IP Library Granted Patent US 12,413,569
Granted Patent B2
US 12,413,569 · App. 17/955,820 · Granted Sep 9, 2025

Single sign-on between 2 independent states

Inventors: Shobhank Sharma (Kirkland, WA); Venkata Subbarao Evani (Fremont, CA); Kranthi Kiran Pandiri (Redmond, WA); Girish Nagaraja (Sammamish, WA); Nagaraj Pattar (Karnataka, IN); Martinus Petrus Lambertus van den Dungen (Redmond, WA); Ashok Kumar Subbaiyan (Tamil Nadu, IN); Ghazanfar Ahmed (Redmond, WA)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04L63/0815H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,569
App. No.
17/955,820
Granted
Sep 9, 2025
Kind
B2
Abstract

Systems and methods for single sign-on between two independent systems are disclosed herein. The method can include receiving a request to access a first application of a first system having a first login protocol. The method can include receiving user login credentials and authenticating the user login credentials. The method can include logging the user in to the first system and a second system based on the received login credentials. The second system can have a second login protocol independent of the first login protocol.

Claims (31)

1. A method comprising:

receiving a request to access a first application of a first system having a first login protocol, the first system comprising an attribute-based access control (“ABAC”) system;

receiving user login credentials;

authenticating the user login credentials; and

logging the user in to the first system and a second system based on the received login credentials, the second system comprising a role-based access control (“RBAC”) system, wherein the second system has a second login protocol independent of the first login protocol, wherein logging the user in to the first system and the second system based on the received login credentials comprises generating a public/private key pair with the first application, wherein generating a public/private key pair starts a first OAuth flow between the user and the first system, wherein logging the user in to the first system and the second system based on the received login credential further comprises starting a second OAuth flow between the first system and the second system, and wherein the second OAuth flow is embedded in the first OAuth flow.

2. The method of claim 1 , wherein the user login credentials are authenticated by the first system.

3. The method of claim 1 , wherein the user login credentials are authenticated by the second system.

4. The method of claim 3 , wherein the second system establishes an authenticated session for the user on the first system via an exchange of at least one 0 between the second system and the first system.

5. The method of claim 1 , wherein logging the user in to the first system and the second system based on the received login credentials further comprises sending the public key to the first system, and storing the public key in a cache of the first system.

6. The method of claim 5 , wherein the cache of the first system is accessible by the first system.

7. The method of claim 5 , wherein logging the user in to the first system and the second system based on the received login credentials further comprises receiving an authenticating user credentials with the second system.

8. The method of claim 7 , wherein logging the user in to the first system and the second system based on the received login credentials further comprises providing an authorization code from the second system to the first system upon successful authentication of the user credentials with the second system.

9. The method of claim 8 , wherein logging the user in to the first system and the second system based on the received login credentials further comprises providing a token from the second system to the first system in response to a request from the first system to the second system, the request including the authorization code.

10. The method of claim 9 , wherein logging the user in to the first system and the second system based on the received login credentials further comprises translating the token from a first token type to a second token type, wherein the first token type is compatible with the second system, and wherein the second token type is compatible with the first system.

11. The method of claim 10 , wherein logging the user in to the first system and the second system based on the received login credentials further comprises providing the translated token to the user and redirecting the user to the requested application.

12. The method of claim 11 , wherein the token provided by the second system to the first system includes the public key.

13. A system comprising:

a first access control system having a first login protocol, the first system comprising an attribute-based access control (“ABAC”) system, the first access control system comprising:

at least one first processor; and

a memory comprising a plurality of instructions executable by the at least one first processor, and

a second access control system, the second system comprising a role-based access control (“RBAC”) system, wherein the second access control system has a second login protocol independent of the first login protocol,

wherein the first access control system is configured to:

receive a request to access a first application of the first access control system;

receive user login credentials;

authenticate the user login credentials; and

log the user in to the first access control system and to the second access control system based on the received login credentials, wherein logging the user in to the first system and the second system based on the received login credentials comprises generating a public/private key pair with the first application, wherein generating a public/private key pair starts a first OAuth flow between the user and the first system, wherein logging the user in to the first system and the second system based on the received login credential further comprises starting a second OAuth flow between the first system and the second system, and wherein the second OAuth flow is embedded in the first OAuth flow.

