IP Library Granted Patent US 8,453,224
Granted Patent B2
US 8,453,224 · App. 12/604,952 · Granted May 28, 2013

Single sign-on authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,453,224
App. No.
12/604,952
Granted
May 28, 2013
Kind
B2
Abstract

Apparatus, systems, and methods may operate to receive a request from a node to provide access to a web site, to provide site authenticity information associated with the web site to the node, and to receive single sign-on (SSO) information from the node in response to validation of the site authenticity information by the node, the SSO information enabling the node to automatically log in to the web site. Additional activities include receiving site authenticity information from a node associated with a web site, and automatically transmitting SSO information to the node responsive to validating the site authenticity information. Additional apparatus, systems, and methods are disclosed.

Claims (43)

1. A system, comprising:

a reception module in a first node comprising a physical machine, the reception module to receive a request from a second node to provide access to a web site; and

a transmission module to provide site authenticity information associated with the web site to the second node, wherein the reception module is to receive single sign-on information from the second node in response to validation of the site authenticity information by the second node, the single sign-on information enabling the second node to automatically log in to the web site, wherein at least one of the transmission module or the reception module is configured to record an event associated with at least one of transmitting of the single sign-on information, capturing the site authenticity information, failing to match potentially false site authenticity information with a stored version of the site authenticity information, recording new site information as the potentially false site authenticity information, or preventing transmission of the single sign-on information in response to detecting the potentially false site authenticity information.

2. The system of claim 1 , wherein the transmission module is to transmit display information comprising a username log-in field and/or a password log-in field, and secure sockets layer security certificate availability.

3. The system of claim 1 , further comprising:

a single sign-on client operating as an intermediary node between the first node and the second node, the single sign-on client to capture the site authenticity information for storage and recall, wherein the recall of the site authenticity information is used during subsequent single sign-on sessions to validate authenticity of a subsequently-accessed web site purporting to be the web site.

4. An apparatus, comprising:

a reception module in a second node comprising a physical machine, the reception module to receive site authenticity information from a first node associated with a web site; and

a transmission module to transmit single sign-on information to the first node responsive to validating the site authenticity information, the single sign-on information enabling automatic log-in to the web site by the second node, wherein at least one of the transmission module or the reception module is configured to record an event associated with at least one of transmitting of the single sign-on information, capturing the site authenticity information, failing to match potentially false site authenticity information with a stored version of the site authenticity information, recording new site information as the potentially false site authenticity information, or preventing transmission of the single sign-on information in response to detecting the potentially false site authenticity information.

5. The apparatus of claim 4 , further comprising:

a third node to store the site authenticity information.

6. The apparatus of claim 4 , wherein the second node is to prevent transmission of the single sign-on information upon detecting a potentially false version of the web site.

7. A processor-implemented method to execute on one or more processors that perform the method, comprising:

receiving a request from a node to provide access to a web site;

providing site authenticity information associated with the web site to the node;

receiving single sign-on information from the node in response to validation of the site authenticity information by the node, the single sign-on information enabling the node to automatically log in to the web site; and

recording an event associated with at least one of transmitting of the single sign-on information, capturing the site authenticity information, failing to match potentially false site authenticity information with a stored version of the site authenticity information, recording new site information as the potentially false site authenticity information, or preventing transmission of the single sign-on information in response to detecting the potentially false site authenticity information.

8. The method of claim 7 , wherein the providing further comprises:

providing the site authenticity information comprising a combination of information included in web site content associated with the web site, and information included in a security certificate associated with the web site.

9. The method of claim 8 , wherein the information included in the security certificate comprises at least one of:

time information, organization information, or location information.

10. The method of claim 7 , further comprising:

receiving a request for the site authenticity information from the node.

11. The method of claim 7 , further comprising:

transmitting information to display the web site, along with an image of a secure sockets layer security certificate associated with the site authenticity information.

12. The method of claim 7 , further comprising:

transmitting display information associated with at least a username log-in field or a password log-in field to indicate that single sign-on access to the web site is available.

13. A processor-implemented method to execute on one or more processors that perform the method, comprising:

receiving site authenticity information from a node associated with a web site; and automatically transmitting single sign-on information to the node responsive to validating the site authenticity information, the single sign-on information enabling automatic log-in to the web site; and

recording an event associated with at least one of transmitting of the single sign-on information, capturing the site authenticity information, failing to match potentially false site authenticity information with a stored version of the site authenticity information, recording new site information as the potentially false site authenticity information, or preventing transmission of the single sign-on information in response to detecting the potentially false site authenticity information.

14. The method of claim 13 , further comprising:

recording the site authenticity information to enable single sign-on access to the web site during subsequent access attempts.

15. The method of claim 14 , further comprising:

refraining from the recording if the site authenticity information comprises an invalid security certificate.

16. The method of claim 13 , wherein the receiving further comprises:

receiving the site authenticity information by executing a background application that bypasses browser application activity, wherein the browser is used to display the web site.

17. The method of claim 13 , wherein the validating further comprises:

validating the site authenticity information by matching previously-stored security certificate information with some of the site authenticity information.

18. The method of claim 13 , wherein the site authenticity information is stored in a directory service in conjunction with the single sign-on information.

19. The method of claim 13 , further comprising:

subsequently attempting to access the web site;

receiving false site authenticity information that does not match a stored version of the site authenticity information; and

indicating a potential threat posed by a potentially false version of the web site based on the false site authenticity information.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2009
From: MUTT, GIRISH BITMANDI
To: NOVELL, INC.
Reel/Frame 023514/0574 →