IP Library Granted Patent US 9,331,991
Granted Patent B2
US 9,331,991 · App. 12/575,121 · Granted May 3, 2016

Authenticating a client using linked authentication credentials

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,331,991
App. No.
12/575,121
Granted
May 3, 2016
Kind
B2
Abstract

Techniques are provided for improving security in a single-sign-on context by providing, to a user's client system, two linked authentication credentials in separate logical communication sessions and requiring that both credentials be presented to a host system. Only after presentation of both credentials is the user authenticated and permitted to access applications on the host system.

Claims (57)

1. A method of facilitating authenticating of a client device, the method comprising:

providing, to a client device in a first communication session, a first authentication credential;

providing, to the client device in a second communication session that is different from the first communication session, a second authentication credential, the second authentication credential being linked to the first authentication credential, wherein the second authentication credential includes a status indicator that indicates that the second authentication credential is inactive, and wherein the second authentication credential, including the status indicator that indicates that the second authentication credential is inactive, by itself, fails to authenticate the client device;

receiving the first authentication credential and the second authentication credential from the client device in a third communication session that is different from the second communication session;

determining that the first authentication credential and the second authentication credential are linked; and

based on the determination that the first authentication credential and the second authentication credential are linked, enabling the second authentication credential to be used as a mechanism in authenticating the client device, wherein enabling the second authentication credential comprises setting the status indicator to indicate that the second authentication credential is active, wherein the second authentication credential, once identified as enabled by setting the status indicator to indicate that the second authentication credential is active, authenticates the client device without also presenting the first authentication credential.

2. The method of claim 1 wherein:

providing a first authentication credential to the client device comprises providing, to the client device, a first authentication credential that includes an identifier that uniquely identifies the first authentication credential;

providing a second authentication credential that is linked to the first authentication credential to the client device comprises providing, to the client device, a second authentication credential that includes a parent authentication credential identifier that indicates that the second authentication credential is linked to the first authentication credential by referencing the identifier that uniquely identifies the first authentication credential; and

determining that the first authentication credential and the second authentication credential are linked comprises determining that the second authentication credential includes the parent authentication credential identifier that references the identifier that uniquely identifies the first authentication credential.

3. The method of claim 2 wherein providing, to the client device, a second authentication credential that includes a parent authentication credential identifier that references the identifier that uniquely identifies the first authentication credential comprises providing, to the client device, a second authentication credential identifier that includes a parent authentication credential identifier that includes the identifier that uniquely identifies the first authentication credential.

4. The method of claim 1 wherein:

providing a second authentication credential that is linked to the first authentication credential to the client device comprises providing, to the client device, a second authentication credential that includes an identifier that uniquely identifies the second authentication credential;

providing a first authentication credential to the client device comprises providing, to the client device, a first authentication credential that includes a parent authentication credential identifier that indicates that the second authentication credential is linked to the first authentication credential by referencing the identifier that uniquely identifies the second authentication credential; and

determining that the first authentication credential and the second authentication credential are linked comprises determining that the first authentication credential includes the parent authentication credential identifier that references the identifier that uniquely identifies the second authentication credential.

5. The method of claim 1 further comprising providing, over the third communication session, the second authentication credential that is enabled for use in authenticating the client device.

6. The method of claim 1 wherein:

the first communication session comprises a secure communication session, and

the third communication session comprises a secure communication session.

7. The method of claim 5 wherein the second communication session comprises a communication session that differs in security from the first and third communication sessions.

8. The method of claim 1 wherein enabling the second authentication credential for use in authentication of the client device comprises enabling the second authentication credential for use in authentication of the client device for a predetermined amount of time.

9. The method of claim 1 wherein the first authentication credential comprises a ticket-granting ticket able to be used in only a single communication session.

10. The method of claim 1 wherein the second authentication credential comprises a ticket-granting ticket able to be used in only a single communication session.

11. An apparatus for facilitating authenticating of a client device, the apparatus comprising:

at least one processor; and

memory storing instructions that, when executed by the at least one processor, cause the apparatus to perform:

providing, to a client device in a first communication session, a first authentication credential;

providing, to the client device in a second communication session that is different from the first communication session, a second authentication credential, the second authentication credential being linked to the first authentication credential, wherein the second authentication credential includes a status indicator that indicates that the second authentication credential is inactive, and wherein the second authentication credential, including the status indicator that indicates that the second authentication credential is inactive, by itself, fails to authenticate the client device;

receiving the first authentication credential and the second authentication credential from the client device in a third communication session that is different from the second communication session;

determining that the first authentication credential and the second authentication credential are linked; and

based on the determination that the first authentication credential and the second authentication credential are linked, enabling the second authentication credential to be used as a mechanism in authenticating the client device, wherein enabling the second authentication credential comprises setting the status indicator to indicate that the second authentication credential is active, wherein the second authentication credential, once identified as enabled by setting the status indicator to indicate that the second authentication credential is active, authenticates the client device without also presenting the first authentication credential.

12. The apparatus of claim 11 wherein:

providing a first authentication credential to the client device comprises providing, to the client device, a first authentication credential that includes an identifier that uniquely identifies the first authentication credential;

providing a second authentication credential that is linked to the first authentication credential to the client device comprises providing, to the client device, a second authentication credential that includes a parent authentication credential identifier that indicates that the second authentication credential is linked to the first authentication credential by referencing the identifier that uniquely identifies the first authentication credential; and

determining that the first authentication credential and the second authentication credential are linked comprises determining that the second authentication credential includes the parent authentication credential identifier that references the identifier that uniquely identifies the first authentication credential.