14. A non-transitory computer-readable storage medium storing a plurality of instructions executable by one or more processors, the plurality of instructions when executed by the one or more processors cause the one or more processors to:

receive a request to access a first application of a first system having a first login protocol, the first system comprising an attribute-based access control (“ABAC”) system;

receive user login credentials;

authenticate the user login credentials; and

log the user in to the first system and a second system based on the received login credentials, the second system comprising a role-based access control (“RBAC”) system, wherein the second system has a second login protocol independent of the first login protocol, wherein logging the user in to the first system and the second system based on the received login credentials comprises generating a public/private key pair with the first application, wherein generating a public/private key pair starts a first OAuth flow between the user and the first system, wherein logging the user in to the first system and the second system based on the received login credential further comprises starting a second OAuth flow between the first system and the second system, and wherein the second OAuth flow is embedded in the first OAuth flow.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2022
From: SHARMA, SHOBHANK; EVANI, VENKATA SUBBARAO; PANDIRI, KRANTHI KIRAN; NAGARAJA, GIRISH; PATTAR, NAGARAJ; VAN DEN DUNGEN, MARTINUS PETRUS LAMBERTUS; SUBBAIYAN, ASHOK KUMAR; AHMED, GHAZANFAR
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 061544/0303 →
Continuity (2)
Provisional Application 63250604 · Sep 30, 2021
Related Publication 20230103886A1 · Apr 6, 2023
References Cited (122)
US 8474018B2 · Mardikar et al. · 2013 [cited by applicant]
US 8732800B1 · Askew · 2014 [cited by applicant]
US 8776201B2 · Gao et al. · 2014 [cited by applicant]
US 8990911B2 · Olden et al. · 2015 [cited by applicant]
US 9053302B2 · Sastry et al. · 2015 [cited by applicant]
US 9491200B2 · Mardikar et al. · 2016 [cited by applicant]
US 9560036B2 · Hinton et al. · 2017 [cited by applicant]
US 9781122B1 · Wilson et al. · 2017 [cited by applicant]
US 9838376B1 · Lander et al. · 2017 [cited by applicant]
US 10225242B2 · Grim et al. · 2019 [cited by applicant]
US 10255061B2 · Lander et al. · 2019 [cited by applicant]
US 10341410B2 · Lander et al. · 2019 [cited by applicant]
US 10425386B2 · Wardell et al. · 2019 [cited by applicant]
US 10454940B2 · Lander et al. · 2019 [cited by applicant]
US 10484243B2 · Cole et al. · 2019 [cited by applicant]
US 10484382B2 · Wilson et al. · 2019 [cited by applicant]
US 10511589B2 · Gangawane et al. · 2019 [cited by applicant]
US 10594684B2 · Bansal et al. · 2020 [cited by applicant]
US 10616224B2 · Subramanian et al. · 2020 [cited by applicant]
US 10715564B2 · Mohamad Abdul et al. · 2020 [cited by applicant]
US 10798165B2 · Srinivasan et al. · 2020 [cited by applicant]
US 10846390B2 · Subramanian · 2020 [cited by examiner]
US 10878079B2 · Vepa et al. · 2020 [cited by applicant]
US 10931656B2 · Carru et al. · 2021 [cited by applicant]
US 11061929B2 · Xu et al. · 2021 [cited by applicant]
US 11108828B1 · Curtis et al. · 2021 [cited by applicant]
US 11165634B2 · Medam et al. · 2021 [cited by applicant]
US 11308132B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11321343B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11599677B2 · Buscaglia et al. · 2023 [cited by applicant]
US 11606391B2 · Greenebaum et al. · 2023 [cited by applicant]
