IP Library Granted Patent US 11,652,613
Granted Patent B2
US 11,652,613 · App. 17/012,207 · Granted May 16, 2023

Secure information exchange in federated authentication

Inventors: Dileep Reddem (Hyderabad, IN); Ricardo Fernando Feijoo (Davie, FL)
Assignee: Citrix Systems, Inc.
H04L9/0825H04L9/085H04L9/0866H04L9/3213H04L9/3226
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,652,613
App. No.
17/012,207
Granted
May 16, 2023
Kind
B2
Abstract

Methods, apparatuses, systems, and computer-readable mediums for sharing user credentials in federated authentication are described herein. An identity provider may receive a user credential from a user device. The identity provider may receive, from a relying party, a request for an access token. The identity provider may encrypt the user credential based on a nonce that is uniquely generated for the relying party. The identity provider may send a response to the relying party. The response may include the access token, the encrypted user credential, and the nonce.

Claims (45)

1. A method comprising:

receiving, by an identity provider and from a user device, a user credential;

receiving, by the identity provider and from a relying party, a request for an access token, the request comprising a client secret associated with the relying party;

encrypting, based on a nonce that is uniquely generated for the relying party, the user credential; and

sending, to the relying party, a response to the request, the response comprising the access token, the encrypted user credential, and the nonce;

wherein the encrypting the user credential comprises:

generating, based on the client secret and the nonce, a key, wherein the client secret is associated with the relying party, and

encrypting, based on the key, the user credential; and

wherein generating the key comprises performing a password-based key derivation function, for a predetermined quantity of iterations, on the client secret and the nonce.

2. The method of claim 1 , wherein the encrypting the user credential is further based on a successful authentication, by the identity provider and using the user credential, of a user associated with the user device.

3. The method of claim 1 , further comprising:

generating, by the identity provider, the client secret that is unique to the relying party; and

sending, to the relying party, the client secret.

4. The method of claim 1 , wherein the request comprises a token request that is in accordance with an OpenID connect authorization code flow.

5. The method of claim 1 , wherein the response comprises at least one of a JavaScript Object Notation Web Token (JWT) message or a JavaScript Object Notation Web Encryption (JWE) message.

6. An identity provider comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the identity provider to:

receive, from a relying party, a request for an access token, the request comprising a client secret associated with the relying party;

receive, from a user device, a user credential;

encrypt, based on a nonce that is uniquely generated for the relying party, the user credential; and

send, to the relying party, a response to the request, the response comprising the access token, the encrypted user credential, and the nonce;

wherein the instructions, when executed by the one or more processors, cause the identity provider to encrypt the user credential by:

generating, based on the client secret and the nonce, a key, wherein the client secret is associated with the relying party; and

encrypting, based on the key, the user credential; and

wherein the instructions, when executed by the one or more processors, cause the identity provider to generate the key by performing a password-based key derivation function, for a predetermined quantity of iterations, on the client secret and the nonce.

7. The identity provider of claim 6 , wherein the instructions, when executed by the one or more processors, cause the identity provider to encrypt the user credential further based on a successful authentication, by the identity provider and using the user credential, of a user associated with the user device.

8. The identity provider of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the identity provider to:

generate the client secret that is unique to the relying party; and

send, to the relying party, the client secret.

9. The identity provider of claim 6 , wherein the request comprises a token request that is in accordance with an OpenID connect authorization code flow.

10. The identity provider of claim 6 , wherein the response comprises at least one of a JavaScript Object Notation Web Token (JWT) message or a JavaScript Object Notation Web Encryption (JWE) message.

11. A non-transitory computer-readable medium storing instructions, when executed by a computing device, cause the computing device to:

receive, from a relying party, a request for an access token, the request comprising a client secret associated with the relying party;

receive, from a user device, a user credential;

encrypt, based on a nonce that is uniquely generated for the relying party, the user credential; and

send, to the relying party, a response to the request, the response comprising the access token, the encrypted user credential, and the nonce;

wherein the instructions, when executed by the computing device, cause the computing device to encrypt the user credential by:

generating, based on the client secret and the nonce, a key, wherein the client secret is associated with the relying party, and

encrypting, based on the key, the user credential; and

wherein the instructions, when executed by the computing device, cause the computing device to generate the key by performing a password-based key derivation function, for a predetermined quantity of iterations, on the client secret and the nonce.

12. The non-transitory computer-readable medium of claim 11 , wherein the instructions, when executed by the computing device, cause the computing device to encrypt the user credential further based on a successful authentication, using the user credential, of a user associated with the user device.

13. The non-transitory computer-readable medium of claim 11 , wherein the request comprises a token request that is in accordance with an OpenID connect authorization code flow.

14. The non-transitory computer-readable medium of claim 11 , wherein the request comprises a token request that is in accordance with an OpenID connect authorization code flow, and

wherein the response comprises at least one of a JavaScript Object Notation Web Token (JWT) message or a JavaScript Object Notation Web Encryption (JWE) message.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2021
From: REDDEEM, DILEEP; FEIJOO, RICARDO FERNANDO
To: CITRIX SYSTEMS, INC.
Reel/Frame 057493/0171 →
Continuity (1)
Related Publication 20220078007A1 · Mar 10, 2022