IP Library Granted Patent US 9,979,715
Granted Patent B2
US 9,979,715 · App. 15/626,997 · Granted May 22, 2018

Aggregator technology without usernames and passwords

Inventors: Nelson A. Cicchitto (San Ramon, CA); Anthony R. T. Simmons (Concord, CA)
Assignee: Avatier Corporation
H04L63/0815G06F21/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,979,715
App. No.
15/626,997
Granted
May 22, 2018
Kind
B2
Abstract

Techniques are described in which to access a user's web applications, the user registers and signs on to an aggregator system using any supported login identity provider username and password. When the user registers for the first time, the system collects additional information to verify the user for a subsequent access to the system. The system also automatically creates a system secret username and secret, highly securely generated password, both of which are unknown and inaccessible to the user. The secret username and password are stored in an lightweight directory access protocol (LDAP) server or database or in a distributed cloud database system. The system also maps the login identity provider user name to the secret user name and password for subsequent usage.

Claims (35)

1. A method of providing access of web applications over a network to a remote user computer, the method comprising:

providing access to an aggregator application from the remote computer via a social login identity provider;

receiving a username associated with the social login identity provider at a lightweight directory access protocol (LDAP) server sent from a data source associated with the aggregator application over the Internet, the LDAP server comprising a microprocessor and a memory that stores the user's informational data, the microprocessor:

identifying the stored user's informational data by comparing the received username to a private username and/or private password previously stored for said user but is inaccessible to said user;

generating a challenge question having an associated answer, request for biometric or social information from the user, or request other relevant stored data about the user, each of which indicates the identity of the user;

formatting the challenge into data blocks according to a format associated with said social login identity provider; and

transmitting the formatted challenge over a communication channel to the remote computer intended for the user to answer,

wherein when the user provides a correct answer, the LDAP server causes the aggregator application to activate and display on the remote computer all of the web applications on which the user has accounts, and

wherein when the user logs in using a new unregistered login identity provider, and the user never enabled that login identity provider web application for the aggregator application, the aggregator application attempts to identify the user by reading a stored list of usernames and related metadata and display candidate selections from the registered login identity providers for the user to select.

2. The method of claim 1 , wherein the LDAP server causes the aggregator application to activate and display on the remote computer also web applications on which the user does not have accounts or are not enabled and wherein the aggregator application is configured to display a visual indicator to indicate when an application does not have an account for a user or is not enabled.

3. The method of claim 1 , wherein if the user decides to login using a new unregistered login identity provider, and the user never enabled that login identity provider web application for the aggregator application, the aggregator application attempts to identify the user.

4. The method of claim 1 , wherein when a second user is delegating an aggregator enabled web application to a plurality of people or within the user's organization to the user, the aggregator application causes the shared web application to automatically appear on the user's interface.

5. A system, comprising:

a processor; and

non-transitory computer-readable storage medium coupled to the processor and having instructions stored thereon, which, when executed by the processor, cause the processor to perform operations comprising:

providing access to an aggregator application from the remote computer via a social login identity provider;

receiving a username associated with the social login identity provider at a lightweight directory access protocol (LDAP) server sent from a data source associated with the aggregator application over the Internet, the LDAP server comprising a microprocessor and a memory that stores the user's informational data, the microprocessor:

identifying the stored user's informational data by comparing the received username to a private username and/or private password previously stored for said user but is inaccessible to said user;

generating a challenge question having an associated answer, request for biometric or social information from the user, or request other relevant stored data about the user, each of which indicates the identity of the user;

formatting the challenge into data blocks according to a format associated with said social login identity provider; and

transmitting the formatted challenge over a communication channel to the remote computer intended for the user to answer,

wherein when the user provides a correct answer, the LDAP server causes the aggregator application to activate and display on the remote computer all of the web applications on which the user has accounts, and

wherein when the user logs in using a new unregistered login identity provider, and the user never enabled that login identity provider web application for the aggregator application, the aggregator application attempts to identify the user by reading a stored list of usernames and related metadata and display candidate selections from the registered login identity providers for the user to select.

6. The system of claim 5 , wherein the LDAP server causes the aggregator application to activate and display on the remote computer also web applications on which the user does not have accounts or are not enabled and wherein the aggregator application is configured to display a visual indicator to indicate when an application does not have an account for a user or is not enabled.

7. The system of claim 5 , wherein if the user decides to login using a new unregistered login identity provider, and the user never enabled that login identity provider web application for the aggregator application, the aggregator application attempts to identify the user.

8. The system of claim 5 , wherein when a second user is delegating an aggregator enabled web application to a plurality of people or within the user's organization to the user, the aggregator application causes the shared web application to automatically appear on the user's interface.

9. A non-transitory computer-readable storage medium having stored thereon a computer program comprising a program code for performing, when running on a computer, a method comprising:

providing access to an aggregator application from the remote computer via a social login identity provider;

receiving a username associated with the social login identity provider at a lightweight directory access protocol (LDAP) server sent from a data source associated with the aggregator application over the Internet, the LDAP server comprising a microprocessor and a memory that stores the user's informational data, the microprocessor:

identifying the stored user's informational data by comparing the received username to a private username and/or private password previously stored for said user but is inaccessible to said user;

generating a challenge question having an associated answer, request for biometric or social information from the user, or request other relevant stored data about the user, each of which indicates the identity of the user;

formatting the challenge into data blocks according to a format associated with said social login identity provider; and

transmitting the formatted challenge over a communication channel to the remote computer intended for the user to answer,

wherein when the user provides a correct answer, the LDAP server causes the aggregator application to activate and display on the remote computer all of the web applications on which the user has accounts, and

wherein when the user logs in using a new unregistered login identity provider, and the user never enabled that login identity provider web application for the aggregator application, the aggregator application attempts to identify the user by reading a stored list of usernames and related metadata and display candidate selections from the registered login identity providers for the user to select.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Mar 25, 2025
From: AVATIER IP, LLC
To: PICCADILLY PATENT FUNDING LLC, AS SECURITY HOLDER
Reel/Frame 070613/0769 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2025
From: AVATIER CORPORATION
To: AVATIER IP, LLC
Reel/Frame 070184/0820 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2018
From: CICCHITTO, NELSON A.; SIMMONS, ANTHONY R. T.
To: AVATIER CORPORATION
Reel/Frame 044848/0016 →
Continuity (3)
Division 15052747 · Feb 24, 2016
Provisional Application 62120153 · Feb 24, 2015
Related Publication 20170295165A1 · Oct 12, 2017