US 11627123B2 · Stayskal et al. · 2023 [cited by applicant]
US 11847239B2 · Grand · 2023 [cited by applicant]
US 11962624B2 · Kuehr-McLaren et al. · 2024 [cited by applicant]
US 20050154913A1 · Barriga et al. · 2005 [cited by applicant]
US 20060074894A1 · Remahl et al. · 2006 [cited by applicant]
US 20070056018A1 · Ridlon et al. · 2007 [cited by applicant]
US 20070143291A1 · Browne · 2007 [cited by applicant]
US 20080276296A1 · Larsen · 2008 [cited by applicant]
US 20090249060A1 · Dossett et al. · 2009 [cited by applicant]
US 20130227658A1 · Leicher et al. · 2013 [cited by applicant]
US 20130283350A1 · Afek et al. · 2013 [cited by applicant]
US 20140075942A1 · Rewers et al. · 2014 [cited by applicant]
US 20140181003A1 · Kling et al. · 2014 [cited by applicant]
US 20150089575A1 · Vepa et al. · 2015 [cited by applicant]
US 20150215348A1 · Koeten et al. · 2015 [cited by applicant]
US 20150350338A1 · Bamett et al. · 2015 [cited by applicant]
US 20160072839A1 · Mortimore, Jr. · 2016 [cited by examiner]
US 20160277390A1 · Minov et al. · 2016 [cited by applicant]
US 20160359861A1 · Manov et al. · 2016 [cited by applicant]
US 20170063931A1 · Seed et al. · 2017 [cited by applicant]
US 20170177894A1 · Stock et al. · 2017 [cited by applicant]
US 20170230419A1 · Prafullchandra et al. · 2017 [cited by applicant]
US 20170329957A1 · Vepa · 2017 [cited by examiner]
US 20170331832A1 · Lander et al. · 2017 [cited by applicant]
US 20180081905A1 · Kamath et al. · 2018 [cited by applicant]
US 20180144150A1 · Aakolk et al. · 2018 [cited by applicant]
US 20180234416A1 · Moerk et al. · 2018 [cited by applicant]
US 20190068377A1 · Matsugashita et al. · 2019 [cited by applicant]
US 20190073468A1 · Kazerani et al. · 2019 [cited by applicant]
US 20190273746A1 · Coffing · 2019 [cited by applicant]
US 20190362087A1 · Ferrans et al. · 2019 [cited by applicant]
US 20200007530A1 · Mohamad Abdul · 2020 [cited by examiner]
US 20200053091A1 · Childress et al. · 2020 [cited by applicant]
US 20200120098A1 · Berg et al. · 2020 [cited by applicant]
US 20200264860A1 · Srinivasan et al. · 2020 [cited by applicant]
US 20210044595A1 · Childress et al. · 2021 [cited by applicant]
US 20210081252A1 · Bhargava et al. · 2021 [cited by applicant]
US 20210084031A1 · Lao et al. · 2021 [cited by applicant]
US 20210234706A1 · Nair · 2021 [cited by examiner]
US 20210377044A1 · Leibmann · 2021 [cited by examiner]
US 20220116376A1 · Stayskal et al. · 2022 [cited by applicant]
US 20220210194A1 · Parekh et al. · 2022 [cited by applicant]
US 20220210195A1 · Parekh et al. · 2022 [cited by applicant]
US 20220210196A1 · Parekh et al. · 2022 [cited by applicant]
US 20220239640A1 · Wang et al. · 2022 [cited by applicant]
US 20220247787A1 · Lippert et al. · 2022 [cited by applicant]
US 20230103886A1 · Sharma et al. · 2023 [cited by applicant]
US 20250080530A1 · Trinelli et al. · 2025 [cited by applicant]
CN 110336820A · 2019 [cited by applicant]
EP 3528454A1 · 2019 [cited by applicant]
WO 2018053122A1 · 2018 [cited by applicant]
Roei Schuster, Vitaly Shmatikov, and Eran Tromer. 2018. Situational Access Control in the Internet of Things. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS '18). Associati… [cited by examiner]
Access Control, Google Cloud, Available Online at: https://cloud.google.com/kubernetes-engine/docs/concepts/access-control, Accessed from Intemeton Sep. 16, 2021, 3 pages. [cited by applicant]
AWS IAM Identity Center (Successorto AWS Single Sign-On), Centrally Manage Workforce Access to Multiple AWS Accounts and Applications, Available Online at: https://aws.amazon.com/iam/identity-center/, Accessed from Inte… [cited by applicant]
