IP Library › Granted Patent US 10,721,222
Granted Patent B2
US 10,721,222 · App. 15/679,686 · Granted Jul 21, 2020

Extending single-sign-on to relying parties of federated logon providers

Inventors: Ricardo Fernando Feijoo (Fort Lauderdale, FL); Thomas Kludy (Cooper City, FL)
Assignee: Citrix Systems, Inc.
H04L63/0815G06F21/335G06F21/41H04L63/0807G06F21/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,721,222
App. No.
15/679,686
Granted
Jul 21, 2020
Kind
B2
Abstract

Aspects of the disclosure relate to extending single-sign-on to relying parties for federated logon providers. An enterprise identity provider server may receive a first authentication token previously issued to an enterprise server by the enterprise identity provider server. Subsequently, the enterprise identity provider server may retrieve, from a token store, a second authentication token associated with a federated identity service provided by a federated identity provider server. The enterprise identity provider server may refresh the second authentication token with the federated identity service provided by the federated identity provider server to obtain a refreshed authentication token. Finally, the enterprise identity provider server may send the refreshed authentication token to the enterprise server, which may enable user devices managed by the enterprise server to access one or more resources provided by a third party system using the federated identity service.

Claims (55)

1. An enterprise identity provider server comprising:

at least one processor;

a communication interface;

memory storing instructions that, when executed by the at least one processor, cause the enterprise identity provider server to:

receive, via the communication interface and from an enterprise server integrated with an enterprise identity service provided by the enterprise identity provider server, a first request to access a first set of resources, wherein the first request comprises a first authentication token previously issued to the enterprise server by the enterprise identity provider server, wherein the first authentication token enables single-sign-on access to the first set of resources of an enterprise system by user devices managed by the enterprise server, the access enabled by the first authentication token including use of the enterprise identity service provided by the enterprise identity provider server;

receive, via the communication interface, a second request from the enterprise server to access a second set of resources provided by a third party system using a federated identity service;

in response to receiving the second request from the enterprise server and the first authentication token, retrieve, from a token store maintained by the enterprise identity provider server, a second authentication token associated with the federated identity service provided by a federated identity provider server, wherein the second authentication token enables single-sign-on access to the second set of resources of the third party system by the user devices managed by the enterprise server, the access enabled by the second authentication token including use of the federated identity service provided by the federated identity provider server, and the third party system being outside the enterprise system;

initiate a refresh of the second authentication token with the federated identity service provided by the federated identity provider server to obtain a refreshed authentication token; and

send, via the communication interface, to the enterprise server, the refreshed authentication token, wherein sending the refreshed authentication token to the enterprise server enables the user devices managed by the enterprise server to access the second set of resources provided by the third party system using the federated identity service.

2. The enterprise identity provider server of claim 1 , wherein the memory stores additional instructions that, when executed by the at least one processor, cause the enterprise identity provider server to:

prior to receiving the first request, provision the enterprise server with the first authentication token.

3. The enterprise identity provider server of claim 1 , wherein the memory stores additional instructions that, when executed by the at least one processor, cause the enterprise identity provider server to:

store, in the token store, the second authentication token and a reference associating the second authentication token with the first authentication token.

4. The enterprise identity provider server of claim 1 , wherein the memory stores additional instructions that, when executed by the at least one processor, cause the enterprise identity provider server to:

in response to initiating the refresh of the second authentication token, store, in the token store, the refreshed authentication token and a reference associating the refreshed authentication token with the first authentication token.

5. The enterprise identity provider server of claim 1 , wherein initiating the refresh of the second authentication token further causes the enterprise identity provider server to:

send, via the communication interface, a request to the federated identity provider server to regenerate the second authentication token, wherein the federated identity provider server generates the refreshed authentication token; and

receive, via the communication interface, the refreshed authentication token from the federated identity provider server.

6. The enterprise identity provider server of claim 5 , wherein initiating the refresh of the second authentication token further causes the enterprise identity provider server to:

update the token store with the refreshed authentication token and a reference associating the refreshed authentication token with the first authentication token.

7. The enterprise identity provider server of claim 1 , wherein the memory stores additional instructions that, when executed by the at least one processor, cause the enterprise identity provider server to respond to the second request from the enterprise server by:

redirecting, via the communication interface, the second request from the enterprise server to the federated identity service provided by the federated identity provider server.

8. The enterprise identity provider server of claim 1 , wherein retrieving the second authentication token further causes the enterprise identity provider server to:

retrieve, from the token store, the second authentication token based on a reference associating the second authentication token with the first authentication token.

