IP Library Granted Patent US 9,525,679
Granted Patent B2
US 9,525,679 · App. 15/001,134 · Granted Dec 20, 2016

Sending session tokens through passive clients

Inventors: Seshadri Mani (Redmond, WA); William Taylor (Redmond, WA); Haytham Abuel-Futuh (Redmond, WA); Titus Miron (Seattle, WA); Murli Satagopan (Kirkland, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/0807H04L9/3213H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,525,679
App. No.
15/001,134
Granted
Dec 20, 2016
Kind
B2
Abstract

A session token can be requested to be sent to a first computing service from a second computing service, and a first computing service can receive the requested session token from the second computing service. The first computing service can send a message that includes the session token through a passive client to the second computing service. The second computing service can receive the message that includes the session token from the passive client, and the second computing service can verify that the message is valid. This verification of the validity of the message can include verifying that the session token received back from the passive client matches the session token the second computing service sent to the first computing service.

Claims (41)

1. A computer-implemented method, comprising:

requesting a proof token to be sent to a first computing service from a second computing service;

the first computing service receiving a proof key with the requested proof token from the second computing service; and

the first computing service sending a message comprising the proof token through a passive client to the second computing service.

2. The method of claim 1 , wherein the method further comprises the first computing service signing a set of additional data with the proof key and including the set of additional data in the message comprising the proof token.

3. The method of claim 2 , wherein the set of additional data is a first set of additional data, the message comprising the proof token is a first message, and the method further comprises the first computing service signing a second set of additional data with the proof key, including the second set of additional data in a second message comprising the proof token, and sending the second message through a passive client to the second computing service.

4. The method of claim 2 , wherein the set of additional data comprises a profile identity token indicating that an identified profile associated with the passive client is authorized to use the first computing service.

5. The method of claim 1 , further comprising:

authorizing a first profile to use the first computing service; and

the first computing service receiving a request to use the second computing service, the request to use the second computing service being received from the passive client, the passive client being associated with the first profile, and the first computing service requesting the proof token from the second computing service being done in response to the first computing service receiving the request to use the second computing service.

6. The method of claim 5 , wherein the first computing service authorizing the first profile to use the first computing service comprises the first computing service using an identity providing service that is separate from the first computing service to authenticate the first profile.

7. The method of claim 1 , wherein the passive client is remote from the first computing service and from the second computing service.

8. The method of claim 1 , wherein the passive client is a browser client.

9. The method of claim 1 , wherein the method is performed at least in part by hardware logic.

10. A computer system comprising:

at least one processor; and

memory comprising instructions stored thereon that when executed by at least one processor cause at least one processor to perform acts comprising:

requesting a proof token to be sent to a first computing service from a second computing service;

the first computing service receiving a proof key with the requested proof token from the second computing service; and

the first computing service sending a message comprising the proof token through a passive client to the second computing service.

11. The computer system of claim 10 , wherein the acts further comprise the first computing service signing a set of additional data with the proof key and including the set of additional data in the message comprising the proof token.

12. The computer system of claim 11 , wherein the set of additional data is a first set of additional data, the message comprising the proof token is a first message, and the acts further comprise the first computing service signing a second set of additional data with the proof key, including the second set of additional data in a second message comprising the proof token, and sending the second message through a passive client to the second computing service.

13. The computer system of claim 11 , wherein the set of additional data comprises a profile identity token indicating that an identified profile associated with the passive client is authorized to use the first computing service.

14. The computer system of claim 10 , wherein the acts further comprise:

authorizing a first profile to use the first computing service; and

the first computing service receiving a request to use the second computing service, the request to use the second computing service being received from the passive client, the passive client being associated with the first profile, and the first computing service requesting the proof token from the second computing service being done in response to the first computing service receiving the request to use the second computing service.

15. The computer system of claim 14 , wherein the first computing service authorizing the first profile to use the first computing service comprises the first computing service using an identity providing service that is separate from the first computing service to authenticate the first profile.

16. The computer system of claim 10 , wherein the passive client is remote from the first computing service and from the second computing service.

17. The computer system of claim 10 , wherein the passive client is a browser client.

18. A computer system comprising:

at least one processor; and

memory comprising instructions stored thereon that when executed by at least one processor cause at least one processor to perform acts comprising:

a first computing service requesting a proof token from a second computing service;

the first computing service receiving the requested proof token and a proof key from the second computing service, the proof token being opaque to the first computing service;

the first computing service signing a set of additional data with the proof key, the set of additional data comprising a profile identity token indicating that an identified profile associated with a passive browser client is authorized to use the first computing service;

the first computing service including the signed set of additional data and the proof token in a message; and

the first computing service sending the message over a computer network and through the passive browser client to the second computing service, the sending of the message through the passive browser client comprising the first computing service identifying the second computing service to the passive browser and instructing the passive browser to send the message to the second computing service.

19. The computer system of claim 18 , wherein the set of additional data is a first set of additional data, the message comprising the proof token is a first message, and the acts further comprise the first computing service signing a second set of additional data with the proof key, including the second set of additional data in a second message comprising the proof token, and sending the second message through a passive client to the second computing service.

20. The computer system of claim 18 , wherein the acts further comprise:

authorizing a first profile to use the first computing service; and

the first computing service receiving a request to use the second computing service, the request to use the second computing service being received from the passive client, the passive client being associated with the first profile, and the first computing service requesting the proof token from the second computing service being done in response to the first computing service receiving the request to use the second computing service.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2016
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 037527/0430 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2016
From: MANI, SESHADRI; TAYLOR, WILLIAM DAVID; ABUEL-FUTUH, HAYTHAM; MIRON, TITUS C.; SATAGOPAN, MURLI D.
To: MICROSOFT CORPORATION
Reel/Frame 037562/0370 →
Continuity (3)
Division 14016237 · Sep 3, 2013
Provisional Application 61835538 · Jun 15, 2013
Related Publication 20160134617A1 · May 12, 2016