How does SAML Single Logout Requestwork?, Available Online at: https://support.servicenow.com/kbid=kb_article_view&sysparm_article=KB0788164, Sep. 20, 2021, 2 pages. [cited by applicant]
How Does Single Sign-on Work?, How Single Sign-on Works, Step by Step, Available online at https://www.onelogin.com/leam/how-single-sign-on-works, Accessed from Intemeton Sep. 20, 2021, pp. 1-5. [cited by applicant]
IDM365 Identity and Access Managementfor the RBAC/ABAC Hybrid Solution, IDM 365, Available Online at: https://idm365.com/idm365-the-rbac-abac-hybrid-solution/, Accessed from Internet on Sep. 20, 2021, 5 pages. [cited by applicant]
IdP Single Logout (SLO), Available Online at: https://docs.pingidentity.com/bundle/integrations/page/gdz1563995023643.html, Jul. 24, 2019, 1 page. [cited by applicant]
Multicloud Identity and Access Management Architecture, IBM Cloud, Available Online at: https://www.ibm.com/cloud/architecture/architectures/security-iam/reference-architecture, Accessed from Internet on Sep. 16, 2021, … [cited by applicant]
OpenID Connect Single Logout, Available Online at: https://is.docs.wso2.com/en/latest/learn/openid-connect-single-logout/, 2021, 18 pages. [cited by applicant]
Single Logout (SLO), Available Online at: https://identitydocs.akamai.com/gettingstarted/sessions/3logout/page2-slo/, Accessed from Intemet on Sep. 20, 2021, 2 pages. [cited by applicant]
Single Sign-On SSO, JWT SSO, Available Online at: https://www.miniorange.com/saml-identity-provider-with-jwt-protocol, Accessed from Internet on Sep. 20, 2021, 7 pages. [cited by applicant]
Single Sign-Out SAML Protocol, Microsoft Docs, Available Online at: https://docs.microsoft.com/enus/azure/activedirectory/develop/single-sign-out-saml-protocol, Aug. 24, 2021, 3 pages. [cited by applicant]
The Definitive Guide to Attribute-Based Access Control (ABAC), Nextlabs, Available Online at: https://www.nextlabs.com/products/technology/abac/, Accessed from Intemet on Sep. 16, 2021, 10 pages. [cited by applicant]
Use IdP-Initiated Single Logout (SLO), Available Online at: https://help.sap.com/viewer/6d6d63354d1242d185ab4830fc04feb1/Cloud/enUS/da2e4f9866dc45f0b4723ca41f051bea.html, Accessed from Internet on Sep. 20, 2021, 1 page. [cited by applicant]
User Management Service Single Sign-on, IBM Documentation, Available online at https://www.ibm.com/docs/en/cloud-paks/1.0?topic=services-ums-single-sign, Accessed from Internet on Sep. 20, 2021, pp. 1-3. [cited by applicant]
What is Azure Attribute-Based Access Control (Azure ABAC)?, Microsoft Docs, Available Online at: https://docs.microsoft.com/en-us/azure/role-based-access-control/conditions-overview, May 13, 2021, 7 pages. [cited by applicant]
What is Azure role-based Access Control (Azure RBAC)?, Microsoft, Available Online at: https://docs.microsoft.com/en-us/azure/role-based-access-control/overview, May 17, 2021, 7 pages. [cited by applicant]
Why SSO is only Part of Multi-Cloud Identity, Available Online at: https://www.strata.io/resources/blog/multi-cloud-identity/sso-only-part-of-multi-cloud-identity/, Jun. 1, 2021, 6 pages. [cited by applicant]
Parker, A Guide to Authorization: A Discussion of New Best Practices Using Hybrid Role and Attribute Techniques Available Online at: https://f.hubspotusercontent10.net/hubfs/174819/docs/A%20Guide%20To%20Authorization%20… [cited by applicant]
