IP Library › Granted Patent US 12,199,970
Granted Patent B2
US 12,199,970 · App. 17/377,294 · Granted Jan 14, 2025

Cryptographic binding of native application and external browser sessions

Inventors: Danxiang Li (Arlington, MA); Vincent Parla (North Hampton, NH); Andrzej Kielbasinski (Grafton, MA); Dany Jacques Rochefort (Norfolk, MA)
Assignee: Cisco Technology, Inc.
H04L63/0815G06F21/602H04L9/3066H04L63/0272H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,970
App. No.
17/377,294
Granted
Jan 14, 2025
Kind
B2
Abstract

Systems and methods are provided for receiving information associated with a final single sign-on page from a native browser, extracting a public key from the information associated with the final single sign-on page, generating a single sign-on token to bind a browser session and a native application session, associating the single sign-on token with the public key extracted from the information associated with the final single sign-on page, and encrypting the single sign-on token with the public key to bind the browser session and the native application session.

Claims (36)

1. A computer-implemented method comprising:

receiving, at a server, information associated with a final single sign-on page from a native browser;

extracting, by the server, a public key from the information associated with the final single sign-on page from an HTTP cookie associated with the final single sign-on page;

determining whether the public key matches an active VPN authentication key;

generating, by the server, a single sign-on token to bind a browser session and a native application session;

associating, by the server, the single sign-on token with the public key extracted from the information associated with the final single sign-on page; and

encrypting, by the server, the single sign-on token with the public key to bind the browser session and the native application session.

2. The computer-implemented method of claim 1 , wherein the single sign-on token is a Security Assertion Markup Language authentication token.

3. The computer-implemented method of claim 1 , wherein the browser session is an external transport layer security browser session and the native application session is a native application transport layer security session.

4. The computer-implemented method of claim 1 , wherein the encrypting of the single sign-on token is based on an encryption scheme including at least one of Elliptic Curve Diffie-Hellman (ECDH), Elliptic Curve Integrated Encryption Scheme (ECIES), and Hybrid Public Key Encryption (HPKE).

5. The computer-implemented method of claim 1 , wherein the encrypting of the single sign-on token includes encrypting additional metadata associated with the single sign-on token.

6. A system comprising:

one or more processors; and

at least one computer-readable storage medium having stored therein instructions which, when executed by the one or more processors, cause the system to:

receive information associated with a final single sign-on page from a native browser;

extract a public key from the information associated with the final single sign-on page from an HTTP cookie associated with the final single sign-on page;

determine whether the public key matches an active VPN authentication key;

generate a single sign-on token to bind a browser session and a native application session;

associate the single sign-on token with the public key extracted from the information associated with the final single sign-on page; and

encrypt the single sign-on token with the public key to bind the browser session and the native application session.

7. The system of claim 6 , wherein the single sign-on token is a Security Assertion Markup Language authentication token.

8. The system of claim 6 , wherein the browser session is an external transport layer security browser session and the native application session is a native application transport layer security session.

9. The system of claim 6 , wherein the encrypting of the single sign-on token is based on an encryption scheme including at least one of Elliptic Curve Diffie-Hellman (ECDH), Elliptic Curve Integrated Encryption Scheme (ECIES), and Hybrid Public Key Encryption (HPKE).

10. The system of claim 6 , wherein the encrypting of the single sign-on token includes encrypting additional metadata associated with the single sign-on token.

11. A non-transitory computer-readable storage medium comprising:

instructions stored on the non-transitory computer-readable storage medium, the instructions, when executed by one or more processors, cause the one or more processors to:

receive information associated with a final single sign-on page from a native browser;

extract a public key from the information associated with the final single sign-on page from an HTTP cookie associated with the final single sign-on page;

determine whether the public key matches an active VPN authentication key;

generate a single sign-on token to bind a browser session and a native application session;

associate the single sign-on token with the public key extracted from the information associated with the final single sign-on page; and

encrypt the single sign-on token with the public key to bind the browser session and the native application session.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the single sign-on token is a Security Assertion Markup Language authentication token.

13. The non-transitory computer-readable storage medium of claim 11 , wherein the browser session is an external transport layer security browser session and the native application session is a native application transport layer security session.

14. The non-transitory computer-readable storage medium of claim 11 , wherein the encrypting of the single sign-on token is based on an encryption scheme including at least one of Elliptic Curve Diffie-Hellman (ECDH), Elliptic Curve Integrated Encryption Scheme (ECIES), and Hybrid Public Key Encryption (HPKE).

15. The non-transitory computer-readable storage medium of claim 11 , wherein the encrypting of the single sign-on token includes encrypting additional metadata associated with the single sign-on token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2021
From: LI, DANXIANG; PARLA, VINCENT; KIELBASINSKI, ANDRZEJ; ROCHEFORT, DANY JACQUES
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056873/0098 →
Continuity (1)
Related Publication 20230017382A1 · Jan 19, 2023
References Cited (8)
US 10826895B1 · Krut et al. · 2020 [cited by applicant]
US 10873572B1 · Krishna · 2020 [cited by applicant]
US 11381600B1 · Wang · 2022 [cited by examiner]
US 20160119323A1 · Krishna · 2016 [cited by applicant]
US 20170111351A1 · Grajek · 2017 [cited by examiner]
US 20180152439A1 · Hande et al. · 2018 [cited by applicant]
US 20190273730A1 · Yefimov et al. · 2019 [cited by applicant]
US 20200007530A1 · Mohamad Abdul · 2020 [cited by examiner]