IP Library › Granted Patent US 12,032,674
Granted Patent B2
US 12,032,674 · App. 17/419,402 · Granted Jul 9, 2024

Method and system for managing access to a service

Inventor: Jonas Paert (Gemenos, FR)
Assignee: THALES DIS FRANCE SAS
G06F21/41
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,032,674
App. No.
17/419,402
Granted
Jul 9, 2024
Kind
B2
Abstract

The invention method comprises: authenticating successfully, by a user authentication server, through a logon agent in a device, a device user; sending, by the user authentication server, to the logon agent, session data relating to the successful authentication session; sending, by the logon agent, to a logon application the session data; receiving, by at least one browser, from the device user, a first request for accessing the service with a first server identifier; sending, by the logon application, to the at least one browser, the session data; sending, by the browser, based on the first server identifier, to a first receiving server, the session data; verifying, by the first receiving server, whether the session data is or is not valid, and, if yes, authorizing access to the service.

Claims (54)

1. A method for managing access to a service, comprising:

a) authenticating successfully, by a user authentication server, through a logon agent, a device user, the device comprising the logon agent;

b) sending, by the user authentication server, to the logon agent, session data, the session data relating to the successful authentication session and further including information relating to user authentication data that has been used to authenticate successfully the user;

c) sending, by the logon agent, to a logon application the session data;

d) storing, by the logon application, the session data;

e) receiving, by at least one browser, from the device user, a first request for accessing the service, the first service access request including or being accompanied with an identifier relating to a first server to be addressed, the device comprising the at least one browser;

f) sending, by the logon application, to the at least one browser, the session data;

g) sending, by the browser, based on the first server identifier, to, as a first receiving server, either the first server or through the user authentication server, to the first server, the session data;

h) verifying, by the first receiving server, whether the session data is or is not valid; and

i) if the session data is valid, analysing, by the first receiving server, whether information included in the session data relating to user authentication data, and that has been used to authenticate successfully the user, does or does not allow access to the requested service;

j) authorizing, by the first receiving server, access to the service only if the session data is valid and if the information included in the session data relating to user authentication data, and that has been used to authenticate successfully the user, allows access to the requested service.

2. The method according to claim 1 , wherein, after step e) and prior to step f), the browser sends to the logon application a request for getting the session data.

3. The method according to claim 1 , wherein the session data includes a session identifier, the session identifier identifying the successful user authentication session.

4. The method according to claim 3 , wherein the information relating to the user authentication data includes at least one element of a group comprising:

first reference user authentication data;

at least one information item relating to the session event;

at least one indicator relating to the user authentication data that has been used to authenticate successfully the user;

a signature relating to the user authentication server;

a public key relating to the user authentication server; and

a certificate relating to the user authentication server.

5. The method according to claim 1 , wherein, once the at least one browser has received the first service access request, the browser sends to the user authentication server the first service access request, the user authentication server sends to the browser a request for not displaying any information relating to the user authentication server, the browser displaying no information relating to the user authentication server during a data exchange between the browser and the user authentication server.

6. The method according to claim 1 , wherein the method further comprises the following steps:

the first receiving server sends, if the session data is valid and the session data does not allow access to the requested service, to the browser a request for displaying a prompt message for getting additional data relating to the user authentication with respect to the first user authentication data that has been used by the user authentication server to authenticate successfully the user;

the browser displays, based on the prompt message displaying request, on at least one display screen incorporated in or connected to the device, a message for getting, from the device user, additional data relating to the user authentication;

the user provides, through the browser, the first receiving server with second user authentication data;

the first receiving server verifies whether the second provided user authentication data does or does not match second predetermined reference user authentication data; and

the first receiving server authorizes access to the requested service only if the second provided user authentication data matches the second reference user authentication data.

7. The method according to claim 1 , wherein, to authenticate successfully to the user authentication server, the method comprises the following steps:

the user provides the logon agent with first user authentication data;

the logon agent sends to the user authentication server the first provided user authentication data;

the user authentication server verifies whether the first provided user authentication data does or does not match first predetermined reference user authentication data; and

the user authentication server authenticates successfully the user only if the first provided user authentication data matches the first reference user authentication data.

8. The method according to claim 1 , wherein, to carry out the step i), when the user authentication server is the first receiving server, the user authentication server opens a Single Sign On, SSO, session by sending, through the browser, to the first server a request for setting a cookie.

9. A system for managing access to a service, the system comprising a device and a user authentication server, the device comprising a logon agent and at least one browser, wherein the device authenticates successfully, through the logon agent, to the user authentication server, a device user;

wherein the user authentication server sends, to the logon agent, session data, the session data relating to the successful authentication session and further including information relating to user authentication data that has been used to authenticate successfully the user;

wherein the logon agent sends to a logon application the session data;

wherein the logon application stores the session data; wherein the at least one browser receives, from the device user, a first request for accessing the service, the first service access request including or being accompanied with an identifier relating to a first server to be addressed;

wherein the logon application sends to the at least one browser the session data;

wherein the at least one browser sends, based on the first server identifier, to, as a first receiving server, either the first server or through the user authentication server, to the first server, the session data; and

wherein the first receiving server:

verifies, whether the session data is or is not valid;

if the session data is valid, analysing, by the first receiving server, whether information included in the session data relating to user authentication data, and that has been used to authenticate successfully the user, does or does not allow access to the requested service; and

authorizes access to the service, only if the session data is valid and if the information included in the session data relating to user authentication data, and that has been used to authenticate successfully the user, allows access to the requested service.

10. A method for managing access to a service, comprising:

a) authenticating successfully, by a user authentication server, through a logon agent, a device user, the device comprising the logon agent;

b) sending, by the user authentication server, to the logon agent, session data, the session data relating to the successful authentication session;

c) sending, by the logon agent, to a logon application the session data;

d) storing, by the logon application, the session data;

e) receiving, by at least one browser, from the device user, a first request for accessing the service, the first service access request including or being accompanied with an identifier relating to a first server to be addressed, the device comprising the at least one browser;

f) sending, by the logon application, to the at least one browser, the session data;

g) sending, by the browser, based on the first server identifier, to, as a first receiving server, either the first server or through the user authentication server, to the first server, the session data;

h) verifying, by the first receiving server, whether the session data is or is not valid; and

i) authorizing, by the first receiving server, only if the session data is valid, access to the service

wherein, once the at least one browser has received the first service access request, the browser sends to the user authentication server the first service access request, the user authentication server sends to the browser a request for not displaying any information relating to the user authentication server, the browser displaying no information relating to the user authentication server during a data exchange between the browser and the user authentication server.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2022
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 058903/0188 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2021
From: PAERT, JONAS
To: THALES DIS CANADA, INC.
Reel/Frame 058244/0136 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2021
From: THALES DIS CANADA, INC.
To: THALES DIS FRANCE SA
Reel/Frame 058244/0157 →
Priority Claims (1)
EP 18216000 · Dec 31, 2018 · regional
Continuity (1)
Related Publication 20220067138A1 · Mar 3, 2022