IP Library Granted Patent US 8,763,102
Granted Patent B2
US 8,763,102 · App. 12/233,666 · Granted Jun 24, 2014

Single sign on infrastructure

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,763,102
App. No.
12/233,666
Granted
Jun 24, 2014
Kind
B2
Abstract

One embodiment is a method that uses a Single Sign On (SSO) infrastructure in an application for creating a security context that identifies a user. The application then passes the security context to a second application and to the user as a cookie. The cookie is passed back to applications to enable SSO access to resources.

Claims (28)

1. A method executed by a computer, comprising: authenticating, by the computer, a user at an application;

calling, by the computer, a Single Sign On (SSO) infrastructure in the application for creating a security context that identifies the user;

passing, by the computer, the security context from the application to a second application and to the user as a cookie; and

calling, by the computer, a SSO infrastructure in the second application to authenticate a request that includes the cookie from the user;

wherein the SSO filter of the second application decrypts an encrypted token in the cookie from a web service (WS) call received from the application to obtain a security context for the user that initiates HTTP (Hyper Text Markup Language) requests to the second application.

2. The method of claim 1 further comprising: encrypting, with the SSO infrastructure in the application, the security context to create the token that is passed in the cookie to the user and passed to the SSO infrastructure of the second application.

3. The method of claim 1 further comprising, placing an expiration time limit on the security context to limit ability of a hacker to use the security context.

4. The method of claim 1 further comprising:

creating an application session at the second application with the security context; and

passing the security context in a cookie from the second application to a browser of the user for use in a subsequent request from the browser to the second application.

5. The method of claim 1 further comprising, enabling the user to be authenticated only once at the application using a single sign on process to gain access to multiple different applications in an enterprise.

6. A tangible non-transitory computer readable storage medium having instructions, that when executed, cause a computer:

authenticate a user at an application that includes Single Sign On (SSO) infrastructure in the application for creating a security context that identifies the user;

pass the security context in a cookie from the application to a browser of the user and to a second application;

perform a Web Service (WS) call that includes the security context from the application to the second application;

use a SSO infrastructure in the second application to retrieve the security context from the WS call, validate the WS call, and respond to the WS call;

create an application session at the second application with the security context; and

pass the security context in a cookie from the second application to the browser of the user for use in a subsequent request from the browser to the second application, wherein the SSO filter of the second application decrypts an encrypted token in the cookie from a web service (WS) call received from the application to obtain a security context for the user that initiates HTTP (Hyper Text Markup Language) requests to the second application.

7. The tangible non-transitory computer readable storage medium of claim 6 comprising instructions that cause the computer to: receive, at the second application and from the browser of the user, the subsequent request that includes the cookie sent from the second application to the browser of the user.

8. The tangible non-transitory computer readable storage medium of claim 6 , wherein the first and second applications share a same secret to validate the browser of the user.

9. The tangible non-transitory computer readable storage medium of claim 6 comprising instructions that cause the computer to, store the security context in an encrypted token in both the application and in the second application.

10. The tangible non-transitory computer readable storage medium of claim 6 , wherein the application authenticates the user for the second application so the user is not required to be re-authenticated at the second application.

11. A computer system, comprising: one or more servers;

a first software application executing on the one or more servers and including a Single Sign On (SSO) filter, a SSO utility, and an application core; and

a second software application executing on the one or more servers and including a SSO filter, a SSO utility, and an application core, wherein the first and second applications communicate to enable both Web SSO and Web Services SSO, and

wherein the first software application transmits over a network an encrypted token in a cookie to a browser so a user can transmit the encrypted token and the cookie back to the first software application and to the second software application to access resources of the first software application and the second software application in a SSO session, wherein the SSO utility of the first software application creates a security context from user login information and from security data that includes groups, roles, and attributes for the user, and the wherein the SSO filter of the second software application decrypts the encrypted token from a WS call.

12. The computer system of claim 11 , wherein the SSO filter of the second software application decrypts the encrypted token from a WS call received from the first software application to obtain a security context for the user that initiates HTTP (Hyper Text Markup Language) requests to the second software application.

13. The computer system of claim 11 , wherein the first software application transfers user data to the second software application so a WS call from the first software application to the second software application can be executed without requiring the user to be re-authenticated.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 063546/0181) Recorded Jun 21, 2024
From: BARCLAYS BANK PLC
To: MICRO FOCUS LLC
Reel/Frame 067807/0076 →
SECURITY INTEREST Recorded Aug 30, 2023
From: MICRO FOCUS LLC
To: THE BANK OF NEW YORK MELLON
Reel/Frame 064760/0862 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0181 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0190 →
SECURITY INTEREST Recorded May 4, 2023
From: MICRO FOCUS LLC
To: BARCLAYS BANK PLC
Reel/Frame 063546/0230 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2008
From: FURMAN, MICHAEL; BARKAN, ASAF
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 021554/0830 →