IP Library Granted Patent US 8,296,834
Granted Patent B2
US 8,296,834 · App. 12/184,741 · Granted Oct 23, 2012

Secure single-sign-on portal system

Assignee: Deluxe Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,296,834
App. No.
12/184,741
Granted
Oct 23, 2012
Kind
B2
Abstract

A computer-implemented portal system facilitates access to secure data and multiple secure-access internet sites. The system authenticates a user based on a single-sign-on identifier (ID) and password. The system stores user authentication information for the secure-access internet sites so that once the user is authenticated, the system can automatically authenticate the user to the sites, thus allowing the user to access multiple secure sites after a single manual authentication.

Claims (49)

1. A computer enabled system comprising:

a processor;

a single-sign-on user account accessible by a user providing a corresponding single-sign-on user identifier (ID) and password;

a set of secure-access internet sites associated with the single-sign-on user account;

a plurality of user ID and password combinations associated with the set of secure-access internet sites;

an access component configured to automatically enter the combinations into designated locations of the secure-access internet sites to allow the user to access the sites;

a user home page displaying links to the secure-access internet sites, wherein the access component operates, in response to a user selection of one of the links, to automatically enter a user ID and password combination into a secure-internet site corresponding to the link, and wherein the home page includes a link to a secure data storage location storing secure personal data associated with the user; and

a branded portal comprising a graphical user interface adapted to receive the single-sign-on user ID and password, to retrieve the user home page after the single-sign-on user ID and password have been validated, and to provide single-sign-on access to multiple secure services through the branded portal.

2. The system of claim 1 , further comprising a scanned document storing component for storing scanned documents within the secure data storage location in response to user inputs to a graphical interface accessible via the user home page.

3. The system of claim 1 , wherein the single-sign-on user account requires the user to perform two-factor authentication by providing further authentication information in addition to the single-sign-on ID password.

4. The system of claim 3 , wherein the further authentication information comprises one or more of a security code available to the user by a security token, and biometric data.

5. The system of claim 1 , further comprising a password updating component for automatic updating passwords associated with individual sites in the set of secure-access internet sites.

6. The system of claim 1 , wherein the set of secure-access internet sites comprises one or more sites to which multiple users have access; and

wherein the one or more sites are included in the set based on a role associated with the user.

7. The system of claim 6 , further comprising:

a user home page displaying links to the secure-access internet sites, wherein the links are displayed in the home page based on the role associated with the user.

8. A non-transitory computer-readable medium storing a secure-sign-on branded portal program configured to pre-fill at least one login name and code combination for at least one secure-access internet site and enabling a brand owner to provide single-sign-on access to multiple secure services through a branded portal, the program comprising code for executing a method comprising:

judging whether a single-sign-on ID and a single-sign-on password are valid;

accepting the single-sign-on ID and single-sign-on password when valid;

accessing a database to pre-fill the combination for at least one secure-access internet site; wherein the database stores the combination as a result of prior activity of a user account associated with the single-sign-on ID and single-sign-on password;

displaying, via a user home page, links to the at least one secure-access internet site, the user home page including a link to a secure data storage location storing secure personal data associated with the user;

automatically entering, in response to a user selection of one of the links, a user ID and password combination into a secure-internet site corresponding to the link;

receiving, via a branded portal comprising a graphical user interface, the single-sign-on user ID and password; and

retrieving the user home page after the single-sign-on user ID and password have been validated.

9. The computer-readable medium of claim 8 , wherein the method further comprises:

generating a user home page corresponding to the user account, the user home page including links to the at least one secure-access internet site.

10. The computer-readable medium of claim 9 , wherein the method further comprises:

determining a user role based on the single-sign-on ID or single-sign-on password; and

generating the home page with links corresponding to one or more accounts shared by the user and one or more additional users, wherein the links are selected based on the user role.

11. The computer-readable medium of claim 8 , wherein the method further comprises:

automatically updating the password of the combination based on data transmitted from the secure-access internet site to the portal program.

12. A computer implemented method enabling a brand owner to provide single-sign-on access to multiple secure services through a branded portal, comprising:

receiving a single-sign-on identifier (ID) and password combination via a single-sign-on branded portal;

authenticating, a user based on the combination;

after authenticating the user, receiving a request from the user to access a particular secure-access internet site;

upon receiving the request, accessing, a database storing a plurality of user ID and password combinations for a corresponding plurality of secure-access internet sites, receiving a particular user ID and password combination for the particular secure-access internet site, and automatically filling the particular user ID and password combination into designated portions of the particular secure-access site;

displaying, via a user home page, links to the secure-access internet site, the user home page including a link to a secure data storage location storing secure personal data associated with the user;

automatically entering, in response to a user selection of one of the links, a user ID and password combination into a secure-internet site corresponding to the link;

receiving, via a branded portal comprising a graphical user interface, the single-sign-on user ID and password; and

retrieving the user home page after the single-sign-on user ID and password have been validated.

13. The method of claim 12 , wherein the combination further includes, in addition to the single-sign-on identifier and password, information for two-factor authentication.

14. The method of claim 13 , wherein the information for two-factor authentication includes a security code or biometric data.

15. The method of claim 12 , further comprising:

upon authenticating the user, presenting a personalized home page including links to the plurality of secure-access internet sites, wherein the user request is received in response to a user selection of one of the links.

16. The method of claim 15 , wherein multiple users share accounts for one or more of the plurality of secure-access internet sites, and the personalized home page is populated with links to one or more of the internet sites corresponding to the shared accounts based on user login profiles stored in the database.

17. The method of claim 12 , further comprising:

receiving a request to access secure personal data; and

upon receiving the request, generating a graphical user interface providing the user with access to the secure personal data.

18. The method of claim 17 , wherein the secure personal data is stored in the database in an encrypted and compressed form.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Dec 5, 2024
From: DELUXE CORPORATION; DELUXE SMALL BUSINESS SALES, INC.; WAUSAU FINANCIAL SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069525/0854 →
PATENT SECURITY AGREEMENT Recorded Dec 5, 2024
From: DELUXE CORPORATION; DELUXE SMALL BUSINESS SALES, INC.; WAUSAU FINANCIAL SYSTEMS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
Reel/Frame 069525/0878 →
SECURITY INTEREST Recorded Jun 1, 2021
From: DELUXE CORPORATION; DIRECT CHECKS UNLIMITED, LLC; WAUSAU FINANCIAL SYSTEMS, INC.; DELUXE SMALL BUSINESS SALES, INC.; LOGOMIX, INC.
To: JPMORGAN CHASE BANK, N.A,, AS ADMINISTRATIVE AGENT
Reel/Frame 056403/0946 →
RELEASE OF SECURITY INTEREST Recorded Mar 23, 2018
From: JPMORGAN CHASE BANK, N.A.
To: DELUXE CORPORATION
Reel/Frame 045335/0587 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2010
From: ASHBY, JOHN P; RITARI, DANIEL L
To: DELUXE CORPORATION
Reel/Frame 024264/0204 →
SECURITY AGREEMENT Recorded Mar 16, 2010
From: DELUXE CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 024079/0753 →
Continuity (2)
Provisional Application 60935243 · Aug 2, 2007
Related Publication 20090172795A1 · Jul 2, 2009