IP Library Granted Patent US 9,369,457
Granted Patent B2
US 9,369,457 · App. 14/316,657 · Granted Jun 14, 2016

Mobile multifactor single-sign-on authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,369,457
App. No.
14/316,657
Granted
Jun 14, 2016
Kind
B2
Abstract

Features are disclosed for authentication of mobile device applications using a native, independent browser using a single-sign-on system. An authentication module within the mobile application can direct the mobile device's native browser to a URL to initiate authentication with an authentication appliance. The mobile browser can receive and store a browser-accessible token to indicate previous authentication performed by the user. The mobile application can receive from the application appliance and store a client application ID token that may be presented to network services for access. A second mobile device application may direct the same browser to the authentication appliance. The authentication appliance may inspect the persistent browser-accessible token and issue a second client application ID identity to the second application without collecting additional authentication information, or collecting additional authentication information that is different from the first authentication information.

Claims (37)

1. A computer-implemented method for providing single-sign-on (SSO) authentication to a user of a client application on a mobile device, the computer-implemented method comprising:

receiving, from an independent browser on a mobile device, a first request to access a first uniform resource locator (URL) associated with a first non-browser mobile application executing on the mobile device;

authenticating the user interacting with the mobile device at least partly by: receiving first authentication information related to the user from the independent browser, and verifying the first authentication information with an identity database;

identifying a first URL mapping configured to invoke the first non-browser mobile application;

sending, to the independent browser, a browser-based token, the first URL mapping, and a first client application identity for use by the first non-browser mobile application;

receiving, from the independent browser on the mobile device, a second request to access a second uniform resource locator (URL) associated with a second non-browser mobile application executing on the mobile device, wherein the second request comprises the browser-based token;

verifying, with the identity database, non-revocation of the browser-based token;

identifying a second URL mapping configured to invoke the second non-browser mobile application; and

sending, to the independent browser, a second client application identity for use by the second non-browser mobile application and the second URL mapping,

said method performed in its entirety by a computer system that is separate from the mobile device,

wherein the independent browser has not been specifically configured to provide identity information for non-browser mobile applications.

2. The method of claim 1 , wherein the first uniform resource locator (URL) is identical to the second uniform resource locator (URL).

3. The method of claim 1 , wherein the first non-browser mobile application and the second non-browser mobile application are distinct mobile applications.

4. The method of claim 1 , further comprising sending, to the independent browser, a third uniform resource locator (URL) that is associated with a URL mapping for the first mobile application wherein the first URL mapping configured to invoke the first non-browser mobile application comprises a URL registered in the mobile device in association with the first non-browser mobile application.

5. The method of claim 1 , wherein the first client application identity comprises one of an encrypted portion of a URL query string parameter.

6. The method of claim 1 , wherein the first authentication information comprises a username, password, and one of: a portion of an SMS message, a knowledge based answer, a static pin, or a USB key.

7. The method of claim 1 , further comprising receiving, from the independent browser, second authentication information that is different than the first authentication information.

8. The method of claim 1 , further comprising sending, to the independent browser, a list of uniform resource locators for use by the first non-browser mobile application configured to trigger logout of one or more logged-in non-browser mobile applications.

9. A non-transitory computer storage medium which stores a program comprising executable code that directs a computing device to perform a process that provides single-sign-on (SSO) authentication to a user of a mobile device, comprising:

receiving, from an independent browser on a mobile device, a first request to access a first uniform resource locator (URL) associated with a first non-browser mobile application executing on a mobile device;

authenticating the user interacting with the mobile device by:

receiving first authentication information related to the user from the independent browser,

verifying the first authentication information with an identity database;

identifying a first URL mapping configured to invoke the first non-browser mobile application;

sending, to the independent browser, a browser-based token, the first URL mapping, and a first client application identity for use by the first non-browser mobile application;

receiving, from the independent browser on the mobile device, a second request to access a second uniform resource locator (URL) associated with a second non-browser mobile application executing on the mobile device, wherein the second request comprises the browser-based token;

verifying, with the identity database, non-revocation of the browser-based token;

identifying a second URL mapping configured to invoke the first non-browser mobile application;

and

sending, to the independent browser, a second client application identity for use by the second non-browser mobile application and the second URL mapping,

wherein the independent browser has not been specifically configured to provide identity information for non-browser mobile applications.

10. The non-transitory computer storage medium of claim 9 , wherein the first uniform resource locator (URL) is identical to the second uniform resource locator (URL).

11. The non-transitory computer storage medium of claim 9 , wherein the first non-browser mobile application and the second non-browser mobile application are distinct non-browser mobile applications.

12. The non-transitory computer storage medium of claim 9 , which stores the program comprising executable code that directs the computing device to perform the process further comprising sending, to the independent browser, wherein the first URL mapping configured to invoke the first non-browser mobile application comprises a URL registered in the mobile device in association with the first non-browser mobile application a third uniform resource locator (URL) that is associated with a URL mapping for the first mobile application.

13. The non-transitory computer storage medium of claim 9 , wherein the first client application identity comprises one of: a userid sent as a URL query string parameter, a userid sent as an encrypted URL query string parameter, a cookie, or an encrypted cookie.

14. The non-transitory computer storage medium of claim 9 , wherein the first authentication information comprises a username, password, and one of: a portion of an SMS message, a knowledge based answer, a static pin, or a USB key.

15. The non-transitory computer storage medium of claim 9 , which stores the program comprising executable code that directs the computing device to perform the process further comprising sending, to the independent browser, a plurality of distinct uniform resource locators, each uniform resource locator configured to trigger logout of a distinct logged-in non-browser mobile applications.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0011 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 070086/0158 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: SECUREAUTH CORPORATION
Reel/Frame 068288/0856 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: SECUREAUTH CORPORATION
Reel/Frame 068251/0496 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
SECURITY INTEREST Recorded Oct 27, 2021
From: SECUREAUTH CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 057937/0732 →
SECURITY INTEREST Recorded Jan 3, 2018
From: SECUREAUTH CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 044522/0031 →
RELEASE OF SECURITY INTEREST Recorded Dec 18, 2017
From: WESTERN ALLIANCE BANK
To: SECUREAUTH CORPORATION
Reel/Frame 044899/0635 →
SECURITY INTEREST Recorded Aug 8, 2016
From: SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 039368/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2014
From: GRAJEK, GARRET FLORIAN; LO, JEFF CHIWAI; PHILLIPS, ROBERT JASON; TUNG, SHU JEN
To: SECUREAUTH CORPORATION
Reel/Frame 034497/0687 →