IP Library Granted Patent US 9,485,239
Granted Patent B2
US 9,485,239 · App. 14/334,586 · Granted Nov 1, 2016

Implementing single sign-on across a heterogeneous collection of client/server and web-based applications

Inventors: Aleksey Sanin (Sunnyvale, CA); Christopher Toomey (Cupertino, CA); Alan Keister (Oakton, VA); Andrew L. Wick (McLean, VA); Robert Watkins (Vienna, VA); Xiaopeng Zhang (Oak Hill, VA); Russell Richards (Nokesville, VA); Donald Eaves (Aldie, VA)
Assignee: Citrix Systems, Inc.
H04L63/08G06F21/41G06Q20/3674H04L9/3234H04L9/3271H04L63/0815H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,485,239
App. No.
14/334,586
Granted
Nov 1, 2016
Kind
B2
Abstract

Leveraging an established authenticated session in obtaining authentication to a client application includes receiving a request for access to a client application requiring authentication of a requestor and determining whether there exist characteristics of leverageable authentications corresponding to established sessions having an authenticated state at a time of the determination. When the determination reveals characteristics of at least one leverageable authentication corresponding to an established session, and attempt is made to obtain access for the requestor to the client application based on the at least one leverageable authentication, and the requestor is provided with a notification related to the 1 attempt to obtain access for the requestor to the client application.

Claims (34)

1. A method, comprising:

establishing, based on an authentication credential provided by a user via a first client application, a first authenticated session for a computing device, the first authenticated session being associated with the first client application;

generating a master authentication token and a first authentication token corresponding to the first authentication session;

responsive to an authentication request associated with a second client application, generating, based on the master authentication token and an identification of the second client application, a second authentication token comprising a session identifier different from a session identifier of the first authentication token; and

using the second authentication token to establish a second authenticated session for the computing device, the second authenticated session being associated with the second client application.

2. The method of claim 1 , wherein the computing device comprises a mobile device having a wireless network connection with one or more servers associated with the first client application, and a wireless network connection with one or more servers associated with the second client application.

3. The method of claim 1 , wherein the computing device comprises a mobile phone.

4. The method of claim 1 , wherein the first client application comprises an application executing in a browser application executing on the computing device, and the second client application comprises a different application executing in the browser application.

5. The method of claim 1 , wherein the first client application comprises an application executing in a browser application executing on the computing device, and the second client application comprises a non-browser application executing on the computing device.

6. The method of claim 1 , wherein the first client application comprises a non-browser application executing on the computing device, and the second client application comprises an application executing in a browser application executing on the computing device.

7. The method of claim 1 , wherein the first client application comprises a non-browser application executing on the computing device, and the second client application comprises a different non-browser application executing on the computing device.

8. A system, comprising:

at least one processor; and

a memory storing instructions that when executed by the at least one processor cause the system to:

establish, based on an authentication credential provided by a user via a first client application, a first authenticated session for a computing device, the first authenticated session being associated with the first client application;

generate a master authentication token and a first authentication token corresponding to the first authentication session;

responsive to an authentication request associated with a second client application, generate, based on the master authentication token and an identification of the second client application, a second authentication token comprising a session identifier different from a session identifier of the first authentication token; and

use the second authentication token to establish a second authenticated session for the computing device, the second authenticated session being associated with the second client application.

9. The system of claim 8 , wherein the computing device comprises a mobile phone.

10. The system of claim 8 , wherein the first client application comprises an application executing in a browser application executing on the computing device, and the second client application comprises a different application executing in the browser application.

11. The system of claim 8 , wherein the first client application comprises an application executing in a browser application executing on the computing device, and the second client application comprises a non-browser application executing on the computing device.

12. The system of claim 8 , wherein the first client application comprises a non-browser application executing on the computing device, and the second client application comprises an application executing in a browser application executing on the computing device.

13. The system of claim 8 , wherein the first client application comprises a non-browser application executing on the computing device, and the second client application comprises a different non-browser application executing on the computing device.

14. One or more non-transitory computer-readable media having instructions stored thereon that when executed by one or more computers cause the one or more computers to:

establish, based on an authentication credential provided by a user via a first client application, a first authenticated session for a computing device, the first authenticated session being associated with the first client application;

generate a master authentication token and a first authentication token corresponding to the first authentication session;

responsive to an authentication request associated with a second client application, generate, based on the master authentication token and an identification of the second client application, a second authentication token comprising a session identifier different from a session identifier of the first authentication token; and

use the second authentication token to establish a second authenticated session for the computing device, the second authenticated session being associated with the second client application.

15. The one or more non-transitory computer-readable media of claim 14 , wherein the computing device comprises a mobile device having a wireless network connection with one or more servers associated with the first client application, and a wireless network connection with one or more servers associated with the second client application.

16. The one or more non-transitory computer-readable media of claim 14 , wherein the computing device comprises a mobile phone.

17. The one or more non-transitory computer-readable media of claim 14 , wherein the first client application comprises an application executing in a browser application executing on the computing device, and the second client application comprises a different application executing in the browser application.

18. The one or more non-transitory computer-readable media of claim 14 , wherein the first client application comprises an application executing in a browser application executing on the computing device, and the second client application comprises a non-browser application executing on the computing device.

19. The one or more non-transitory computer-readable media of claim 14 , wherein the first client application comprises a non-browser application executing on the computing device, and the second client application comprises an application executing in a browser application executing on the computing device.

20. The one or more non-transitory computer-readable media of claim 14 , wherein the first client application comprises a non-browser application executing on the computing device, and the second client application comprises a different non-browser application executing on the computing device.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2014
From: AOL INC.
To: CITRIX SYSTEMS, INC.
Reel/Frame 033381/0848 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2014
From: AOL LLC
To: AOL INC.
Reel/Frame 033374/0005 →
CHANGE OF NAME Recorded Jul 22, 2014
From: AMERICA ONLINE, INC.
To: AOL LLC
Reel/Frame 033378/0963 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2014
From: TOOMEY, CHRISTOPHER; WATKINS, ROBERT; SANIN, ALEKSEY; KEISTER, ALAN; WICK, ANDREW L.; EAVES, DONALD; ZHANG, XIAOPENG; RICHARDS, RUSSELL
To: AMERICA ONLINE, INC.
Reel/Frame 033350/0100 →
Continuity (4)
Continuation 12390110 · Feb 20, 2009
Continuation 10424995 · Apr 29, 2003
Provisional Application 60375821 · Apr 29, 2002
Related Publication 20140325621A1 · Oct 30, 2014