IP Library Granted Patent US 12,556,528
Granted Patent B2
US 12,556,528 · App. 18/404,962 · Granted Feb 17, 2026

Application user single sign-on

Inventors: Eui Chung (Seattle, WA); Jen-Hao Yang (Schaumburg, IL); Bharath Sridharan (Hoffman Estates, IL); Jim Pier (Highland Village, TX)
Assignee: TRANSFORM SR BRANDS LLC
H04L63/0815G06F21/41G06F21/604G06F21/629G06F21/78H04L63/0807H04L63/083H04L63/0884H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,528
App. No.
18/404,962
Granted
Feb 17, 2026
Kind
B2
Abstract

Systems and methods are disclosed for accessing protected data. A computing device may have a secured stared storage accessible by two or more applications operating on the mobile device. The computing device may obtain a first token from an authorization service to verify user identity for a first application. The first token may be stored in the shared storage area, and be accessible to one or more applications sharing the storage space. In response to a user attempt to access a web service using a second application, the user identity may be verified using the first token. The authorization service may verify user credentials, and send a second token to the computing device. The second token may be a proxy ticket authorizing access and exchange of protected data between the second application and a web service. The second token may also be stored in the secure storage area.

Claims (49)

1 . A system comprising:

a secure storage;

a processor; and

a memory configured to store a set of instructions that, when executed by the processor, cause the system to:

obtain a first token, associated with a user identity for accessing a first application, from a key store configured exclusively for storing cryptographic keys, the key store being hardware-backed and inaccessible for arbitrary identity tokens or application data;

store the first token in the secure storage;

send, to an authorization service, the first token and an identifier of a second application, wherein the identifier of the second application is passed as a parameter to a dynamically constructed authentication URL to enable access for the second application;

receive, from the authorization service, a second token authorizing communication with the second application, wherein the second token is associated with a stronger authentication process than the first token;

replace the first token by overwriting the first token in secure storage with the second token; and

invalidate the first token by transmitting a revocation instruction to the authorization service to disable server-side use of the first token and securely erasing the first token from the secure storage.

2 . The system of claim 1 , wherein the instructions cause the system to:

receive user credentials for a login to the first application;

send the user credentials to the authorization service; and

verify the user credentials at the authorization service.

3 . The system of claim 1 , wherein the secure storage is a keychain on an operating system of the computing device.

4 . The system of claim 1 , wherein the secure storage is shared between two or more applications on the computing device.

5 . The system of claim 1 , wherein at least one of the tokens are valid for a predetermined period of time.

6 . The system of claim 1 , wherein the first token is a proxy granting ticket (PGT).

7 . The system of claim 1 , wherein the second token is a proxy ticket (PT).

8 . A method comprising:

obtaining a first token, associated with a user identity for accessing a first application on a computing device, from a key store configured exclusively for storing cryptographic keys, the key store being hardware-backed and inaccessible for arbitrary identity tokens or application data;

storing the first token in a secure storage on the computing device;

sending, to an authorization service, the first token and an identifier of a second application, wherein the identifier of the second application is passed as a parameter to a dynamically constructed authentication URL to enable access for the second application;

receiving, from the authorization service, a second token authorizing communication with the second application, wherein the second token is associated with a stronger authentication process than the first token;

replacing the first token by overwriting the first token in secure storage with the second token; and

invalidating the first token by transmitting a revocation instruction to the authorization service to disable server-side use of the first token and securely erasing the first token from the secure storage.

9 . The method of claim 8 , comprising:

determining whether the first token is available in the secure storage; and

requesting user credentials if the token is unavailable.

10 . The method of claim 8 , wherein the first token is a proxy granting ticket and the second token is a proxy ticket.

11 . The method of claim 8 , comprising entering a user name and password to obtain the token.

12 . The method of claim 8 , wherein the secure storage is a keychain on an operating system of the computing device.

13 . The method of claim 8 , wherein the secure storage is shared between two or more applications on the computing device.

14 . The method of claim 8 , wherein authorizing a communication with the second application comprises establishing a session for a period of time.

15 . A non-transitory computer-readable storage medium comprising instructions stored thereon that, when executed by a computing device, cause the computing device to at least:

obtain a first token, associated with a user identity for accessing a first application, from a key store configured exclusively for storing cryptographic keys, the key store being hardware-backed and inaccessible for arbitrary identity tokens or application data;

store the first token in a secure storage;

send, to an authorization service, the first token and an identifier of a second application, wherein the identifier of the second application is passed as a parameter to a dynamically constructed authentication URL to enable access for the second application;

receive, from the authorization service, a second token authorizing communication with the second application, wherein the second token is associated with a stronger authentication process than the first token;

replace the first token by overwriting the first token in secure storage with the second token; and

invalidate the first token by transmitting a revocation instruction to the authorization service to disable server-side use of the first token and securely erasing the first token from the secure storage.

16 . The non-transitory computer-readable storage medium of claim 15 , comprising instructions to:

receive user credentials for a log in to the first application;

send the user credentials to the authorization service; and

verify the user credentials at the authorization service.

17 . The non-transitory computer-readable storage medium of claim 15 , wherein the secure storage is a keychain on an operating system of the computing device.

18 . The non-transitory computer-readable storage medium of claim 15 , wherein the secure storage is shared between two or more applications on the computing device.

19 . The non-transitory computer-readable storage medium of claim 15 , wherein at least one of the tokens are valid for a predetermined period of time.

20 . The non-transitory computer-readable storage medium of claim 15 , wherein the first token is a proxy granting ticket and the second token is a proxy ticket.

Assignments (2)
SECURITY INTEREST Recorded Apr 10, 2024
From: TRANSFORM SR BRANDS LLC
To: JPP, LLC, AS AGENT
Reel/Frame 067063/0523 →
SECURITY INTEREST Recorded Apr 10, 2024
From: TRANSFORM SR BRANDS LLC
To: CANTOR FITZGERALD SECURITIES, AS AGENT
Reel/Frame 067063/0561 →
Continuity (4)
Continuation 18113556 · Feb 23, 2023
Continuation 15999154 · Aug 17, 2018
Provisional Application 62547667 · Aug 18, 2017
Related Publication 20240137357A1 · Apr 25, 2024
References Cited (9)
US 20080127323A1 · Soin et al. · 2008 [cited by applicant]
US 20140082715A1 · Grajek · 2014 [cited by examiner]
US 20140250511A1 · Kendall · 2014 [cited by applicant]
US 20170006020A1 · Fallodiya · 2017 [cited by applicant]
Int'l Search Report and Written Opinion Appln No. PCT/US2018/000297 mailed Nov. 5, 2018. [cited by applicant]
“How to share Keychain between iOS apps”; http://evgenii.com/blog/sharing-keychain-in-ios/; accessed May 8, 2019. [cited by applicant]
“262 code results in DrKLO/Telegran”; https://github.com/DrKLO/Telegram/search?utf8=%E2%9C%93&q-account; GitHub, Inc .; 2019; accessed May 8, 2019. [cited by applicant]
“AccountManager”; https://developer.android.com/reference/android/accounts/AccountManager.html; accessed May 8, 2019. [cited by applicant]
“Create a custom account type”; https://developer.android.com/training/id-auth/custom_auth.html; accessed May 8, 2019. [cited by applicant]