IP Library Granted Patent US 11,916,905
Granted Patent B2
US 11,916,905 · App. 18/088,561 · Granted Feb 27, 2024

Secure identity provider authentication for native application to access web service

Inventors: Joel Specht (Folsom, CA); Matthew Rojas (Roseville, CA)
Assignee: INDUCTIVE AUTOMATION, LLC
H04L63/0876H04L63/1425H04L63/20H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,916,905
App. No.
18/088,561
Granted
Feb 27, 2024
Kind
B2
Abstract

A native application on a client computing device enables secure user authentication via an identity provider (IdP) for accessing services of a web service provider. The native application forwards a redirect request generated by a main gateway of the service provider and including an IdP uniform resource locator (URL) to a system browser of the client computing device. The redirect request directs the system browser to a broker gateway of the service provider that registers an authentication response handler and redirects the system browser to the IdP URL to enable a user of the native client computing device to authenticate. After the broker gateway receives an IdP authentication response from the IdP following authentication by the user, the broker gateway provides the IdP authentication response to the native application for providing back to the main gateway. The main gateway finally processes the authentication response to complete the authentication request.

Claims (28)

1. A method comprising:

requesting, by a computing device via a native application running on the computing device, access to a service from a main gateway of a service provider associated with the native application;

in response to using a redirect request to redirect a web browser of the computing device to a broker gateway, intercepting, by an authentication server of the computing device, a browser redirect request from the broker gateway;

redirecting, by the authentication server, the web browser to an identity provider using a cached security assertion markup language (“SAML”) authentication request received from the main gateway; and

providing, by the native application, sequentially received partitioned SAML components from the broker gateway assembled into a SAML authentication response to the main gateway.

2. The method of claim 1 , wherein the broker gateway receives the SAML authentication response from the identity provider and partitions the SAML authentication response into a plurality of partitioned components.

3. The method of claim 1 , wherein assembling the partitioned SAML components comprises extracting a portion of the SAML authentication response from a URL corresponding to each of the partitioned SAML component and concatenating the extracted portions of the SAML authentication response.

4. The method of claim 3 , wherein the broker gateway embeds portions of the SAML authentication response into the URLs such that a size of the URL is below the browser URL size limit.

5. The method of claim 1 , wherein the authentication server is initialized within the native application.

6. The method of claim 1 , wherein the redirect request is modified to be directed to the authentication server, and wherein the broker gateway registers a response handler using an authentication server port included within the modified redirect request.

7. The method of claim 1 , wherein the main gateway generates the redirect request in response to receiving the request for access to the server from the native application.

8. The method of claim 7 , wherein the redirect request includes an identify provider (“IdP”) URL.

9. The method of claim 1 , wherein the SAML authentication request is generated by the main gateway in response to a request for an SAML authentication request received from the native application.

10. The method of claim 1 , wherein the native application communicates with the main gateway using a web view of the native application.

11. A non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to perform operations comprising:

requesting, by a computing device via a native application running on the computing device, access to a service from a main gateway of a service provider associated with the native application;

in response to using a redirect request to redirect a web browser of the computing device to a broker gateway, intercepting, by an authentication server of the computing device, a browser redirect request from the broker gateway;

redirecting, by the authentication server, the web browser to an identity provider using a cached security assertion markup language (“SAML”) authentication request received from the main gateway; and

providing, by the native application, sequentially received partitioned SMAL components from the broker gateway assembled into a SAML authentication response to the main gateway.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the broker gateway receives the SAML authentication response from the identity provider and partitions the SAML authentication response into a plurality of partitioned components.

13. The non-transitory computer-readable storage medium of claim 11 , wherein assembling the partitioned SAML components comprises extracting a portion of the SAML authentication response from a URL corresponding to each of the partitioned SAML component and concatenating the extracted portions of the SAML authentication response.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the broker gateway embeds portions of the SAML authentication response into the URLs such that a size of the URL is below the browser URL size limit.

15. The non-transitory computer-readable storage medium of claim 11 , wherein the authentication server is initialized within the native application.

16. The non-transitory computer-readable storage medium of claim 11 , wherein the redirect request is modified to be directed to the authentication server, and wherein the broker gateway registers a response handler using an authentication server port included within the modified redirect request.

17. The non-transitory computer-readable storage medium of claim 11 , wherein the main gateway generates the redirect request in response to receiving the request for access to the server from the native application.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the redirect request includes an identify provider (“IdP”) URL.

19. The non-transitory computer-readable storage medium of claim 11 , wherein the SAML authentication request is generated by the main gateway in response to a request for an SAML authentication request received from the native application.

20. The non-transitory computer-readable storage medium of claim 11 , wherein the native application communicates with the main gateway using a web view of the native application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2023
From: SPECHT, JOEL; ROJAS, MATTHEW
To: INDUCTIVE AUTOMATION, LLC
Reel/Frame 062265/0202 →
Continuity (4)
Continuation 17524595 · Nov 11, 2021
Continuation 17324988 · May 19, 2021
Provisional Application 63131766 · Dec 29, 2020
Related Publication 20230129305A1 · Apr 27, 2023