9. The enterprise identity provider server of claim 1 , wherein the first set of resources are different from the second set of resources.

10. A method comprising:

at an enterprise identity provider server comprising at least one processor, memory, and a communication interface:

receiving, via the communication interface and from an enterprise server integrated with an enterprise identity service provided by the enterprise identity provider server, a first request to access a first set of resources, wherein the first request comprises a first authentication token previously issued to the enterprise server by the enterprise identity provider server, wherein the first authentication token enables single-sign-on access to the first set of resources of an enterprise system by user devices managed by the enterprise server, the access enabled by the first authentication token including use of the enterprise identity service provided by the enterprise identity provider server;

receiving, via the communication interface, a second request from the enterprise server to access a second set of resources provided by a third party system using a federated identity service;

in response to receiving the second request from the enterprise server and the first authentication token, retrieving, from a token store maintained by the enterprise identity provider server, a second authentication token associated with the federated identity service provided by a federated identity provider server, wherein the second authentication token enables single-sign-on access to the second set of resources of the third party system by the user devices managed by the enterprise server, the access enabled by the second authentication token including use of the federated identity service provided by the enterprise identity provider server, and the third party system being outside the enterprise system;

initiating a refresh of the second authentication token with the federated identity service provided by the federated identity provider server to obtain a refreshed authentication token; and

sending, via the communication interface, to the enterprise server, the refreshed authentication token, wherein sending the refreshed authentication token to the enterprise server enables the user devices managed by the enterprise server to access the second set of resources provided by the third party system using the federated identity service.

11. The method of claim 10 , further comprising:

prior to receiving the first request, provisioning the enterprise server with the first authentication token.

12. The method of claim 10 , further comprising:

storing, in the token store, the second authentication token and a reference associating the second authentication token with the first authentication token.

13. The method of claim 10 , further comprising:

in response to initiating the refresh of the second authentication token, storing, in the token store, the second authentication token and a reference associating the second authentication token with the first authentication token.

14. The method of claim 10 , wherein initiating the refresh of the second authentication token further comprises:

sending, via the communication interface, a request to the federated identity provider server to regenerate the second authentication token, wherein the federated identity provider server generates the refreshed authentication token;

receiving, via the communication interface, the refreshed authentication token from the federated identity provider server; and

updating the token store with the refreshed authentication token and a reference associating the second authentication token with the first authentication token.

15. The method of claim 10 , further comprising:

receiving, via the communication interface, a request from the enterprise server to access the second set of resources provided by the third party system using the federated identity service; and

redirecting, via the communication interface, the second request from the enterprise server to the federated identity service provided by the federated identity provider server.

16. The method of claim 10 , further comprising:

retrieving, from the token store, the second authentication token based on a reference associating the second authentication token to the first authentication token.

17. The method of claim 10 , wherein the first set of resources are different from the second set of resources.

18. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, memory, and a communication interface, cause the computing platform to:

receive, via the communication interface and from an enterprise server integrated with an enterprise identity service provided by an enterprise identity provider server, a first request to access a first set of resources, wherein the first request comprises a first authentication token previously issued to the enterprise server by the enterprise identity provider server, wherein the first authentication token enables single-sign-on access to the first set of resources of an enterprise system by user devices managed by the enterprise server to have single-sign-on access to the first set of resources within the enterprise system, the access enabled by the first authentication token including use of the enterprise identity service provided by the enterprise identity provider server;

receive, via the communication interface, a second request from the enterprise server to access a second set of resources provided by a third party system using a federated identity service;

in response to receiving the second request from the enterprise server and the first authentication token, retrieve, from a token store maintained by the enterprise identity provider server, a second authentication token associated with the federated identity service provided by a federated identity provider server, wherein the second authentication token enables single-sign-on access to the second set of resources of the third party system by the user devices managed by the enterprise server, the access enabled by the second authentication token including use of the federated identity service provided by the federated identity provider server, and the third party system being outside the enterprise system;

initiate a refresh of the second authentication token with the federated identity service provided by the federated identity provider server to obtain a refreshed authentication token; and

send, via the communication interface, to the enterprise server, the refreshed authentication token, wherein sending the refreshed authentication token to the enterprise server enables the user devices managed by the enterprise server to access the second set of resources provided by the third party system using the federated identity service.

19. The non-transitory computer-readable media of claim 18 , wherein the first set of resources are different from the second set of resources.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2017
From: FEIJOO, RICARDO FERNANDO; KLUDY, THOMAS
To: CITRIX SYSTEMS, INC.
Reel/Frame 043334/0578 →
Continuity (1)
Related Publication 20190058706A1 · Feb 21, 2019