IP Library Granted Patent US 9,838,727
Granted Patent B1
US 9,838,727 · App. 13/031,105 · Granted Dec 5, 2017

Method and system for discovering an identity provider

Inventors: Kapil Chaudhry (Cerritos, CA); David N. Schlacht (Los Angeles, CA)
Assignee: The DIRECTV Group, Inc.
H04N21/25816
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,727
App. No.
13/031,105
Granted
Dec 5, 2017
Kind
B1
Abstract

A method and system includes an external service provider that receives a request for restricted content, forms, at the external service provider, a redirection request based on the request for restricted content, an external service provider identifier, and a return response location identifier. The system also includes a discovery service that receives the redirection request from the external service provider and parses the redirection request to obtain an identity provider location identifier and the external service provider identifier when a common domain cookie exists in the redirection request. The discovery service generates a response based on the return response location identifier wherein the response comprises the identity provider location identifier. The external service provider receives the response, generates an authentication request and communicates the authentication request to the identity provider based on the identity provider location identifier.

Claims (32)

1. A method comprising:

registering an external service provider with a discovery service and storing a token for the external service provider in the discovery service, said discovery service associated with a primary service provider;

forming, at a user device, a common domain cookie comprising a list of identity location identifiers;

receiving a request for restricted content at an external service provider from the user device, comprising the common domain cookie, said request for restricted content comprising a location identifier for the restricted content;

forming, at the external service provider, a redirection request based on the request for restricted content, an external service provider identifier, and a return response location identifier;

communicating the redirection request from the external service provider to the discovery service with the common domain cookie;

determining, at the discovery service, whether the redirection request originates from the external service provider that is registered based on the token;

when the redirection request originates from the external service provider that is registered, parsing the redirection request at the discovery service to obtain a previously used identity provider location identifier from the list of identity location identifiers within the common domain cookie and the external service provider identifier;

generating a response at the discovery service with the previously used identity provider location identifier;

communicating the response to the external service provider based on the return response location identifier wherein the response comprises the identity provider location identifier;

generating an authentication request at the external service provider with the previously used identity provider location identifier;

communicating the authentication request to the identity provider based on the previously used identity provider location identifier;

authenticating the user device at the identity provider; and

allowing access to the restricted content based on authenticating.

2. A method as recited in claim 1 wherein receiving the request comprises receiving the request for restricted content at the external service provider from a mobile user device.

3. A method as recited in claim 1 wherein parsing the redirection request at the discovery service to obtain the identity provider location identifier comprises parsing the redirection request at the discovery service to obtain a previously used identity provider location identifier.

4. A method as recited in claim 1 wherein the previously used identity provider location comprises a last used identity provider identifier.

5. A method as recited in claim 1 further comprising forming a common domain cookie that includes a last used identity provider identifier at a user device.

6. A method as recited in claim 1 further comprising communicating a discovery service location to the external service provider.

7. A method as recited in claim 1 further comprising prior to receiving a request, registering the service provider identifier with the discovery service to form a registered service provider identifier.

8. A method as recited in claim 7 further comprising when the service provider identifier is a preregistered service provider identifier, performing the step of parsing.

9. A system comprising:

a discovery service registering an external service provider and storing a token for the external service provider;

a user device forming a common domain cookie comprising a list of identity location identifiers;

said external service provider receiving a request for restricted content from the user device, forming a redirection request based on the request for restricted content, an external service provider identifier and, a return response location identifier; and

said discovery service receiving the redirection request from the external service provider with the common domain cookie, when the redirection request originates from the external service provider that is registered, the discovery service parsing the redirection request to obtain a previously used identity provider location identifier from the list of identity location identifiers within the common domain cookie and the external service provider identifier, said discovery service generating a response based on the return response location identifier with the previously used identity provider location identifier;

said external service provider receiving the response, generating an authentication request with the previously used identity provider location identifier and communicating the authentication request to the identity provider based on the identity provider location identifier;

said identity provider authenticating the user device; and

said user device accessing the restricted content based on authenticating.

10. A system as recited in claim 9 wherein the user device comprises a mobile user device.

11. A system as recited in claim 9 wherein the common domain cookie comprises a last used identity provider identifier.

12. A system as recited in claim 9 wherein the discovery service parses the request when the external service provider is a preregistered service provider.

Assignments (6)
SUCCESSION OF AGENCY IN PATENT SECURITY INTERESTS Recorded Oct 3, 2025
From: UBS AG, STAMFORD BRANCH (AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH)
To: UBS AG, STAMFORD BRANCH
Reel/Frame 072994/0001 →
SECURITY AGREEMENT Recorded Jan 25, 2024
From: DIRECTV, LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 066371/0690 →
SECURITY AGREEMENT Recorded Aug 5, 2021
From: DIRECTV, LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A. AS COLLATERAL AGENT
Reel/Frame 058220/0531 →
SECURITY AGREEMENT Recorded Aug 3, 2021
From: DIRECTV, LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 057695/0084 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2021
From: THE DIRECTV GROUP, INC.
To: DIRECTV, LLC
Reel/Frame 057043/0109 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2011
From: CHAUDHRY, KAPIL; SCHLACHT, DAVID N.
To: THE DIRECTV GROUP, INC.
Reel/Frame 026681/0641 →