IP Library › Granted Patent US 10,511,670
Granted Patent B2
US 10,511,670 · App. 15/387,475 · Granted Dec 17, 2019

Techniques for providing authentication information to external and embedded web browsers

Inventor: Hui Wang (San Mateo, CA)
Assignee: Apple Inc.
H04L67/141G06F21/10G06F21/64H04L9/32H04L63/08H04L63/0807H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,511,670
App. No.
15/387,475
Granted
Dec 17, 2019
Kind
B2
Abstract

Representative embodiments set forth herein disclose techniques for enabling a client application to supplement its features by utilizing the functionalities provided by a web browser in a secure manner. According to some embodiments, the client application can authenticate with an authentication server to establish a trusted connection between the client application and the authentication server. In turn, the client application can issue a request to the authentication server for particular content. Next, the authentication server can establish a “content uniform resource locator (URL)” for accessing the content, and interface with a web server to establish an “authentication URL”, and return both the content URL and the authentication URL to the client application. In turn, the client application invokes an instance of the web browser and causes the web browser to access the authentication URL to obtain session information, and subsequently access the content URL to obtain the content.

Claims (64)

1. A method for enabling a client application executing on a remote computing device to access content hosted by a content provider, the method comprising, at an authentication server:

receiving, from the client application, a first request to access the content, wherein the first request includes an authorization token; and

in response to validating the authorization token:

generating a content uniform resource locator (URL) for accessing the content, wherein the content URL references the content;

issuing, to a web server associated with the content provider, a second request for an authentication URL;

receiving, from the web server, the authentication URL, wherein the authentication URL is associated with a session ID and a session cookie that are generated by the web server; and

providing the authentication URL and the content URL to the client application, wherein the client application, in conjunction with receiving the authentication URL and the content URL, causes a web browser executing on the remote computing device to:

(1) obtain the session cookie from the web server in response to the web server validating the authentication URL and the session ID, wherein the session cookie includes authentication information that enables the content to be accessed via the content URL, and

(2) access the content from the web server by way of the content URL and the session cookie.

2. The method of claim 1 , further comprising, prior to receiving the first request:

receiving and authorizing credentials provided by the client application; and

providing the authorization token to the client application.

3. The method of claim 1 , further comprising:

receiving, from the web server, a request to validate the authentication URL; and

when the authentication URL is valid:

indicating, to the web server, that the authentication URL is valid; and

invalidating the authentication URL to prevent future requests received by way of the authentication URL from being validated.

4. The method of claim 1 , wherein the content URL expires when the web browser accesses the content URL.

5. The method of claim 1 , wherein the web browser is embedded within the client application or is external to the client application.

6. The method of claim 1 , wherein the session cookie is based on the authentication URL.

7. At least one non-transitory computer readable storage medium configured to store instructions that, when executed by at least one processor included in an authentication server, cause the authentication server to enable a client application executing on a remote computing device to access content hosted by a content provider, by carrying out steps that include:

receiving, from the client application, a first request to access the content, wherein the first request includes an authorization token; and

in response to validating the authorization token:

generating a content uniform resource locator (URL) for accessing the content, wherein the content URL references the content;

issuing, to a web server associated with the content provider, a second request for an authentication URL;

receiving, from the web server, the authentication URL, wherein the authentication URL is associated with a session ID and a session cookie that are generated by the web server; and

providing the authentication URL and the content URL to the client application, wherein the client application, in conjunction with receiving the authentication URL and the content URL, causes a web browser executing on the remote computing device to:

(1) obtain the session cookie from the web server in response to the web server validating the authentication URL and the session ID, wherein the session cookie includes authentication information that enables the content to be accessed via the content URL, and

(2) access the content from the web server by way of the content URL and the session cookie.

8. The at least one non-transitory computer readable storage medium of claim 7 , wherein the steps further include, prior to receiving the first request:

receiving and authorizing credentials provided by the client application; and

providing the authorization token to the client application.

9. The at least one non-transitory computer readable storage medium of claim 7 , wherein the steps further include:

receiving, from the web server, a request to validate the authentication URL; and

when the authentication URL is valid:

indicating, to the web server, that the authentication URL is valid; and

invalidating the authentication URL to prevent future requests received by way of the authentication URL from being validated.

10. The at least one non-transitory computer readable storage medium of claim 7 , wherein the content URL expires when the web browser accesses the content URL.

11. The at least one non-transitory computer readable storage medium of claim 7 , wherein the web browser is embedded within the client application or is external to the client application.

12. The at least one non-transitory computer readable storage medium of claim 7 , wherein the session cookie is based on the authentication URL.

13. The at least one non-transitory computer readable storage medium of claim 7 , wherein the content provider provides the content to the client application in response to verifying the session cookie.

14. An authentication server configured to enable a client application executing on a remote computing device to access content hosted by a content provider, the authentication server comprising:

at least one processor; and

at least one memory configured to store instructions that, when executed by the at least one processor, cause the authentication server to:

receive, from the client application, a first request to access the content, wherein the first request includes an authorization token; and

in response to validating the authorization token:

generate a content uniform resource locator (URL) for accessing the content, wherein the content URL references the content;

issue, to a web server associated with the content provider, a second request for an authentication URL;

receive, from the web server, the authentication URL, wherein the authentication URL is associated with a session ID and a session cookie that are generated by the web server; and

provide the authentication URL and the content URL to the client application, wherein the client application, in conjunction with receiving the authentication URL and the content URL, causes a web browser executing on the remote computing device to:

(1) obtain the session cookie from the web server in response to the web server validating the authentication URL and the session ID, wherein the session cookie includes authentication information that enables the content to be accessed via the content URL, and

(2) access the content from the web server by way of the content URL and the session cookie.

15. The authentication server of claim 14 , wherein the at least one processor further causes the authentication server to, prior to receiving the first request:

receive and authorizing credentials provided by the client application; and

provide the authorization token to the client application.

16. The authentication server of claim 14 , wherein the at least one processor further causes the authentication server to:

receive, from the web server, a request to validate the authentication URL; and

when the authentication URL is valid:

indicate, to the web server, that the authentication URL is valid; and

invalidate the authentication URL to prevent future requests received by way of the authentication URL from being validated.

17. The authentication server of claim 14 , wherein the content URL expires when the web browser accesses the content URL.

18. The authentication server of claim 14 , wherein the web browser is embedded within the client application or is external to the client application.

19. The authentication server of claim 14 , wherein the session cookie is based on the authentication URL.

20. The authentication server of claim 14 , wherein the content provider provides the content to the client application in response to verifying the session cookie.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2017
From: WANG, HUI
To: APPLE INC.
Reel/Frame 041011/0439 →
Continuity (1)
Related Publication 20180176203A1 · Jun 21, 2018