IP Library Granted Patent US 12,095,752
Granted Patent B2
US 12,095,752 · App. 17/646,693 · Granted Sep 17, 2024

System for managing remote software applications

Inventors: Erik Gustavson (Los Angeles, CA); Scott Kriz (Manhattan Beach, CA); Aaron Eisenberger (Santa Monica, CA); Garrett Brown (Costa Mesa, CA); Jason Carulli (Dana Point, CA); Andrew Arrow (Culver City, CA); Prashant Nadarajan (Singapore, SG); Chung Weng Wai (Kuala Lumpur, MY); Saw Kee Wooi (Kuala Lumpur, MY); Fong Woh Fai (Kuala Lumpur, MY)
Assignee: Google LLC
H04L63/08H04L63/0815H04L63/168H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,095,752
App. No.
17/646,693
Granted
Sep 17, 2024
Kind
B2
Abstract

The disclosure describes systems, methods and devices relating to a sign-on and management hub or service for users of multiple internal, external or Software-as-a-Service (SaaS) software applications (Apps), with options for centralized management and sharing of accounts without needing to provide login credentials to individual users.

Claims (32)

1. A computer-implemented method when executed by data processing hardware of a sign-on system causes the data processing hardware to perform operations comprising:

receiving, from an add-on of a client device, a request to access a third party external application;

determining that a user associated with the client device is signed in to the sign-on system;

in response to determining that the user associated with the client device is signed in to the sign-on system:

determining, by the sign-on system, that the third party external application requires a client-side login to initiate an authenticated session, the client-side login comprising session credentials from the client device; and

in response to determining that the third party external application requires the client-side login to initiate the authenticated session, generating a login script for execution by the client device; and

sending the login script to the client device, the login script, when executed, configured to cause the client device to provide login credentials associated with the third party external application and the session credentials from the client device to the third party external application without the user associated with the client device knowing the login credentials.

2. The computer-implemented method of claim 1 , wherein the operations further comprise, receiving, from the client device, additional login credentials comprising a username and password.

3. The computer-implemented method of claim 1 , wherein determining that the third party external application requires the client-side login comprises determining that the third party external application does not allow the sign-on system to send an access token associated with the login credentials to the third party external application.

4. The computer-implemented method of claim 1 , wherein the operations further comprise sending the session credentials of the authenticated session between a virtual web browser instantiated by the sign-on system and the third party external application for the client device.

5. The computer-implemented method of claim 4 , wherein the session credentials comprise a web browser cookie.

6. The computer-implemented method of claim 1 , wherein the operations further comprise determining whether the third party external application requires an application programming interface (API).

7. The computer-implemented method of claim 1 , wherein the third party external application comprises a software as a service (SaaS) application.

8. The computer-implemented method of claim 1 , wherein the operations further comprise selecting the third party external application from among a plurality of third party external applications.

9. The computer-implemented method of claim 1 , wherein the operations further comprise determining whether the client device comprises the add-on.

10. A system comprising:

data processing hardware of a sign-on system; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

receiving, from an add-on of a client device, a request to access a third party external application;

determining that a user associated with the client device is signed in to the sign-on system;

in response to determining that the user associated with the client device is signed in to the sign-on system:

determining, by the sign-on system, that the third party external application requires a client-side login to initiate an authenticated session, the client-side login comprising session credential from the client device; and

in response to determining that the third party external application requires the client-side login to initiate the authenticated session, generating a login script for execution by the client device; and

sending the login script to the client device, the login script, when executed, configured to cause the client device to provide login credentials associated with the third party external application and the session credentials from the client device to the third party external application without the user associated with the client device knowing the login credentials.

11. The system of claim 10 , wherein the operations further comprise, receiving, from the client device, additional login credentials comprising a username and password.

12. The system of claim 10 , wherein determining that the third party external application requires the client-side login comprises determining that the third party external application does not allow the sign-on system to send an access token associated with the login credentials to the third party external application.

13. The system of claim 10 , wherein the operations further comprise sending the session credentials of the authenticated session between a virtual web browser instantiated by the sign-on system and the third party external application for the client device.

14. The system of claim 13 , wherein the session credentials comprise a web browser cookie.

15. The system of claim 10 , wherein the operations further comprise determining whether the third party external application requires an application programming interface (API).

16. The system of claim 10 , wherein the third party external application comprises a software as a service (SaaS) application.

17. The system of claim 10 , wherein the operations further comprise selecting the third party external application from among a plurality of third party external applications.

18. The system of claim 10 , wherein the operations further comprise determining whether the client device comprises the add-on.

Continuity (4)
Continuation 16048460 · Jul 30, 2018
Continuation 14097120 · Dec 4, 2013
Provisional Application 61782519 · Mar 14, 2013
Related Publication 20220124081A1 · Apr 21, 2022