IP Library Granted Patent US 8,832,787
Granted Patent B1
US 8,832,787 · App. 12/390,110 · Granted Sep 9, 2014

Implementing single sign-on across a heterogeneous collection of client/server and web-based applications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,832,787
App. No.
12/390,110
Granted
Sep 9, 2014
Kind
B1
Abstract

Leveraging an established authenticated session in obtaining authentication to a client application includes receiving a request for access to a client application requiring authentication of a requestor and determining whether there exist characteristics of leverageable authentications corresponding to established sessions having an authenticated state at a time of the determination. When the determination reveals characteristics of at least one leverageable authentication corresponding to an established session, and attempt is made to obtain access for the requestor to the client application based on the at least one leverageable authentication, and the requestor is provided with a notification related to the 1 attempt to obtain access for the requestor to the client application.

Claims (45)

1. A method of leveraging an established authenticated session in obtaining authentication to an application, the method comprising:

receiving, at an application server system, an application token sent, over a network, by an access device as part of a request to establish an authenticated session with the application server system, the application token being specific to the application server system and being generated by a token generating system in response to a request from the access device, the token generating system generating the token by leveraging a persistent authenticated session established between the access device and another application server system, and the token generating system being different from the access device and the application server system;

validating, by the application server system, the application token, the validation being performed by the application server based on the application token and without requiring communication between the application server system and the token generating system after receipt of the application token; and

in response to the application validating the application token, establishing, by the application server system, an authenticated session with the access device.

2. The method of claim 1 wherein:

receiving the application token comprises receiving an application token that includes a checksum of the application token contents; and

validating the application token comprises validating the checksum included in the application token.

3. The method of claim 1 wherein:

receiving the application token comprises receiving an application token that is encrypted with a secret key; and

validating the application token comprises decrypting the application token using the secret key.

4. The method of claim 1 wherein receiving the application token comprises receiving an application token transmitted from the access device to the application server system using a browser client.

5. The method of claim 4 wherein receiving the application token transmitted from the access device to the application server system using a browser client comprises receiving an application token passed as query data on a uniform resource locator of the application server system returned to the access device from the token generating system in the form of a hypertext transfer protocol redirect in response to an image request.

6. The method of claim 1 wherein:

receiving the application token comprises receiving an application token that includes a timestamp that indicates when the token was generated; and

validating the application token comprises determining whether the application token is older than a configurable maximum age based on the timestamp and rejecting the application token in response to a determination that the application token is older than the configurable maximum age.

7. The method of claim 1 wherein:

receiving the application token comprises receiving an application token that includes a random number; and

validating the application token comprises validating that the random number included in the application token matches a random number included in an encrypted cookie that is only readable and writable by the application server system on a browser of the access device.

8. The method of claim 1 wherein the request to establish the authenticated session with the application server system is a request from a browser program of the access device and the token generating system generated the token by leveraging a persistent authenticated session established by a non-browser program of the access device.

9. The method of claim 1 wherein the request to establish the authenticated session with the application server system is a request from a non-browser program of the access device and the token generating system generated the token by leveraging a persistent authenticated session established by a browser program of the access device.

10. The method of claim 1 wherein the application token was generated by the token generating system in response to receiving a master token from the access device, the master token having been generated by the token generating system in response to the access device providing valid login credentials to the token generating system and having been stored on the access device.

11. A computer program product on a non-transitory computer storage medium comprising instruction operable for an application server system configured to perform operations comprising:

receiving an application token sent, over a network, by an access device as part of a request to establish an authenticated session with the application server system, the application token being specific to the application server system and being generated by a token generating system in response to a request from the access device, the token generating system generating the token by leveraging a persistent authenticated session established between the access device and another application server system, and the token generating system being different from the access device and the application server system;

validating the application token, the validation being performed by the application server based on the application token and without requiring communication between the application server system and the token generating system after receipt of the application token; and

in response to the application validating the application token, establishing an authenticated session with the access device.

12. The computer program product of claim 11 wherein:

receiving the application token comprises receiving an application token that includes a checksum of the application token contents; and

validating the application token comprises validating the checksum included in the application token.

13. The computer program product of claim 11 wherein:

receiving the application token comprises receiving an application token that is encrypted with a secret key; and

validating the application token comprises decrypting the application token using the secret key.

14. The computer program product of claim 11 wherein receiving the application token comprises receiving an application token transmitted from the access device to the application server system using a browser client.

15. The computer program product of claim 14 wherein receiving the application token transmitted from the access device to the application server system using a browser client comprises receiving an application token passed as query data on a uniform resource locator of the application server system returned to the access device from the token generating system in the form of a hypertext transfer protocol redirect in response to an image request.

16. The computer program product of claim 11 wherein:

receiving the application token comprises receiving an application token that includes a timestamp that indicates when the token was generated; and

validating the application token comprises determining whether the application token is older than a configurable maximum age based on the timestamp and rejecting the application token in response to a determination that the application token is older than the configurable maximum age.

17. The computer program product of claim 11 wherein:

receiving the application token comprises receiving an application token that includes a random number; and

validating the application token comprises validating that the random number included in the application token matches a random number included in an encrypted cookie that is only readable and writable by the application server system on a browser of the access device.

18. The computer program product of claim 11 wherein the request to establish the authenticated session with the application server system is a request from a browser program of the access device and the token generating system generated the token by leveraging a persistent authenticated session established by a non-browser program of the access device.

19. The computer program product of claim 11 wherein the request to establish the authenticated session with the application server system is a request from a non-browser program of the access device and the token generating system generated the token by leveraging a persistent authenticated session established by a browser program of the access device.

20. A system comprising:

means for receiving an application token sent, over a network, by an access device as part of a request to establish an authenticated session with an application server system, the application token being specific to the application server system and being generated by a token generating system in response to a request from the access device, the token generating system generating the token by leveraging a persistent authenticated session established between the access device and another application server system, and the token generating system being different from the access device and the application server system;

means for validating the application token, the validation being performed by the application server based on the application token and without requiring communication between the application server system and the token generating system after receipt of the application token; and

means for, in response to the application validating the application token, establishing an authenticated session with the access device.

Assignments (13)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2012
From: AOL, INC.; RELEGANCE CORPORATION
To: CITRIX SYSTEMS, INC.
Reel/Frame 028391/0832 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 16, 2010
From: BANK OF AMERICA, N A
To: AOL INC; AOL ADVERTISING INC; GOING INC; LIGHTNINGCAST LLC; MAPQUEST, INC; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC; TACODA LLC; TRUVEO, INC; YEDDA, INC
Reel/Frame 025323/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2009
From: AOL LLC
To: AOL INC.
Reel/Frame 023723/0645 →
SECURITY AGREEMENT Recorded Dec 14, 2009
From: AOL INC.; AOL ADVERTISING INC.; BEBO, INC.; ICQ LLC; GOING, INC.; LIGHTNINGCAST LLC; MAPQUEST, INC.; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC.; TACODA LLC; TRUVEO, INC.; YEDDA, INC.
To: BANK OF AMERICAN, N.A. AS COLLATERAL AGENT
Reel/Frame 023649/0061 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2009
From: SANIN, ALEKSEY; TOOMEY, CHRISTOPHER; KEISTER, ALAN; WICK, ANDREW L.; WATKINS, ROBERT, `; EAVES, DONALD; ZHANG, XIAOPENG; RICHARDS, RUSSELL
To: AOL LLC
Reel/Frame 022291/0833 →