IP Library Granted Patent US 9,961,071
Granted Patent B2
US 9,961,071 · App. 15/219,687 · Granted May 1, 2018

Native application single sign-on

Inventors: Richard John Walters (Benson, GB); Simon David Knott (Bristol, GB)
Assignee: Intermedia.net, Inc.
H04L63/0815H04L12/4641H04L63/0272H04L67/02H04L67/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,961,071
App. No.
15/219,687
Granted
May 1, 2018
Kind
B2
Abstract

In an example embodiment, a virtual private network (VPN) connection is established between a client device and an authentication service. Then a request is received from a third-party application on the client device, with the request being for a third-party service. A log-in page is requested from the third-party service, with the log-in page including one or more log-in fields usable to enter credential information. The log-in page is then modified to hide the one or more log-in fields. Credentials corresponding to a user of the client device and also corresponding to the third-party service are then obtained. The modified log-in page is sent to the client device via the VPN connection. A log-in submission is received from the third-party application. The credentials corresponding to the user and to the third-party service are sent to the third-party service to log-in the user to the third-party service.

Claims (49)

1. A method of providing single sign-on, comprising:

establishing a virtual private network (VPN) connection between a client device and an authentication service;

receiving, at the authentication service, via the VPN connection, a request from a third-party application on the client device, the request for a third-party service, the request also including first credentials entered by a user;

obtaining, at the authentication service, a log-in web page corresponding to the third-party service;

scanning the log-in page to determine a credential type associated with the log-in web page;

obtaining second credentials, of the determined credential type, corresponding to a user of the client device and also uniquely corresponding to the third-party service;

submitting, to the third-party service, the second credentials by filling in the log-in web page with the second credentials.

2. The method of claim 1 , further comprising:

detecting that the user has multiple possible credentials for the third-party service;

sending a notification to an authentication client application on the client device, the notification including the multiple possible credentials and designed to trigger the authentication client application to notify the user of the multiple possible credentials and obtain a credential choice from the user;

receiving the credential choice from the authentication client application; and

wherein the submitting the second credentials comprises submitting second credentials corresponding to the selection.

3. The method of claim 2 , wherein the sending a notification comprises sending a push notification.

4. A system comprising:

an authentication client application operating on a client device; and

an authentication service comprising one or more processors and configured to:

establish a virtual private network (VPN) connection between a client device and an authentication service;

receive at the authentication service, via the VPN connection, a request from a third-party application on the client device, the request for a third-party service, the request also including first credentials entered by a user;

obtain, at the authentication service, a log-in web page corresponding to the third-party service;

scan the log-in page to determine a credential type associated with the log-in web page;

obtain second credentials, of the determined credential type, corresponding to a user of the client device and also uniquely corresponding to the third-party service;

detect that the user has multiple possible credentials for the third-party service;

send a notification to the authentication client application on the client device, the notification including the multiple possible credentials and designed to trigger the authentication client application to notify the user of the multiple possible credentials and obtain a credential choice from the user;

receive the credential choice from the authentication client application; and

submit the second credentials corresponding to the selection to the third-party service to log-in the user to the third-party service by filling in the log-in web page with the credential choices.

5. The system of claim 4 , wherein the client device is a mobile device.

6. A non-transitory machine-readable storage medium comprising instructions, which when implemented by one or more machines, cause the one or more machines to perform operations comprising:

establishing a virtual private network (VPN) connection between a client device and an authentication service;

receiving, at the authentication service, via the VPN connection, a request from a third-party application on the client device, the request for a third-party service, the request also including first credentials entered by a user;

obtaining, at the authentication service, a log-in web page corresponding to the third-party service;

scanning the log-in page to determine a credential type associated with the log-in web page;

obtaining second credentials, of the determined credential type, corresponding to a user of the client device and also uniquely corresponding to the third-party service;

submitting, to the third-party service, the second credentials by filling in the log-in web page with the second credentials.

7. The non-transitory machine-readable storage medium of claim 6 , wherein the operations further comprise:

detecting that the user has multiple possible credentials for the third-party service;

sending a notification to an authentication client application on the client device, the notification including the multiple possible credentials and designed to trigger the authentication client application to notify the user of the multiple possible credentials and obtain a credential choice from the user;

receiving the credential choice from the authentication client application; and

wherein the submitting the second credentials comprises submitting second credentials corresponding to the selection.

8. The non-transitory machine-readable storage medium of claim 7 , wherein the sending a notification comprises sending a push notification.

9. The method of claim 1 , further comprising modifying a log-in page using the credentials, wherein the modifying the log-in page includes removing code corresponding to the one or more log-in fields from code in the programming code representation of the log-in page.

10. The method of claim 1 , further comprising modifying a log-in page using the credentials, wherein the modifying the log-in page includes inserting code in the programming code representation of the log-in page, the code causing the one or more fields to not be visible to the user when the log-in page is displayed.

11. The method of claim 1 , wherein the receiving a log-in submission comprises receiving dummy credentials; and

wherein the submitting the credentials includes replacing the dummy credentials with the credentials corresponding to the user and to the third-party service.

12. The method of claim 1 , wherein the obtaining credentials comprises obtaining credentials from a data store managed by the authentication service.

13. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise modifying the log-in page includes removing code corresponding to the one or more log-in fields from the log-in page.

14. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise modifying the log-in page includes inserting code in the log-in page, the code causing the one or more fields to not be visible to the user when the log-in page is displayed.

15. The non-transitory machine-readable storage medium of claim 7 , wherein the receiving a log-in submission comprises receiving dummy credentials; and

wherein the submitting the credentials includes replacing the dummy credentials with the credentials corresponding to the user and to the third-party service.

16. The non-transitory machine-readable storage medium of claim 7 , wherein the obtaining credentials comprises obtaining credentials from a data store managed by the authentication service.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded May 27, 2026
From: INTERMEDIA.NET, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075653/0429 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS, RECORDED AT REEL 014590, FRAME 0192 Recorded Jul 23, 2018
From: SUNTRUST BANK
To: INTERMEDIA.NET, INC.
Reel/Frame 046610/0041 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Jul 23, 2018
From: SUNTRUST BANK
To: ACCESSLINE COMMUNICATIONS CORPORATION; INTERMEDIA.NET, INC.
Reel/Frame 046619/0417 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Feb 1, 2017
From: INTERMEDIA.NET, INC.
To: SUNTRUST BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 041590/0122 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Feb 1, 2017
From: INTERMEDIA.NET, INC.
To: SUNTRUST BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 041590/0158 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2016
From: WALTERS, RICHARD JOHN; KNOTT, SIMON DAVID
To: INTERMEDIA.NET, INC.
Reel/Frame 039406/0467 →
Continuity (2)
Continuation 14556391 · Dec 1, 2014
Related Publication 20160337340A1 · Nov 17, 2016