IP Library Granted Patent US 12,388,821
Granted Patent B1
US 12,388,821 · App. 19/060,693 · Granted Aug 12, 2025

Secure identity provider authentication for native application to access web service

Inventors: Joel Specht (Folsom, CA); Matthew Rojas (Roseville, CA)
Assignee: Inductive Automation, LLC
H04L63/0876H04L63/1425H04L63/20H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,821
App. No.
19/060,693
Granted
Aug 12, 2025
Kind
B1
Abstract

A native application on a client computing device enables secure user authentication via an identity provider (IdP) for accessing services of a web service provider. The native application forwards a redirect request generated by a main gateway of the service provider and including an IdP uniform resource locator (URL) to a system browser of the client computing device. The redirect request directs the system browser to a broker gateway of the service provider that registers an authentication response handler and redirects the system browser to the IdP URL to enable a user of the native client computing device to authenticate. After the broker gateway receives an IdP authentication response from the IdP following authentication by the user, the broker gateway provides the IdP authentication response to the native application for providing back to the main gateway. The main gateway finally processes the authentication response to complete the authentication request.

Claims (32)

1. A method comprising:

receiving, by a broker gateway, a security assertion markup language (“SAML”) authentication request from a client device;

redirecting, by the broker gateway, the client device to an authentication server;

in response to determining that an identity provider has authenticated the SAML request, partitioning, by the broker gateway, a SAML authentication response into SAML components; and

sequentially providing, by the broker gateway, the partitioned SAML components to the client device for re-assembly.

2. The method of claim 1 , wherein the SAML authentication response is received from the identity provider.

3. The method of claim 1 , wherein assembling the partitioned SAML components comprises extracting a portion of the SAML authentication response from a URL corresponding to each of the partitioned SAML components and concatenating the extracted portions of the SAML authentication response.

4. The method of claim 3 , wherein the broker gateway embeds portions of the SAML authentication response into the URLs such that a size of the URL is below the web browser URL size limit.

5. The method of claim 1 , wherein the authentication server is initialized within a native application on the client device.

6. The method of claim 1 , wherein the SAML authentication request is generated by a main gateway in response to a request for an SAML authentication request received from a native application.

7. The method of claim 6 , wherein the native application communicates with the main gateway using a web view of the native application.

8. A non-transitory computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving, by a broker gateway, a security assertion markup language (“SAML”) authentication request from a client device;

redirecting, by the broker gateway, the client device to an authentication server;

in response to determining that an identity provider has authenticated the SAML request, partitioning, by the broker gateway, a SAML authentication response into SAML components; and

sequentially providing, by the broker gateway, the partitioned SAML components to the client device for re-assembly.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the SAML authentication response is received from the identity provider.

10. The non-transitory computer-readable storage medium of claim 8 , wherein assembling the partitioned SAML components comprises extracting a portion of the SAML authentication response from a URL corresponding to each of the partitioned SAML components and concatenating the extracted portions of the SAML authentication response.

11. The non-transitory computer-readable storage medium of claim 10 , wherein the broker gateway embeds portions of the SAML authentication response into the URLs such that a size of the URL is below the web browser URL size limit.

12. The non-transitory computer-readable storage medium of claim 8 , wherein the authentication server is initialized within a native application on the client device.

13. The non-transitory computer-readable storage medium of claim 8 , wherein the SAML authentication request is generated by a main gateway in response to a request for an SAML authentication request received from a native application.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the native application communicates with the main gateway using a web view of the native application.

15. A system comprising a hardware processor and a non-transitory computer-readable storage medium storing executable instructions that, when executed by the hardware processor, cause the system to perform steps comprising:

receiving, by a broker gateway, a security assertion markup language (“SAML”) authentication request from a client device;

redirecting, by the broker gateway, the client device to an authentication server;

in response to determining that an identity provider has authenticated the SAML request, partitioning, by the broker gateway, a SAML authentication response into SAML components; and

sequentially providing, by the broker gateway, the partitioned SAML components to the client device for re-assembly.

16. The system of claim 15 , wherein the SAML authentication response is received from the identity provider.

17. The system of claim 15 , wherein assembling the partitioned SAML components comprises extracting a portion of the SAML authentication response from a URL corresponding to each of the partitioned SAML components and concatenating the extracted portions of the SAML authentication response.

18. The system of claim 17 , wherein the broker gateway embeds portions of the SAML authentication response into the URLs such that a size of the URL is below the web browser URL size limit.

19. The system of claim 15 , wherein the authentication server is initialized within a native application on the client device.

20. The system of claim 15 , wherein the SAML authentication request is generated by a main gateway in response to a request for an SAML authentication request received from a native application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2025
From: SPECHT, JOEL; ROJAS, MATTHEW
To: INDUCTIVE AUTOMATION, LLC
Reel/Frame 071241/0491 →
Continuity (7)
Continuation 18946943 · Nov 14, 2024
Continuation 18661618 · May 11, 2024
Continuation 18411622 · Jan 12, 2024
Continuation 18088561 · Dec 24, 2022
Continuation 17524595 · Nov 11, 2021
Continuation 17324988 · May 19, 2021
Provisional Application 63131766 · Dec 29, 2020
References Cited (14)
US 6704873B1 · Underwood · 2004 [cited by examiner]
US 8200971B2 · Edwards · 2012 [cited by examiner]
US 9009848B2 · Orsini · 2015 [cited by examiner]
US 11558383B1 · Au Yeung · 2023 [cited by examiner]
US 20060080352A1 · Boubez · 2006 [cited by examiner]
US 20080098453A1 · Hinton · 2008 [cited by examiner]
US 20160191509A1 · Bestler · 2016 [cited by examiner]
US 20170339070A1 · Chang · 2017 [cited by examiner]
US 20180109506A1 · Helsen · 2018 [cited by examiner]
US 20200267146A1 · Nambiar · 2020 [cited by examiner]
United States Office Action, U.S. Appl. No. 18/088,561, filed Aug. 15, 2023, nine pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 18/411,622, filed Mar. 27, 2024, eight pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 18/661,618, filed Jul. 17, 2024, nine pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 18/946,943, filed Dec. 26, 2024, eight pages. [cited by applicant]