IP Library Granted Patent US 10,356,079
Granted Patent B2
US 10,356,079 · App. 15/368,943 · Granted Jul 16, 2019

System and method for a single sign on connection in a zero-knowledge vault architecture

Inventors: Craig B. Lurey (El Dorado Hills, CA); Darren S. Guccione (Chicago, IL)
Assignee: KEEPER SECURITY, INC.
H04L63/0815G06F21/41G06F21/602H04L63/083H04L67/02H04W12/06H04L63/0823H04L63/168H04L67/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,356,079
App. No.
15/368,943
Granted
Jul 16, 2019
Kind
B2
Abstract

A system and/or method include a connect module for facilitating a single sign-on to a digital vault provided by a service provider in a zero-knowledge architecture.

Claims (32)

1. A computer-implemented method for facilitating a single sign-on to a digital vault provided by a service provider, comprising:

detecting by a connect module a login attempt, where the login attempt is from an application provided by the service provider and stored local to a client device;

performing by the connect module a redirect and sending the client device to authenticate on an identity provider with one or more login credentials;

receiving by the connect module via a security protocol an authentication of the client device from the identity provider, without receiving an encryption key; and

providing by the connect module a master password to the application local to the client device in response to the authentication, where the master password decrypts the digital vault without the service provider knowing the master password

encoding the master password in the redirect within a fragment identifier of a universal resource locator, or embedding the master password within the HTML body of the response to the authentication, or embedding the master password inside a Javascript code section within the response to the authentication;

reading, by the client application, the master password from the response to the authentication, and deriving an encryption key using a password derivation function; and

wherein the client application uses the encryption key to log the client device into the digital vault and decrypt the digital vault.

2. The computer-implemented method of claim 1 , wherein the identity provider is configured within the connect module.

3. The computer-implemented method of claim 1 , wherein the connect module is hosted by at least one of an enterprise network, client-side on-premise server, or a cloud hosting provider not operated by the service provider.

4. The computer-implemented method of claim 3 , wherein the master password is stored in an encrypted format on the enterprise network, the client-side on-premise server, or the cloud hosting provider.

5. The computer-implemented method of claim 1 , wherein the identity provider is configured within the connect module.

6. The computer-implemented method of claim 1 , wherein the connect module is opened with a determined Internet protocol address or hostname.

7. The computer-implemented method of claim 1 , wherein the redirect comprises an Hypertext Transfer Protocol Secure redirect.

8. The computer-implemented method of claim 1 , wherein information stored in the digital vault is instantly encrypted and decrypted on-the-fly on the client device even when using the client application provided by the service provider.

9. The computer-implemented method of claim 1 , wherein the digital vault is able to authenticate the client device and decrypt data for the client device without the identity provider or service provider having access to the encryption key.

10. The computer-implemented method of claim 1 , further including administering users of the connect module.

11. The computer-implemented method of claim 1 , wherein the digital vault at least one of securely stores, protects, manages and shares passwords, documents, digital assets and photos.

12. A computer-implemented method for facilitating a single sign-on to a digital vault provided by a service provider, comprising:

detecting by a connect module a login attempt, where the login attempt is from an application provided by the service provider and stored local to a client device;

performing by the connect module a redirect and sending the client device to authenticate on an identity provider with one or more login credentials;

receiving by the connect module via a security protocol an authentication of the client device from the identity provider, without receiving an encryption key;

providing by the connect module a master password to the application local to the client device in response to the authentication, where the master password decrypts the digital vault without the service provider knowing the master password, wherein the master password is sent via the redirect directly to the client application;

encoding the master password in the redirect within a fragment identifier of a universal resource locator, or embedding the master password within the HTML body of the response to the authentication, or embedding the master password inside a Javascript code section within the response to the authentication; and

reading, by the client application, the master password from the response to the authentication, and deriving an encryption key using a password derivation function, the client application using the encryption key to log the client device into the digital vault and decrypt the digital vault.

13. The computer-implemented method of claim 12 , wherein the redirect comprises at least one of a Hypertext Transfer Protocol Secure protocol and a push notification.

14. The computer-implemented method of claim 12 , wherein the fragment identifier is not transmitted beyond a scope of the redirect, and remains stored within a memory of the client device so as not to be accessible by the service provider.

15. The computer-implemented method of claim 12 , wherein the encryption key is not stored or transmitted to the digital vault.

16. The computer-implemented method of claim 12 , wherein the connect module is further configured to receive an authentication of the client device via a security protocol from the identity provider, without receiving an encryption key.

17. The computer-implemented method of claim 12 , wherein the connect module is hosted by at least one of an enterprise network, client-side on-premise server, or a cloud hosting provider not operated by the service provider.

18. The computer-implemented method of claim 12 , wherein the master password is not transmitted beyond a scope of the redirect, and remains stored within a memory of the client device so as not to be accessible by the service provider.

19. The computer-implemented method of claim 12 , further comprising the client application reading the master password from a response of the connect module, and deriving an encryption key using a password derivation function.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2016
From: LUREY, CRAIG B.; GUCCIONE, DARREN S.
To: KEEPER SECURITY, INC.
Reel/Frame 040521/0751 →
Continuity (1)
Related Publication 20180159842A1 · Jun 7, 2018
Cited By (6)
US 12,190,327 US 12,205,076 US 12,333,623 US 12,346,984 US 12,353,482 US 12,657,589