US2021297492A1PendingUtilityA1

Maintaining a session across multiple web applications

Assignee: CITRIX SYSTEMS INCPriority: Mar 29, 2017Filed: Jun 9, 2021Published: Sep 23, 2021
Est. expiryMar 29, 2037(~10.7 yrs left)· nominal 20-yr term from priority
H04L 67/146H04L 67/141H04L 67/025H04L 63/0838
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A technique for maintaining user sessions across multiple web applications includes receiving, by a first web application running on a first server, a cross-application request from a client application. The cross-application request indicates a user action to access a second web application, which runs on a second server. In response to receiving the cross-application request, the first web application sends a single-use password to the client application, which may send the single-use password to the second web application. The first web application receives a session request, which includes the single-use password, from the second web application. In response to receiving the session request, the first web application sends session data to the second web application, enabling the second web application to participate in a session with the client application.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of maintaining user sessions across multiple web applications, the method comprising:
 receiving, by a first web application running on a first server, a cross-application request from a client application running on a client device, the cross-application request indicating a user action to access a second web application, the second web application running on a second server;   sending, by the first web application in response to receiving the cross-application request, a single-use password to the client application;   receiving, by the first web application, a session request from the second web application, the session request including (i) the single-use password as received by the second web application from the client application and (ii) a service secret that identifies the second web application as trusted; and   in response to confirming that the service secret as received from the second web application is valid, sending, by the first web application, session data to the second web application, the session data (i) pertaining to a session previously established between the client application and the first web application and (ii) enabling the second web application to participate in the session with the client application.   
     
     
         2 . The method of  claim 1 , further comprising:
 the first server generating the single-use password in response to the first web application receiving the cross-application request, the first server generating the single-use password with a predefined expiration period,   wherein the first web application is configured to treat the single-use password as invalid after the expiration period has elapsed.   
     
     
         3 . The method of  claim 2 , further comprising, prior to the first server receiving the cross-application request:
 creating the session data upon establishing the session with the client application and after successfully authenticating a user of the client application;   assigning a session key to the session data, the session key uniquely identifying the session data for the session from among other session data for other sessions; and   sending the session key to the client application.   
     
     
         4 . The method of  claim 3 , wherein the session key is a random or pseudorandom value. 
     
     
         5 . The method of  claim 3 , wherein the cross-application request received from the client device includes the session key as previously sent to the client application. 
     
     
         6 . The method of  claim 5 , further comprising, after establishing the session with the client application and prior to receiving the cross-application request, sending a web page to the client device to be rendered by the client application, the web page including a user control configured to issue the cross-application request when operated by the user. 
     
     
         7 . The method of  claim 1 , further comprising, when sending the session data to the second web application, also sending the session key to the second web application. 
     
     
         8 . The method of  claim 1 , wherein the session data as sent to the second web application includes a list of allowed operations that the user is permitted to perform, such that the web second application can restrict activities of the user to those included in the list of allowed operations. 
     
     
         9 . The method of  claim 1  wherein, prior to the first web application receiving the cross-application request, the method further includes assigning the service secret to the second web application by a platform server that unifies the first web application and the second web application under a common framework, 
     
     
         10 . A system, comprising a first server that runs a first web application and a second server that runs a second web application,
 the first web application configured to:
 receive a cross-application request from a client application that runs on a client device, the cross-application request indicating a user action to access the second web application; and 
 in response to receipt of the cross-application request, send a single-use password to the client application; 
   the second web application configured to:
 receive an access request from the client application, the access request including the single-use password; and 
 send a session request to the first web application, the session request including (i) the single-use password as received by the second web application in the access request and (ii) a service secret that identifies the second web application as trusted; 
   wherein the first web application is further configured to send, in response to confirmation that the service secret as received from the second web application is valid, session data to the second web application, the session data pertaining to a session previously established between the client application and the first web application, and   wherein the second web application is further configured to participate in the session with the client application.   
     
     
         11 . The method of  claim 10 , wherein the first web application and the second web application are hosted from different Internet domains. 
     
     
         12 . The method of  claim 11 , wherein the second web application configured to participate in the session with the client application is further configured to send content to the client application within the session. 
     
     
         13 . The method of  claim 12 , wherein the first web application is further configured to successfully authenticate a user of the client application and provide an indication of successful authentication of the user in the session data,
 wherein the second web application is further configured to send the content to the client application based on the successful authentication of the user by the first web application and without requiring additional authentication of the user by the second web application.   
     
     
         14 . A system, comprising a first server that includes a set of processors coupled to memory to form control circuitry, the control circuitry including instructions that implement a first web application constructed and arranged to:
 receive a cross-application request from a client application that runs on a client device, the cross-application request indicating a user action to access the second web application;   in response to receipt of the cross-application request, send a single-use password to the client application;   receive a session request from a second web application that runs on a second server, the session request including the single-use password as received by the second web application from the client application; and   in response to receipt of the session request, send session data to the second web application, the session data (i) pertaining to a session previously established between the client application and the first web application and (ii) enabling the second web application to participate in the session with the client application, the session data including a list of allowed operations that the user is permitted to perform, such that the second web application can restrict activities of the user to those included in the list of allowed operations.   
     
     
         15 . The system of  claim 14 , wherein the first web application is further constructed and arranged to:
 generate the single-use password, having a predefined expiration period, in response to the first web application receiving the cross-application request,   wherein the first web application is further constructed and arranged to treat the single-use password as invalid after the expiration period has elapsed.   
     
     
         16 . The system of  claim 15 , wherein the first web application is further constructed and arranged, prior to receipt of the cross-application request, to:
 create the session data upon establishing the session with the client application and after successfully authenticating a user of the client application;   assign a session key to the session data, the session key uniquely identifying the session data for the session from among other session data for other sessions; and   send the session key to the client application.   
     
     
         17 . The system of  claim 16 , wherein the cross-application request received from the client device includes the session key as previously sent to the client application. 
     
     
         18 . The system of  claim 17 , wherein the first web application is further constructed and arranged to, after establishment of the session with the client application and prior to receipt the cross-application request, send a web page to the client device to be rendered by the client application, the web page including a user control configured to issue the cross-application request when operated by the user. 
     
     
         19 . The system of  claim 14 , wherein the session request received from the second web application further includes a service secret that identifies the second web application as trusted, and wherein the first web application is constructed and arranged to send the session data to the second web application only after the first web application confirms that the service secret as received from the second web application is valid. 
     
     
         20 . The system of  claim 19 , wherein the first web application constructed and arranged to send the session data to the second web application is further constructed and arranged to send the session key to the second web application.

Join the waitlist — get patent alerts

Track US2021297492A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.