IP Library Granted Patent US 8,719,899
Granted Patent B2
US 8,719,899 · App. 12/550,302 · Granted May 6, 2014

Seamless cross-site user authentication status detection and automatic login

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,719,899
App. No.
12/550,302
Granted
May 6, 2014
Kind
B2
Abstract

A system and method for determining in a global network the user network authentication status as the user goes from site to site within the network is provided. Additionally, the system and method provides for transparent or implicit multi-site logon functionality, including automatic introduction from one site to the other using a baseline authentication agency ( 102 ). The system and method provides an architecture for a core global network ( 100 ) (referred to herein as NET) that incorporates some or all of the following features and components: a set of baseline authentication agencies responsible for the core global network (NET) services, such as login and user-selected service-provider lookup; a shared NET domain and associated DNS records ( 106 ) used for cookie ( 110 ) sharing, login routing, and the like; and a collection of partner sites ( 108 ) accessible via the NET.

Claims (38)

1. A computer-implemented method for a baseline authentication agency allowing for seamless login of a user as the user accesses a site of a collection of sites within a network, the method comprising:

retrieving computer-executable instructions from computer storage of a server of the baseline authentication agency; and

executing the computer-executable instructions on at least one computer processor of the server, thereby causing computer hardware of the server to perform operations comprising:

receiving a request from a browser of the user who has been previously been authenticated by the baseline authentication agency with respect to the network, the request comprising a site identifier related to the site, the request also comprising a cookie related to the user, the cookie including a reference designating the baseline authentication agency, the baseline authentication agency one of a set of baseline authentication agencies and associated with the user, wherein the cookie is stored on a global network domain used for cookie sharing and the collection of sites have access to cookies on the global network domain;

determining whether the cookie is valid;

when the cookie is valid,

determining whether a trust relationship is established between the user and the site indicating that the site is one of a group of partner sites for which the user has defined login parameters;

generating a login ticket for the site and sending the login ticket to the user's browser to allow for seamless login of the user to the site when the trust relationship is established; and

wherein the method further comprises generating JavaScript code that

writes out an HTML form that includes the login ticket as a hidden field and a partner Web site global network login handler as an action URL, and

auto-submits said HTML form such that the user's browser posts the HTML form to the partner Web site, global network login handler URL on the site.

2. The method of claim 1 , further comprising checking if the site identifier is known or valid.

3. The method of claim 1 , wherein the cookie includes a set of user information.

4. The method of claim 1 , wherein sending the login ticket for the site comprises sending the JavaScript code.

5. The method of claim 1 , further comprising:

if the cookie is valid,

receiving the ticket from the site;

determining whether the ticket is valid; and

if the ticket is valid, sending user identification information to the site, the user identification information to be used by the site to login the user.

6. A computer-implemented method for a baseline authentication agency that determines a user's login permission for a site, the method comprising:

retrieving computer-executable instructions from computer storage of a server of the baseline authentication agency; and

executing the computer-executable instructions on at least one computer processor of the server, thereby causing computer hardware of the server to perform operations comprising:

receiving a request from the user's browser, the request comprising a site identifier related to the site, and a user status identifier related to the user and including a reference designating the baseline authentication agency, the baseline authentication agency being one of a set of baseline authentication agencies and is associated with the user;

determining whether the user status identifier is valid;

when the user status identifier is valid, determining whether the user has authorized seamless login for the site, the site selected the by the user to establish the site as one of a group of partner sites for which the user has defined login parameters; and

generating a login ticket for the site and sending the login ticket to the user's browser when the user has authorized seamless login for the site;

wherein the user status identifier is stored on a global network domain used for sharing user status identifiers, and the site is one of a collection of sites with access to cookies on the global network domain; and

wherein the method further comprises generating JavaScript code that

writes out an HTML form comprising the login ticket as a hidden field and a partner Web site global network login handler as an action URL, and

auto-submits said HTML form such that the user's browser posts the HTML form to the partner Web site global network login handler URL on the site.

7. The method of claim 6 , further comprising: checking if the site identifier is known or valid.

8. The method of claim 6 , wherein the user status identifier includes a set of user information.

9. The method of claim 6 , wherein sending the login ticket for the site comprises sending the JavaScript code.

10. The method of claim 6 , further comprising: if the user status identifier is valid,

receiving the ticket from the site;

determining whether the ticket is valid; and

if the ticket is valid,

sending user identification information to the site, the user identification information to be used by the site to login the user.

Assignments (7)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044277/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2014
From: BRIGHT SUN TECHNOLOGIES
To: GOOGLE INC.
Reel/Frame 033488/0331 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2014
From: MARATHON SOLUTIONS LLC
To: BRIGHT SUN TECHNOLOGIES
Reel/Frame 031900/0494 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2012
From: AOL INC.
To: MARATHON SOLUTIONS LLC
Reel/Frame 028911/0969 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 16, 2010
From: BANK OF AMERICA, N A
To: AOL INC; AOL ADVERTISING INC; GOING INC; LIGHTNINGCAST LLC; MAPQUEST, INC; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC; TACODA LLC; TRUVEO, INC; YEDDA, INC
Reel/Frame 025323/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2009
From: AOL LLC
To: AOL INC.
Reel/Frame 023720/0309 →
SECURITY AGREEMENT Recorded Dec 14, 2009
From: AOL INC.; AOL ADVERTISING INC.; BEBO, INC.; ICQ LLC; GOING, INC.; LIGHTNINGCAST LLC; MAPQUEST, INC.; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC.; TACODA LLC; TRUVEO, INC.; YEDDA, INC.
To: BANK OF AMERICAN, N.A. AS COLLATERAL AGENT
Reel/Frame 023649/0061 →