IP Library Granted Patent US 10,587,603
Granted Patent B2
US 10,587,603 · App. 15/240,962 · Granted Mar 10, 2020

Zero sign-on using a web browser

Inventors: Anil Lingamallu (Bellevue, WA); Nate Yocom (Bellevue, WA); Paul Moore (Bellevue, WA); Fei Chen (Bellevue, WA)
Assignee: IDAPTIVE, LLC
H04L63/0823G06F21/33G06F21/44H04L63/083H04L63/0815H04L63/0861H04L67/02G06F2221/2103H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,587,603
App. No.
15/240,962
Filed
Aug 18, 2016
Granted
Mar 10, 2020
Kind
B2
Art Unit
2497
USPC
726/7
Abstract

Method for enabling zero sign-on (ZSO) through a standard web browser. The device running the browser is first enrolled with a web service using an installed enrollment agent on the device which authenticates a user of the device. After authentication, the enrollment agent stores a device profile that includes a user certificate for the user and an authority certificate issued by said web service. The device profile is stored at a device location accessible by each of the web browsers used by said device. The enrollment agent configures each of the web browsers on the device to respond correctly to ZSO certificate challenges from the web service. Once enrolled, the device's web browsers can respond correctly to a ZSO Uniform Resource Locator (URL) certificate challenge received from the web service. After a successful response to the challenge, the browser is granted a secure socket layer (SSL) connection.

Claims (37)

1. Method for enabling zero sign-on (ZSO) through a standard web browser comprising:

enrolling a device which uses at least one standard web browser with a web service by:

authenticating a user of said device using an enrollment service of said web service configured to receive from said device a request for authentication;

said enrollment service sending a request for user credentials to an enrollment agent installed on said device;

said enrollment service receiving from said enrollment agent, user credentials obtained from the user;

said enrollment service authenticating the user with said web service using said obtained user credentials;

said enrollment service downloading to said enrollment agent, a device profile that contains a user certificate for the user with an accompanying authority certificate issued by said web service, said enrollment agent for storing the user and authority certificates to a predetermined location on the device, and configuring each of said at least one standard web browsers on said device to respond correctly to ZSO Uniform Resource Locator (URL) certificate challenges from said web service, wherein said configuring comprises adding a policy setting which enables auto selecting of URL certificates that contain a ZSO URL, and the user certificate and authority certificate stored in a keychain to present when connecting to the ZSO URL returns a challenge requesting a certificate.

2. The method defined by claim 1 wherein said web service is a device management service.

3. The method defined by claim 1 wherein said web service downloads said device profile to said enrollment agent for storing said user and authority certificates to a predetermined location on said device.

4. The method defined by claim 1 wherein said web service downloads said device profile to a device management agent for storing said user and authority certificates to a predetermined location on said device.

5. The method defined by claim 1 wherein authentication further comprises said enrollment service requiring multi-factor authentication, and said web service sends to said enrollment agent a request for prompting said user to supply additional information including one of a fingerprint swipe and an externally-generated token.

6. Method for enabling zero sign-on (ZSO) using a standard web browser comprising:

enrolling a device which uses at least one standard web browser with a web service by:

an installed enrollment agent on said device sending a request to said web service to authenticate a user of said device;

said installed enrollment agent receiving from an enrollment service of said web service a request for user credentials;

said installed enrollment agent providing said requested user credentials to said enrollment service;

after an authentication performed by said web service, said installed enrollment agent receiving from said web service a device profile including a user certificate for the user and an authority certificate issued by said web service;

said device storing said user certificate and authority certificate at a device location accessible by each of said at least one standard web browsers;

said installed enrollment agent configuring each of said at least one standard web browsers to respond correctly to a ZSO Uniform Resource Locator (URL) certificate challenge received from said web service, wherein said configuring comprises adding a policy setting which enables auto selecting of URL certificates that contain a ZSO URL, and the user certificate and authority certificate stored in a keychain to present when connecting to the ZSO URL returns a challenge requesting a certificate.

7. The method defined by claim 6 wherein said web service is a device management service.

8. The method defined by claim 6 wherein said policy setting is named AutoSelectCertificateForUrls.

9. The method defined by claim 6 wherein said configuring each of said at least one standard web browsers comprises storing the user certificate and authority certificate in a predetermined location for subsequent accessing by each of said at least one standard web browsers.

10. The method defined by claim 6 wherein said configuring each of said at least one standard web browsers comprises using a keychain application program interface (API) to set a certificate preference that ties a ZSO URL to the user certificate.

11. The method defined by claim 6 wherein said authentication comprises:

a) said enrollment agent contacting the web service's enrollment service to authenticate the user, said enrollment service for requesting user credentials from the enrollment agent;

b) said enrollment agent prompting the user to provide predetermined credentials to the enrollment agent;

c) said enrollment agent sending said provided predetermined credentials to said enrollment service.

12. The method defined by claim 11 wherein said predetermined credentials include a username and password.

13. The method defined by claim 11 wherein if the enrollment service requires multi-factor authentication, said enrollment agent prompting said user to supply additional information including one of a fingerprint swipe and an externally-generated token.

14. The method defined by claim 6 wherein said enrolling comprises:

a) said device sending a request to said web service to download said enrollment agent to said device;

b) said web service for processing said request and initiating a download of said enrollment agent;

c) said device downloading the enrollment agent from said web service, and after said downloading is complete, installing the enrollment agent on said device.

15. The method defined by claim 6 wherein said enrolling comprises:

a) said device sending a request to an external source to download said enrollment agent to said device;

b) said external source for processing said request and initiating a download of said enrollment agent

c) said device downloading the enrollment agent from said external source, and after said downloading is complete, installing the enrollment agent on said device.

Assignments (10)
MERGER Recorded Dec 1, 2020
From: IDAPTIVE, LLC
To: CYBERARK SOFTWARE, INC.
Reel/Frame 054500/0240 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2020
From: CYBERARK SOFTWARE, INC.
To: CYBERARK SOFTWARE LTD.
Reel/Frame 054333/0965 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2018
From: CENTRIFY CORPORATION
To: APPS & ENDPOINT COMPANY, LLC
Reel/Frame 047759/0071 →
CHANGE OF NAME Recorded Dec 12, 2018
From: APPS & ENDPOINT COMPANY, LLC
To: IDAPTIVE, LLC
Reel/Frame 049010/0738 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2018
From: CENTRIFY CORPORATION
To: IDAPTIVE, LLC
Reel/Frame 047559/0103 →
RELEASE OF SECURITY INTEREST UNDER REEL/FRAME 46081/0609 Recorded Aug 17, 2018
From: GOLUB CAPITAL LLC
To: CENTRIFY CORPORATION
Reel/Frame 046854/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2018
From: LINGAMALLU, ANIL; YOCOM, NATE; MOORE, PAUL; CHEN, FEI
To: CENTRIFY CORPORATION
Reel/Frame 046144/0723 →
RELEASE OF SECURITY INTEREST Recorded May 7, 2018
From: SILICON VALLEY BANK
To: CENTRIFY CORPORATION
Reel/Frame 045730/0364 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 5, 2018
From: CENTRIFY CORPORATION
To: GOLUB CAPITAL LLC, AS AGENT
Reel/Frame 046081/0609 →
SECURITY INTEREST Recorded Jan 27, 2017
From: CENTRIFY CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 041099/0764 →
Continuity (1)
Related Publication 20180054434A1 · Feb 22, 2018
Cited By (1)
US 12,683,767