IP Library Granted Patent US 9,749,310
Granted Patent B2
US 9,749,310 · App. 14/670,955 · Granted Aug 29, 2017

Technologies for authentication and single-sign-on using device security assertions

Inventors: Hong Li (El Dorado Hills, CA); Suman Sharma (San Jose, CA); John B. Vicente (Roseville, CA); Luis A. Gimenez (Granite Bay, CA); Carlton D. Ashley (Folsom, CA); Navneet Malpani (Phoenix, AZ)
Assignee: Intel Corporation
H04L63/0815G06F21/41G06F21/44H04L63/10H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,749,310
App. No.
14/670,955
Granted
Aug 29, 2017
Kind
B2
Abstract

Technologies for remote device authentication include a client computing device, an identity provider, and an application server in communication over a network. The identity provider sends an authentication challenge to the client. A capability proxy of the client intercepts an authentication challenge response and retrieves one or more security assertions from a secure environment of the client computing device. The capability proxy may be an embedded web server providing an HTTP interface to platform features of the client. The client sends a resource access token based on the security assertions to the identity provider. The identity provider verifies the resource access token and authenticates the client computing device based on the resource access token in addition to user authentication factors such as username and password. The identity provider sends an authentication response to the client, which forwards the authentication response to the application server. Other embodiments are described and claimed.

Claims (53)

1. A computing device for remote device authentication, the computing device comprising:

a user authentication module to:

receive an authentication challenge from an identity provider; and

generate an authentication challenge response to authenticate a user of the computing device in response to receipt of the authentication challenge; and

a device capability module to:

intercept the authentication challenge response in response to generation of the authentication challenge response;

retrieve a security assertion from a secure environment of the computing device in response to interception of the authentication challenge response;

generate a resource access token as a function of the security assertion; and

transmit the authentication challenge response including the resource access token to the identity provider;

wherein the device capability module comprises an embedded technology access server of the computing device;

wherein to retrieve the security assertion comprises to (i) issue an HTTP request to the embedded technology access server and (ii) retrieve, by the embedded technology access server, the security assertion in response to issuance of the HTTP request; and

wherein the computing device further comprises a manageability engine to execute the embedded technology access server.

2. The computing device of claim 1 , wherein:

to receive the authentication challenge from the identity provider comprises to receive the authentication challenge via a public network connection with the identity provider; and

to transmit the authentication challenge response comprises to transmit the authentication challenge response via the public network connection.

3. The computing device of claim 1 , wherein:

the authentication challenge comprises an interactive form; and

to intercept the authentication challenge response comprises to intercept a submit action of the interactive form.

4. The computing device of claim 1 , wherein to retrieve the security assertion from the secure environment comprises to retrieve the security assertion from a manageability engine of the computing device.

5. The computing device of claim 1 , wherein the security assertion comprises an indication that the computing device is subject to a device management policy.

6. The computing device of claim 1 , wherein the security assertion comprises a device trust level assertion associated with the computing device.

7. One or more computer-readable storage media comprising a plurality of instructions that in response to being executed cause a computing device to:

receive an authentication challenge from an identity provider;

generate an authentication challenge response to authenticate a user of the computing device in response to receiving the authentication challenge;

intercept, by a device capability module of the computing device, the authentication challenge response in response to generating the authentication challenge response;

retrieve, by the device capability module, a security assertion from a secure environment of the computing device in response to intercepting the authentication challenge response, wherein to retrieve the security assertion comprises to (i) issue an HTTP request to an embedded technology access server of the computing device and (ii) retrieve, by the embedded technology access server, the security assertion in response to issuing the HTTP request;

generate, by the device capability module, a resource access token as a function of the security assertion;

transmit, by the device capability module, the authentication challenge response including the resource access token to the identity provider; and

execute, by a manageability engine of the computing device, the embedded technology access server.

8. The one or more computer-readable storage media of claim 7 , wherein:

to receive the authentication challenge from the identity provider comprises to receive the authentication challenge via a public network connection with the identity provider; and

to transmit the authentication challenge response comprises to transmit the authentication challenge response via the public network connection.

9. The one or more computer-readable storage media of claim 7 , wherein:

to receive the authentication challenge comprises to receive an interactive form from the identity provider; and

to intercept the authentication challenge response comprises to intercept a submit action of the interactive form.

10. The one or more computer-readable storage media of claim 7 , wherein to retrieve the security assertion comprises to retrieve an indication that the computing device is subject to a device management policy.

11. The one or more computer-readable storage media of claim 7 , wherein to retrieve the security assertion comprises to retrieve a device trust level assertion associated with the computing device.

12. A method for remote device authentication, the method comprising:

receiving, by a computing device, an authentication challenge from an identity provider;

generating, by the computing device, an authentication challenge response to authenticate a user of the computing device in response to receiving the authentication challenge;

intercepting, by a device capability module of the computing device, the authentication challenge response in response to generating the authentication challenge response;

retrieving, by the device capability module, a security assertion from a secure environment of the computing device in response to intercepting the authentication challenge response, wherein retrieving the security assertion comprises (i) issuing an HTTP request to an embedded technology access server of the computing device and (ii) retrieving, by the embedded technology access server, the security assertion in response to issuing the HTTP request;

generating, by the device capability module, a resource access token as a function of the security assertion;

transmitting, by the device capability module, the authentication challenge response including the resource access token to the identity provider; and

executing, by a manageability engine of the computing device, the embedded technology access server.

13. The method of claim 12 , wherein:

receiving the authentication challenge from the identity provider comprises receiving the authentication challenge via a public network connection with the identity provider; and

transmitting the authentication challenge response comprises transmitting the authentication challenge response via the public network connection.

14. The method of claim 12 , wherein:

receiving the authentication challenge comprises receiving an interactive form from the identity provider; and

intercepting the authentication challenge response comprises intercepting a submit action of the interactive form.

15. The method of claim 12 , wherein retrieving the security assertion comprises retrieving an indication that the computing device is subject to a device management policy.

16. The method of claim 12 , wherein retrieving the security assertion comprises retrieving a device trust level assertion associated with the computing device.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE FOURTH INVENTOR NAME PREVIOUSLY RECORDED AT REEL: 040808 FRAME: 0960. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 30, 2017
From: LI, HONG; SHARMA, SUMAN; VICENTE, JOHN B.; GIMENEZ, LUIS A.; ASHLEY, CARLTON D.; MALPANI, NAVNEET
To: INTEL CORPORATION
Reel/Frame 042373/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2016
From: LI, HONG; SHARMA, SUMAN; VICENTE, JOHN B.; GMINEZ, LUIS A.; ASHLEY, CARLTON D.; MALPANI, NAVNEET
To: INTEL CORPORATION
Reel/Frame 040808/0960 →
Continuity (1)
Related Publication 20160285858A1 · Sep 29, 2016