Van Blijderveen et al., How to Scale Your Authorization Needs by Using Attribute-Based Access Control With S3, Available Online at: https://aws.amazon.com/blogs/security/how-to-scale-authorization-needs-using-attribute-… [cited by applicant]
Hu et al., Multiparty Authorization Framework for Data Sharing in Online Social Networks, Data and Applications Security and Privacy XXV, Jul. 11, 2011, pp. 29-43. [cited by applicant]
Moghaddam et al., A Multi-Layered Policy Generation and Management Engine for Semantic Policy, Digital Communications and Networks, vol. 6, No. 1, Feb. 1, 2020, pp. 38-50. [cited by applicant]
International Application No. PCT/US2022/045348, International Search Report and Written Opinion mailed on Jan. 19, 2023, 13 pages. [cited by applicant]
International Application No. PCT/US2022/045370, International Search Report and Written Opinion mailed on Jan. 23, 2023, 13 pages. [cited by applicant]
Wu et al., A Trust-Evaluation-Enhanced Blockchain-Secured Industrial IoT System, IEEE Internet of Things Journal, vol. 8, No. 7, Oct. 13, 2020, pp. 5510-5517. [cited by applicant]
AWS Single Sign-On, AWS, Available Online at https://aws.amazon.com/single-sign-on/, Accessed from Internet on Sep. 20, 2021, pp. 1-11. [cited by applicant]
Shoemaker, Introduction to IndexedDB: The In-Browser Database, CODE Magazine, Available Online at: https://www.codemag.com/article/1411041/Introduction-to-IndexedDB-The-In-Browser-Database, Aug. 31, 2021, 27 pages. [cited by applicant]
International Application No. PCT/US2022/045348 , “International Preliminary Report on Patentability”, Apr. 11, 2024, 9 pages. [cited by applicant]
International Application No. PCT/US2022/045370 , “International Preliminary Report on Patentability”, Apr. 11, 2024, 10 pages. [cited by applicant]
U.S. Appl. No. 17/957,146 , Final Office Action, Mailed On Mar. 7, 2025, 24 pages. [cited by applicant]
U.S. Appl. No. 17/957,146 , Non-Final Office Action, Mailed On Sep. 23, 2024, 19 pages. [cited by applicant]
U.S. Appl. No. 17/957,522 , Non-Final Office Action, Mailed On Sep. 10, 2024, 12 pages. [cited by applicant]
Bailey et al., “Self-Adaptive Authorization Framework for Policy Based RBAC/ABAC Models”, Institute of Electrical and Electronics Engineers Ninth International Conference on Dependable, Autonomic and Secure Computing, D… [cited by applicant]
Pal et al., “On Design of A Fine-Grained Access Control Architecture for Securing IoT-Enabled Smart Healthcare Systems”, In Proceedings of the 14th EAI International Conference on Mobile and Ubiquitous Systems: Computin… [cited by applicant]
Paul , “Authentication and Authorization for the Front-end Web Developer”, School of Science, 2020, 61 page. [cited by applicant]
Wang et al., “Private Set Intersection With Authorization Over Outsourced Encrypted Datasets”, Institute of Electrical and Electronics Engineers Transactions on Information Forensics and Security, vol. 16, Jul. 28, 2021… [cited by applicant]
U.S. Appl. No. 17/957,522, Non-Final Office Action mailed on Apr. 17, 2025, 15 pages. [cited by applicant]
Long et al., RACAC: An Approach toward RBAC and ABAC Combining Access Control, Institute of Electrical and Electronics Engineers 5th International Conference on Computer and Communications, Dec. 6, 2019, pp. 1609-1616. [cited by applicant]
Qi et al., Access Control Model Based on Role and Attribute and Its Applications on Space-Ground Integration Networks, 4th International Conference on Computer Science and Network Technology, vol. 1, Dec. 19, 2015, pp. … [cited by applicant]
U.S. Appl. No. 17/896,969, Notice of Allowance mailed on Jul. 17, 2025, 15 pages. [cited by applicant]
Cited By (1)
US 12,464,036