IP Library Granted Patent US 11,228,574
Granted Patent B2
US 11,228,574 · App. 16/048,460 · Granted Jan 18, 2022

System for managing remote software applications

Inventors: Erik Gustavson (Los Angeles, CA); Scott Kriz (Manhattan Beach, CA); Aaron Eisenberger (Santa Monica, CA); Garrett Brown (Costa Mesa, CA); Jason Carulli (Dana Point, CA); Andrew Arrow (Culver City, CA); Prashant Nadarajan (Singapore, SG); Fong Woh Fai (Kuala Lumpur, MY); Chung Weng Wai (Kuala Lumpur, MY); Saw Kee Wooi (Kuala Lumpur, MY)
Assignee: Google LLC
H04L63/08H04L63/0815H04L63/168H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,228,574
App. No.
16/048,460
Granted
Jan 18, 2022
Kind
B2
Abstract

The disclosure describes systems, methods and devices relating to a sign-on and management hub or service for users of multiple internal, external or Software-as-a-Service (SaaS) software applications (Apps), with options for centralized management and sharing of accounts without needing to provide login credentials to individual users.

Claims (54)

1. A method comprising:

providing, by a client device on behalf of a particular user and to a server of a sign-on system, login credentials of the particular user for the sign-on system;

providing, by the client device and to the server of the sign-on system, a request to access a particular third party application, wherein providing the request to access the particular third party application triggers the server to perform:

identifying, by the server of the sign-on system, login credentials for the particular third party application from among a set of multiple stored login credentials based at least on both the login credentials of the particular user obtained for the sign-on system and the particular third party application that was requested, wherein the login credentials for the particular third party application are unknown to the particular user of the client device; and

determining whether the particular third party application prevents the server from providing the login credentials for the particular third party application that are identified by the server and instead requires the client device to provide login credentials; and

when the particular third party application prevents the server from providing the login credentials for the particular third party application that are identified by the server and instead requires the client device to provide login credentials triggered by the access request, establishing, by the client device, an authenticated session with the particular third party application requested using the login credentials for the particular third party application without providing the particular user access to the login credentials for the particular third party application by:

receiving, by the client device, at least one of:

a client login script including the login credentials for the particular third party application; or

session information of an authenticated session between a virtual web browser instantiated by the server and the third party application for the client device; and

providing, by the client device to the third party application, the at least one of:

the client login script including the login credentials for the particular third party application; or

the session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device.

2. The method of claim 1 , wherein receiving, by the client device, the at least one of the client login script including the login credentials for the particular third party application or the session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device comprises receiving by the client device, the client login script that includes the login credentials for the particular third party application, wherein receipt of the client login script by the client device causes the client device to execute the client login script and establish the authenticated session with the particular third party application without further input from the particular user after the request to access the particular third party application is obtained by the server.

3. The method of claim 1 , wherein receiving, by the client device the at least one of the client login script including the login credentials for the particular third party application or the session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device comprises receiving, by the client device and from the server, the session information for the authenticated session between the virtual web browser on the server and the third party application for the client device to use to establish the authenticated session with the particular third party application.

4. The method of claim 3 , wherein the session information comprises a web browser cookie.

5. The method of claim 3 , wherein the session information is obtained by the server in response to the virtual web browser submitting a login form of the particular third party application with the login credentials for the particular third party application supplied in the login form.

6. The method of claim 5 , wherein the virtual web browser submitting a login form of the particular third party application with the login credentials for the particular third party application supplied in the login form is in response to the server determining that the third party application fails to require login through a specific application programming interface.

7. The method of claim 1 , further comprising providing a prompt for the particular user to provide login credentials for the sign-on system.

8. A system comprising:

one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause the one or more computers to perform operations comprising:

providing, by a client device on behalf of a particular user and to a server of a sign-on system, login credentials of the particular user for the sign-on system;

providing, by the client device and to the server of the sign-on system, a request to access a particular third party application, wherein providing the request to access the particular third party application triggers the server to perform:

identifying, by the server of the sign-on system, login credentials for the particular third party application from among a set of multiple stored login credentials based at least on both the login credentials of the particular user obtained for the sign-on system and the particular third party application that was requested, wherein the login credentials for the particular third party application are unknown to the particular user of the client device; and

determining whether the particular third party application prevents the server from providing the login credentials for the particular third party application that are identified by the server and instead requires the client device to provide login credentials; and

when the particular third party application prevents the server from providing the login credentials for the particular third party application that are identified by the server and instead requires the client device to provide login credentials, establishing, by the client device, an authenticated session with the particular third party application requested using the login credentials for the particular third party application without providing the particular user access to the login credentials for the particular third party application by:

receiving, by the client device, at least one of:

a client login script including the login credentials for the particular third party application; or

session information of an authenticated session between a virtual web browser instantiated by the server and the third party application for the client device; and

providing, by the client device to the third party application, the at least one of:

the client login script including the login credentials for the particular third party application; or

the session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device.

