US2022158990A1PendingUtilityA1

Single-sign-on for third party mobile applications

Assignee: CITRIX SYSTEMS INCPriority: Jul 6, 2018Filed: Feb 4, 2022Published: May 19, 2022
Est. expiryJul 6, 2038(~12 yrs left)· nominal 20-yr term from priority
H04L 63/0876H04W 12/37H04L 63/0272H04L 63/0815H04L 63/0853H04W 12/06H04W 12/069H04L 63/0823
60
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A mobile computing device includes a memory and a processor cooperating with the memory to operate a first native SaaS application requiring authentication to access a first SaaS service, and operate a virtual private network (VPN) application. The VPN application is to store an identity provider (IDP) authentication token based on authentication of the VPN application with an identity provider, and intercept traffic from the first SaaS service to the first native SaaS application. The intercepted traffic is modified by inserting the IDP authentication token to be presented to the identity provider without requiring the user to login for authentication, and with the identity provider providing a first SaaS application access token to the VPN application upon authentication.

Claims

exact text as granted — not AI-modified
1 . A mobile computing device comprising:
 a memory and a processor cooperating with said memory to perform the following:
 operate a first native SaaS application requiring authentication to access a first SaaS service, and 
 operate a virtual private network (VPN) application to perform the following:
 store an identity provider (IDP) authentication token based on authentication of the VPN application with an identity provider, 
 intercept traffic from the first SaaS service to the first native SaaS application, and 
 modify the intercepted traffic by inserting the IDP authentication token to be presented to the identity provider without requiring the user to login for authentication, with the identity provider providing a first SaaS application access token to the VPN application upon authentication. 
 
   
     
     
         2 . The mobile computing device according to  claim 1  wherein said processor is further configured to operate the VPN application to provide the first SaaS application access token to the first native SaaS application to be used to complete authentication. 
     
     
         3 . The mobile computing device according to  claim 1  wherein the intercepted traffic is to redirect the first native SaaS application to the identity provider for the authentication. 
     
     
         4 . The mobile computing device according to  claim 1  wherein said processor is further configured to perform the following:
 operate a second native SaaS application requiring authentication to access a second SaaS service, and 
 operate the VPN application to perform the following:
 intercept traffic from the second SaaS service to the second native SaaS application, and 
 modify the intercepted traffic by inserting the IDP authentication token to be presented to the identity provider without requiring the user to login for authentication, with the identity provider providing a second SaaS application access token to the VPN application upon authentication. 
 
 
     
     
         5 . The mobile computing device according to  claim 1  wherein a session for the first native SaaS application has expired, and wherein said processor is further configured to perform the following:
 re-launch the first native SaaS application based on user input; 
 operate the first native SaaS application to access the first SaaS service, with the first SaaS service redirecting the first native SaaS application to the identity provider for authentication; 
 operate the VPN application to intercept traffic from the first native SaaS application to the identity provider, with the VPN application modifying the intercepted traffic by inserting the IDP authentication token to be presented to the identity provider without requiring the user to login for authentication, with the identity provider providing a new first SaaS application access token to the VPN upon authentication, and with the VPN application then providing the new first SaaS application access token to the first native SaaS application; and 
 operate the first native SaaS application to provide the new first SaaS application access token to the first SaaS service to complete re-authentication. 
 
     
     
         6 . The mobile computing device according to  claim 1  wherein the VPN application uses a client certificate to authenticate with the identity provider to receive the IDP authentication token. 
     
     
         7 . The mobile computing device according to  claim 1  wherein the VPN application uses the user's login information to authenticate with the identity provider to receive the IDP authentication token. 
     
     
         8 . The mobile computing device according to  claim 1  wherein said processor operates the VPN application to only intercepts traffic directed to the identity provider while passing traffic as is for other destinations. 
     
     
         9 . The mobile computing device according to  claim 1  wherein the VPN application presents a server certificate when intercepting traffic from the first SaaS service. 
     
     
         10 . The mobile computing device according to  claim 1  wherein the traffic is based on a secure sockets layer (SSL) protocol. 
     
     
         11 . The mobile computing device according to  claim 1  wherein the mobile computing device is enrolled with a mobile device management (MDM) service. 
     
     
         12 . A method for operating a mobile computing device comprising:
 operating a first native SaaS application requiring authentication to access a first SaaS service; and   operating a virtual private network (VPN) application to perform the following:
 store an identity provider (IDP) authentication token based on authentication of the VPN application with an identity provider, 
 intercept traffic from the first SaaS service to the first native SaaS application, and 
 modify the intercepted traffic by inserting the IDP authentication token to be presented to the identity provider without requiring the user to login for authentication, with the identity provider providing a first SaaS application access token to the VPN application upon authentication. 
   
     
     
         13 . The method according to  claim 12  further comprising operating the VPN application to provide the first SaaS application access token to the first native SaaS application to be used to complete authentication. 
     
     
         14 . The method according to  claim 12  wherein the intercepted traffic is to redirect the first native SaaS application to the identity provider for the authentication. 
     
     
         15 . The method according to  claim 12  further comprising:
 operating a second native SaaS application requiring authentication to access a second SaaS service; and 
 operating the VPN application to perform the following:
 intercept traffic from the second SaaS service to the second native SaaS application, and 
 modify the intercepted traffic by inserting the IDP authentication token to be presented to the identity provider without requiring the user to login for authentication, with the identity provider providing a second SaaS application access token to the VPN application upon authentication. 
 
 
     
     
         16 . The method according to  claim 12  wherein a session for the first native SaaS application has expired, and further comprising:
 re-launching the first native SaaS application based on user input; 
 operating the first native SaaS application to access the first SaaS service, with the first SaaS service redirecting the first native SaaS application to the identity provider for authentication; 
 operating the VPN application to intercept traffic from the first native SaaS application to the identity provider, with the VPN application modifying the intercepted traffic by inserting the IDP authentication token to be presented to the identity provider without requiring the user to login for authentication, with the identity provider providing a new first SaaS application access token to the VPN upon authentication, and with the VPN application then providing the new first SaaS application access token to the first native SaaS application; and 
 operating the first native SaaS application to provide the new first SaaS application access token to the first SaaS service to complete re-authentication. 
 
     
     
         17 . The method according to  claim 12  wherein the VPN application uses a client certificate to authenticate with the identity provider to receive the IDP authentication token. 
     
     
         18 . The method according to  claim 12  wherein the VPN application uses the user's login information to authenticate with the identity provider to receive the IDP authentication token. 
     
     
         19 . The method according to  claim 12  further comprising operating the VPN application to only intercepts traffic directed to the identity provider while passing traffic as is for other destinations. 
     
     
         20 . A non-transitory computer readable medium for operating a mobile computing device, and with the non-transitory computer readable medium having a plurality of computer executable instructions for causing the mobile computing device to perform steps comprising:
 operating a first native SaaS application requiring authentication to access a first SaaS service; and   operating a virtual private network (VPN) application to perform the following:
 store an identity provider (IDP) authentication token based on authentication of the VPN application with an identity provider, 
 intercept traffic from the first SaaS service to the first native SaaS application, and 
 modify the traffic by inserting the IDP authentication token to be presented to the identity provider without requiring the user to login for authentication, with the identity provider providing a first SaaS application access token to the VPN application upon authentication.

Join the waitlist — get patent alerts

Track US2022158990A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.