IP Library Granted Patent US 11,570,172
Granted Patent B2
US 11,570,172 · App. 17/524,595 · Granted Jan 31, 2023

Secure identity provider authentication for native application to access web service

Inventors: Joel Specht (Folsom, CA); Matthew Rojas (Roseville, CA)
Assignee: INDUCTIVE AUTOMATION, LLC
H04L63/0876H04L63/1425H04L63/20H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,172
App. No.
17/524,595
Granted
Jan 31, 2023
Kind
B2
Abstract

A native application on a client computing device enables secure user authentication via an identity provider (IdP) for accessing services of a web service provider. The native application forwards a redirect request generated by a main gateway of the service provider and including an IdP uniform resource locator (URL) to a system browser of the client computing device. The redirect request directs the system browser to a broker gateway of the service provider that registers an authentication response handler and redirects the system browser to the IdP URL to enable a user of the native client computing device to authenticate. After the broker gateway receives an IdP authentication response from the IdP following authentication by the user, the broker gateway provides the IdP authentication response to the native application for providing back to the main gateway. The main gateway finally processes the authentication response to complete the authentication request.

Claims (32)

1. A method comprising:

requesting, by a computing device via a native application running on the computing device, access to a service from a main gateway of a service provider associated with the native application;

modifying, by the computing device via the native application, a redirect request from the main gateway to include an authentication server port;

in response to using the modified redirect request to redirect a web browser of the computing device to a broker gateway, intercepting, by an authentication server of the computing device, a browser redirect request from the broker gateway;

redirecting, by the authentication server, the web browser to an identity provider using a cached security assertion markup language (“SAML”) authentication request received from the main gateway;

sequentially receiving and assembling, by the authentication server, a plurality of partitioned components of an SAML authentication response from the broker gateway; and

providing, by the native application, the assembled SAML authentication response to the main gateway.

2. The method of claim 1 , wherein the broker gateway receives the SAML authentication response from the identity provider and partitions the SAML authentication response into the plurality of partitioned components.

3. The method of claim 1 , wherein receiving and assembling the plurality of partitioned components of the SAML authentication response comprises extracting a portion of the SAML authentication response from a URL corresponding to each of the plurality of partitioned components of the SAML authentication response and concatenating the extracted portions of the SAML authentication response.

4. The method of claim 3 , wherein the broker gateway embeds portions of the SAML authentication response into the URLs such that a size of the URL is below the browser URL size limit.

5. The method of claim 1 , wherein the authentication server is initialized within the native application.

6. The method of claim 1 , wherein the redirect request is modified to be directed to the authentication server, and wherein the broker gateway registers a response handler using the authentication server port.

7. The method of claim 1 , wherein the main gateway generates the redirect request in response to receiving the request for access to the server from the native application.

8. The method of claim 7 , wherein the redirect request includes an identify provider (“IdP”) URL.

9. The method of claim 1 , wherein the SAML authentication request is generated by the main gateway in response to a request for an SAML authentication request received from the native application.

10. The method of claim 1 , wherein the native application communicates with the main gateway using a web view of the native application.

11. A non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to perform operations comprising:

requesting, by a computing device via a native application running on the computing device, access to a service from a main gateway of a service provider associated with the native application;

modifying, by the computing device via the native application, a redirect request from the main gateway to include an authentication server port;

in response to using the modified redirect request to redirect a web browser of the computing device to a broker gateway, intercepting, by an authentication server of the computing device, a browser redirect request from the broker gateway;

redirecting, by the authentication server, the web browser to an identity provider using a cached security assertion markup language (“SAML”) authentication request received from the main gateway;

sequentially receiving and assembling, by the authentication server, a plurality of partitioned components of an SAML authentication response from the broker gateway; and

providing, by the native application, the assembled SAML authentication response to the main gateway.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the broker gateway receives the SAML authentication response from the identity provider and partitions the SAML authentication response into the plurality of partitioned components.

13. The non-transitory computer-readable storage medium of claim 11 , wherein receiving and assembling the plurality of partitioned components of the SAML authentication response comprises extracting a portion of the SAML authentication response from a URL corresponding to each of the plurality of partitioned components of the SAML authentication response and concatenating the extracted portions of the SAML authentication response.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the broker gateway embeds portions of the SAML authentication response into the URLs such that a size of the URL is below the browser URL size limit.

15. The non-transitory computer-readable storage medium of claim 11 , wherein the authentication server is initialized within the native application.

16. The non-transitory computer-readable storage medium of claim 11 , wherein the redirect request is modified to be directed to the authentication server, and wherein the broker gateway registers a response handler using the authentication server port.

17. The non-transitory computer-readable storage medium of claim 11 , wherein the main gateway generates the redirect request in response to receiving the request for access to the server from the native application.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the redirect request includes an identify provider (“IdP”) URL.

19. The non-transitory computer-readable storage medium of claim 11 , wherein the SAML authentication request is generated by the main gateway in response to a request for an SAML authentication request received from the native application.

20. The non-transitory computer-readable storage medium of claim 11 , wherein the native application communicates with the main gateway using a web view of the native application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2021
From: SPECHT, JOEL; ROJAS, MATTHEW
To: INDUCTIVE AUTOMATION, LLC
Reel/Frame 058183/0666 →
Continuity (3)
Continuation 17324988 · May 19, 2021
Provisional Application 63131766 · Dec 29, 2020
Related Publication 20220210155A1 · Jun 30, 2022
Cited By (2)
US 12,438,879 US 12,452,286