9. The system of claim 8 , wherein receiving, by the client device, the at least one of (i) the client login script including the login credentials for the particular third party application or (ii) the session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device comprises receiving by the client device the client login script that includes the login credentials for the particular third party application, wherein receipt of the client login script by the client device causes the client device to execute the client login script and establish the authenticated session with the particular third party application without further input from the particular user after the request to access the particular third party application is obtained by the server.

10. The system of claim 8 , wherein receiving, by the client device, the at least one of the client login script including the login credentials for the particular third party application or the session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device comprises receiving, by the client device and from the server, the session information for the authenticated session between the virtual web browser on the server and the third party application for the client device to use to establish the authenticated session with the particular third party application.

11. The system of claim 10 , wherein the session information comprises a web browser cookie.

12. The system of claim 10 , wherein the session information is obtained by the server in response to the virtual web browser submitting a login form of the particular third party application with the login credentials for the particular third party application supplied in the login form.

13. The system of claim 12 , wherein the virtual web browser submitting a login form of the particular third party application with the login credentials for the particular third party application supplied in the login form is in response to the server determining that the third party application fails to require login through a specific application programming interface.

14. The system of claim 10 , wherein the operations further comprise providing a prompt for the particular user to provide login credentials for the sign-on system.

15. A non-transitory computer-readable medium storing software comprising instructions executable by one or more computers which, upon such execution, cause the one or more computers to perform operations comprising:

providing, by a client device on behalf of a particular user and to a server of a sign-on system, login credentials of the particular user for the sign-on system;

providing, by the client device and to the server of the sign-on system, a request to access a particular third party application, wherein providing the request to access the particular third party application triggers the server to perform:

identifying, by the server of the sign-on system, login credentials for the particular third party application from among a set of multiple stored login credentials based at least on both the login credentials of the particular user obtained for the sign-on system and the particular third party application that was requested, wherein the login credentials for the particular third party application are unknown to the particular user of the client device; and

determining whether the particular third party application prevents the server from providing the login credentials for the particular third party application that are identified by the server and instead requires the client device to provide login credentials; and

when the particular third party application prevents the server from providing the login credentials for the particular third party application that are identified by the server and instead requires the client device to provide login credentials, establishing, by the client device, an authenticated session with the particular third party application requested using the login credentials for the particular third party application without providing the particular user access to the login credentials for the particular third party application by:

receiving, by the client device, at least one of:

a client login script including the login credentials for the particular third party application; or

session information of an authenticated session between a virtual web browser instantiated by the server and the third party application for the client device; and

providing, by the client device to the third party application, the at least one of:

the client login script including the login credentials for the particular third party application: or

the session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device.

16. The medium of claim 15 , wherein receiving, by the client device, the at least one of the client login script including the login credentials for the particular third party application or session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device comprises receiving by the client device the client login script that includes the login credentials for the particular third party application, wherein receipt of the client login script by the client device causes the client device to execute the client login script and establish the authenticated session with the particular third party application without further input from the particular user after the request to access the particular third party application is obtained by the server.

17. The medium of claim 15 , wherein receiving, by the client device, the at least one of the client login script including the login credentials for the particular third party application or the session information of the authenticated session between the virtual web browser instantiated by the server and the third party application for the client device comprises receiving, by the client device and from the server, the session information for the authenticated session between the virtual web browser on the server and the third party application for the client device to use to establish the authenticated session with the particular third party application.

18. The medium of claim 17 , wherein the session information comprises a web browser cookie.

19. The medium of claim 17 , wherein the session information is obtained by the server in response to the virtual web browser submitting a login form of the particular third party application with the login credentials for the particular third party application supplied in the login form.

20. The medium of claim 19 , wherein the virtual web browser submitting a login form of the particular third party application with the login credentials for the particular third party application supplied in the login form is in response to the server determining that the third party application fails to require login through a specific application programming interface.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2018
From: GUSTAVSON, ERIK; KRIZ, SCOTT; EISENBERGER, AARON; BROWN, GARRETT; CARULLI, JASON; ARROW, ANDREW; NADARAJAN, PRASHANT; FAI, FONG WHO; WAI, CHUNG WENG; WOOI, SAW KEE
To: BITIUM, INC.
Reel/Frame 046503/0298 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2018
From: BITIUM INC.
To: GOOGLE LLC
Reel/Frame 046503/0436 →
Continuity (3)
Continuation 14097120 · Dec 4, 2013
Provisional Application 61782519 · Mar 14, 2013
Related Publication 20180337910A1 · Nov 22, 2018