IP Library Granted Patent US 10,749,856
Granted Patent B2
US 10,749,856 · App. 15/821,375 · Granted Aug 18, 2020

System and method for multi-tenant SSO with dynamic attribute retrieval

Inventors: Andrey Kostyukov (Dolgoprudny, RU); Maxim Kuzkin (Irvine, CA)
Assignee: INGRAM MICRO, INC.
H04L63/0815G06F9/44526G06F9/547H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,749,856
App. No.
15/821,375
Granted
Aug 18, 2020
Kind
B2
Abstract

A system and method for multi-tenant single sign-on (SSO) identity management with dynamic attribute retrieval, the system includes at least one service provider, at least one service provider plug-in, and a service automation platform. A method for multi-tenant SSO identity management with dynamic attribute retrieval, includes the steps of receiving a link to a service provider at an SSO dispatcher, the SSO dispatcher identifying a service, requesting at the SSO dispatcher, user attributes for the at least one service provider, assembling at a service provider handler implementation, a response query, retrieving identity provider credentials from the service automation platform, signing at the SSO dispatcher, a package for a user's authentication, and redirecting the package to the service provider.

Claims (16)

1. A method for multi-tenant SSO identity management with dynamic attribute retrieval, the method utilizing a system comprising at least one service provider, at least one service provider plug-in, and a service automation platform, the at least one service provider plug-in further comprising a service provider handler implementation, and the service automation platform further comprising a single sign-on (SSO) dispatcher, the method comprising the steps:

a. activating, by a user, a link to a service provided by the at least one service provider;

b. receiving at an SSO dispatcher, the link activated by the user;

c. identifying by the SSO dispatcher the service provided by the at least one service provider;

d. requesting at the SSO dispatcher, user attributes for the at least one service provider from a service provider handler;

e. assembling at a service provider handler implementation, a response query with the user attributes, the user attributes assembled according to a user attributes schema and service provider settings;

f. checking at the SSO dispatcher, whether the response query is a success, and if successful, proceeding to the next step, and if unsuccessful, displaying a message;

g. checking at the SSO dispatcher, whether the response query includes identification of an identity provider, and if the response query does not include identification of an identity provider, retrieving public identity provider credentials from the service automation platform, and if the response query is successful, proceeding to the next step;

h. determining at the SSO dispatcher, whether the response query identifies a managed identity provider, or an exclusive identity provider, and requesting the respective identity provider's credentials identified herein;

i. signing at the SSO dispatcher, a package for a user's authentication with the credentials;

j. redirecting at the SSO dispatcher, the package to the service provider.

2. The method of claim 1 , wherein the user attributes is selected from a group consisting of a username, email address, address, subscription id, tenant id, and zip-code.

3. The method of claim 1 , wherein the service provider settings are set by the service provider and stored in a user data storage.

4. The method of claim 1 , wherein the service provider settings comprises information about a virtualized identity provider selected from a group consisting of a virtualized public identity provider, virtualized managed identity provider, or virtualized exclusive identity provider.

5. The method of claim 3 , wherein the service provider settings further comprises of information about an SSO protocol.

6. The method of claim 1 further comprising the step allowing a user to log in to the service provider, using the package.

Assignments (8)
SECURITY INTEREST Recorded Sep 25, 2025
From: CLOUDBLUE LLC
To: BANK OF MONTREAL
Reel/Frame 072935/0233 →
NUNC PRO TUNC ASSIGNMENT Recorded Nov 9, 2021
From: INGRAM MICRO INC.
To: CLOUDBLUE LLC
Reel/Frame 058081/0507 →
NOTES SECURITY AGREEMENT Recorded Jul 2, 2021
From: INGRAM MICRO INC.; ACTIFY LLC; SHIPWIRE, INC.; BRIGHTPOINT, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 056756/0834 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 2, 2021
From: INGRAM MICRO INC.; ACTIFY LLC; SHIPWIRE, INC.; BRIGHTPOINT, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 056756/0806 →
ABL SECURITY AGREEMENT Recorded Jul 2, 2021
From: INGRAM MICRO INC.; ACTIFY LLC; SHIPWIRE, INC.; BRIGHTPOINT, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 056756/0820 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2020
From: KUZKIN, MAXIM
To: INGRAM MICRO INC.
Reel/Frame 054001/0822 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2020
From: KOSTYUKOV, ANDREY
To: INGRAM MICRO INC.
Reel/Frame 054001/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2020
From: KOSTYUKOV, ANDREY
To: INGRAM MICRO INC.
Reel/Frame 054001/0714 →
Continuity (2)
Provisional Application 62425646 · Nov 23, 2016
Related Publication 20180167378A1 · Jun 14, 2018
Cited By (1)
US 12,461,727