IP Library Granted Patent US 9,288,195
Granted Patent B2
US 9,288,195 · App. 14/105,932 · Granted Mar 15, 2016

Single sign on with multiple authentication factors

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,288,195
App. No.
14/105,932
Granted
Mar 15, 2016
Kind
B2
Abstract

The authentication of a client to multiple server resources with a single sign-on procedure using multiple factors is disclosed. One contemplated embodiment is a method in which a login session is initiated with the authentication system of a primary one of the multiple server resources. A first set of login credentials is transmitted thereto, and validated. A token is stored on the client indicating that the initial authentication was successful, which is then used to transition to a secondary one of the multiple resources. A second set of login credentials is also transmitted, and access to the secondary one of the multiple resources is granted on the basis of a validated token and second set of login credentials.

Claims (42)

1. A method for authenticating a client to multiple server resources each with a standalone authentication system, the method comprising:

initiating a login session with a first standalone authentication system of a primary one of the multiple server resources;

transmitting a first set of login credentials from the client to the first standalone authentication system of the primary one of the multiple server resources;

validating the client by the first standalone authentication system of the primary one of the multiple server resources based upon the first set of login credentials;

storing on the client a token received from the first standalone authentication system of the primary one of the multiple resources, the token being generated by the first standalone authentication system;

transmitting the token and a second set of login credentials different from the first set of login credentials to a secondary one of the multiple server resources, the second set of login credentials being retrieved from the client, wherein the second set of login credentials is transmitted outside of the token and exists on the client prior to the client transmitting the first set of login credentials to the first standalone authentication system; and

validating the client by a second standalone authentication system of the secondary one of the multiple server resources based upon the transmitted token and the second set of login credentials.

2. The method of claim 1 , wherein the token and the second set of login credentials are transmitted in separate transmissions.

3. The method of claim 1 , wherein the token includes an account identifier associated with a user account on the primary one and the secondary one of the multiple server resources.

4. The method of claim 1 , wherein the second set of login credentials is a digital certificate.

5. The method of claim 4 , wherein the digital certificate is stored on the client.

6. The method of claim 4 , wherein the digital certificate is stored on an external hardware device readable by the client.

7. The method of claim 4 , wherein the digital certificate is associated with a complementary client application of the second standalone authentication system of the secondary one of the multiple server resources.

8. The method of claim 4 , wherein the digital certificate is associated with a client application independent of the second standalone authentication system of the secondary one of the multiple server resources.

9. The method of claim 1 , further comprising:

transmitting the second set of login credentials from the client to the first standalone authentication system of the primary one of the multiple server resources;

wherein validating the client to the primary one of the multiple server resources is further based upon the second set of login credentials.

10. A method for authenticating a client to multiple server resources each with a standalone authentication system, comprising;

receiving a first set of login credentials from the client to a first standalone authentication system of a primary one of the multiple server resources;

validating the client to the primary one of the multiple server resources based upon the first set of login credentials;

transmitting to the client a token generated by the first standalone authentication system of the primary one of the multiple resources in response to a successful validation of the first set of login credentials, the token being generated by the first standalone authentication system;

receiving on a secondary one of the multiple server resources the token and a second set of login credentials different from the first set of login credentials, the second set of login credentials being retrieved from the client, wherein the second set of login credentials is transmitted outside of the token and exists on the client prior to the client transmitting the first set of login credentials to the first standalone authentication system; and

validating the client by a second standalone authentication system of the secondary one of the multiple server resources based upon the received token and the second set of login credentials.

11. The method of claim 10 , wherein the token and the second set of login credentials are received by the secondary one of the multiple server resources through separate transmissions.

12. The method of claim 10 , wherein the token includes an account identifier associated with a user account on the primary one and the secondary one of the multiple server resources.

13. The method of claim 10 , wherein the second set of login credentials is a digital certificate.

14. The method of claim 13 , wherein the digital certificate is stored on the client.

15. The method of claim 13 , wherein the digital certificate is stored on an external hardware device readable by the client.

16. The method of claim 13 , wherein the digital certificate is associated with a complementary client application of the second standalone authentication system of the secondary one of the multiple server resources.

17. The method of claim 13 , wherein the digital certificate is associated with a client application independent of the second standalone authentication system of the secondary one of the multiple server resources.

18. The method of claim 10 , further comprising:

receiving the second set of login credentials on the primary one of the multiple server resources;

wherein:

validating the client to the primary one of the multiple server resources is further based upon the second set of login credentials; and

transmitting the token is in response to a successful validation of the second set of login credentials.

19. An article of manufacture comprising a non-transitory program storage medium readable by a computer, the non-transitory program storage medium tangibly embodying one or more programs of instructions executable by the computer to perform a method for authenticating a client to multiple server resources each with a standalone authentication system, the method comprising;

receiving a first set of login credentials from the client to a first standalone authentication system of a primary one of the multiple server resources;

validating the client to the primary one of the multiple server resources based upon the first set of login credentials;

transmitting to the client a token generated by the first standalone authentication system of the primary one of the multiple resources;

receiving on a secondary one of the multiple server resources the token and a second set of login credentials different from the first set of login credentials, the second set of login credentials being retrieved from the client, wherein the second set of login credentials is transmitted outside of the token and exists on the client prior to the client transmitting the first set of login credentials to the first standalone authentication system; and

validating the client by a second standalone authentication system of the secondary one of the multiple server resources based upon the received token and the second set of login credentials.

20. The article of manufacture of claim 19 , wherein the token and the second set of login credentials are received by the secondary one of the multiple server resources through separate transmissions.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0011 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0158 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: SECUREAUTH CORPORATION
Reel/Frame 068288/0856 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 068251/0496 →
SECURITY INTEREST Recorded Oct 27, 2021
From: SECUREAUTH CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 057937/0732 →
SECURITY INTEREST Recorded Jan 3, 2018
From: SECUREAUTH CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044522/0031 →
RELEASE OF SECURITY INTEREST Recorded Dec 18, 2017
From: WESTERN ALLIANCE BANK
To: SECUREAUTH CORPORATION
Reel/Frame 044899/0635 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2017
From: GRAJEK, GARRET FLORIAN; LO, JEFFREY CHIWAI; WU, TOMMY CHING HSIANG
To: SECUREAUTH CORPORATION
Reel/Frame 043301/0051 →
SECURITY INTEREST Recorded Aug 8, 2016
From: SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 039368/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2015
From: LAMBIASE, MARK
To: SECUREAUTH CORPORATION
Reel/Frame 035430/0219 →