user token; and verifying the received user token.
18 . The method of claim 17 , wherein verifying the received user token comprises verifying the received user token by comparison with a user token stored at the remote computing device.
19 . The method of claim 17 , wherein verifying the received user token comprises verifying the received user token by comparison with a user token stored at the single sign-on provider.
20 . The method of claim 17 , further comprising storing the verified user token at the remote computing device.
21 . The method of claim 17 , further comprising providing access of the user computing device to the requested at least one application running on the remote computing device after verifying the user token at the remote computing device.Join the waitlist — get patent alerts
Track US2013081126A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.