13. The apparatus of claim 12 wherein providing, to the client device, a second authentication credential that includes a parent authentication credential identifier that references the identifier that uniquely identifies the first authentication credential comprises providing, to the client device, a second authentication credential identifier that includes a parent authentication credential identifier that includes the identifier that uniquely identifies the first authentication credential.

14. The apparatus of claim 11 wherein:

providing a second authentication credential that is linked to the first authentication credential to the client device comprises providing, to the client device, a second authentication credential that includes an identifier that uniquely identifies the second authentication credential;

providing a first authentication credential to the client device comprises providing, to the client device, a first authentication credential that includes a parent authentication credential identifier that indicates that the second authentication credential is linked to the first authentication credential by referencing the identifier that uniquely identifies the second authentication credential; and

determining that the first authentication credential and the second authentication credential are linked comprises determining that the first authentication credential includes the parent authentication credential identifier that references the identifier that uniquely identifies the second authentication credential.

15. The apparatus of claim 11 wherein at least one of the first authentication credential and the second authentication credential comprises a ticket-granting ticket able to be used in only a single communication session.

16. At least one non-transitory computer-readable medium storing computer-executable instructions that when executed by at least one processor cause the at least one processor to perform:

providing, to a client device in a first communication session, a first authentication credential;

providing, to the client device in a second communication session that is different from the first communication session, a second authentication credential, the second authentication credential being linked to the first authentication credential, wherein the second authentication credential includes a status indicator that indicates that the second authentication credential is inactive, and wherein the second authentication credential, including the status indicator that indicates that the second authentication credential is inactive, by itself, fails to authenticate the client device;

receiving the first authentication credential and the second authentication credential from the client device in a third communication session that is different from the second communication session;

determining that the first authentication credential and the second authentication credential are linked; and

based on the determination that the first authentication credential and the second authentication credential are linked, enabling the second authentication credential to be used as a mechanism in authenticating the client device, wherein enabling the second authentication credential comprises setting the status indicator to indicate that the second authentication credential is active, wherein the second authentication credential, once identified as enabled by setting the status indicator to indicate that the second authentication credential is active, authenticates the client device without also presenting the first authentication credential.

17. The at least one non-transitory computer-readable medium of claim 16 wherein:

providing a first authentication credential to the client device comprises providing, to the client device, a first authentication credential that includes an identifier that uniquely identifies the first authentication credential;

providing a second authentication credential that is linked to the first authentication credential to the client device comprises providing, to the client device, a second authentication credential that includes a parent authentication credential identifier that indicates that the second authentication credential is linked to the first authentication credential by referencing the identifier that uniquely identifies the first authentication credential; and

determining that the first authentication credential and the second authentication credential are linked comprises determining that the second authentication credential includes the parent authentication credential identifier that references the identifier that uniquely identifies the first authentication credential.

18. The at least one non-transitory computer-readable medium of claim 17 wherein providing, to the client device, a second authentication credential that includes a parent authentication credential identifier that references the identifier that uniquely identifies the first authentication credential comprises providing, to the client device, a second authentication credential identifier that includes a parent authentication credential identifier that includes the identifier that uniquely identifies the first authentication credential.

19. The at least one non-transitory computer-readable medium of claim 16 wherein:

providing a second authentication credential that is linked to the first authentication credential to the client device comprises providing, to the client device, a second authentication credential that includes an identifier that uniquely identifies the second authentication credential;

providing a first authentication credential to the client device comprises providing, to the client device, a first authentication credential that includes a parent authentication credential identifier that indicates that the second authentication credential is linked to the first authentication credential by referencing the identifier that uniquely identifies the second authentication credential; and

determining that the first authentication credential and the second authentication credential are linked comprises determining that the first authentication credential includes the parent authentication credential identifier that references the identifier that uniquely identifies the second authentication credential.

20. The at least one non-transitory computer-readable medium of claim 16 wherein at least one of the first authentication credential and the second authentication credential comprises a ticket-granting ticket able to be used in only a single communication session.

Assignments (13)
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2012
From: AOL, INC.; RELEGANCE CORPORATION
To: CITRIX SYSTEMS, INC.
Reel/Frame 028391/0832 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 16, 2010
From: BANK OF AMERICA, N A
To: AOL INC; AOL ADVERTISING INC; GOING INC; LIGHTNINGCAST LLC; MAPQUEST, INC; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC; TACODA LLC; TRUVEO, INC; YEDDA, INC
Reel/Frame 025323/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2009
From: AOL LLC
To: AOL INC.
Reel/Frame 023723/0645 →
SECURITY AGREEMENT Recorded Dec 14, 2009
From: AOL INC.; AOL ADVERTISING INC.; BEBO, INC.; ICQ LLC; GOING, INC.; LIGHTNINGCAST LLC; MAPQUEST, INC.; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC.; TACODA LLC; TRUVEO, INC.; YEDDA, INC.
To: BANK OF AMERICAN, N.A. AS COLLATERAL AGENT
Reel/Frame 023649/0061 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2009
From: CHENG, YAN; ZHANG, ZHIHONG
To: AMERICA ONLINE, INC.
Reel/Frame 023343/0811 →
CHANGE OF NAME Recorded Oct 8, 2009
From: AMERICA ONLINE, INC.
To: AOL LLC
Reel/Frame 023343/0930 →