IP Library › Granted Patent US 12,261,834
Granted Patent B2
US 12,261,834 · App. 18/543,902 · Granted Mar 25, 2025

Automatic sign-in upon account signup

Inventors: Chuang Wang (Issaquah, WA); Girish Nagaraja (Sammamish, WA); Ghazanfar Ahmed (Redmond, WA); Divya Jain (Bothell, WA); Weisong Lin (Redmond, WA); Zheng Guo (Seattle, WA); Roberto Anthony Franco (Seattle, WA); Philip Kevin Newman (Seattle, WA)
Assignee: Oracle International Corporation
H04L63/0815H04L63/0807H04L63/0892H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,261,834
App. No.
18/543,902
Granted
Mar 25, 2025
Kind
B2
Abstract

The present embodiments relate to systems and methods for automatic sign in upon account signup. Particularly, the present embodiments can utilize a federated login approach for automatic sign in upon account signup for a cloud infrastructure. Specifically, the signup and sign in service (also known as SOUP) and an identity provider portal can be configured such that the nodes are aware of each other as Security Assertion Markup Language (SAML) partners. After new account registration, the signup service can redirect the user browser to a cloud infrastructure console to start with a federated login flow, where a sign in service can issue a SAML authentication request, and redirects it to signup service. Responsive to validating the browser using a SAML authentication process, the browser can be automatically signed into the new account and allowed access the account relating to the cloud infrastructure service.

Claims (69)

1. A method, comprising:

obtaining, by a client computer, a sign-up request, the sign-up request for requesting to sign up a new account to a cloud infrastructure console;

receiving, from a sign on portal, an authentication request message;

forwarding, by the client computer, the authentication request message to authenticate the new account using data included in the sign-up request;

receiving, by the client computer, an authentication response message indicating the authentication of the new account;

forwarding, by the client computer, the authentication response message to the sign on portal;

receiving, from the sign on portal, a security token and an identity token;

providing, by the client computer, the security token and the identity token to the cloud infrastructure console;

receiving, by the client computer, a Secure Password Authentication (SPA) message from the cloud infrastructure console; and

accessing, by the client computer, a secure page at the cloud infrastructure console based at least in part on the SPA message.

2. The method of claim 1 , further comprising:

receiving, from the cloud infrastructure console, a redirect message identifying a sign on portal, wherein redirect message is received responsive to determining that the new account is not authenticated; and

forwarding the redirect message to the sign on portal, wherein the authentication response message is received from the sign on portal responsive to a time duration between the obtaining of the sign-up request and the forwarding of the redirect message to the sign on portal being within a threshold time duration.

3. The method of claim 2 , further comprising:

receiving, from the cloud identity provider portal computer, a first redirect message identifying the cloud infrastructure console; and

forwarding the first redirect message to the cloud infrastructure console, wherein the first redirect message identifying the cloud infrastructure console includes a query string specifying a tenant and a provider for access to cloud identity provider portal computer, and wherein the query string is passed in the redirect message identifying the sign on portal, and wherein the sign on portal generates the authentication request message using the query string.

4. The method of claim 1 , wherein a client web browser is configured to obtain a cookie from the cloud identity provider portal computer with a server side session ID to maintain a server side session with the cloud identity provider portal computer during authentication of the new account.

5. The method of claim 4 , wherein the client web browser is configured to send the cookie to the cloud identity provider portal computer when the authentication request message is forwarded to the cloud identity provider portal computer, wherein the cloud identity provider portal computer is configured to identify a sign up session with the client web browser using the cookie identifying a session ID specifying the sign up session.

6. The method of claim 1 , wherein the authentication request message and the authentication response message are formatted in a Security Assertion Markup Language (SAML).

7. The method of claim 1 , further comprising:

receiving, by the client computer, a first redirect message identifying the cloud infrastructure console;

forwarding the first redirect message to the cloud infrastructure console;

responsive to receiving the first redirect message from the cloud infrastructure console, storing a key pair included in the first redirect message at an indexed database; and

responsive to receiving the security token and the identity token from the sign on portal, storing the security token and the identity token at the indexed database.

8. The method of claim 7 , wherein the authentication request message includes a digital signature of the sign on portal, and the authentication response message includes a digital signature from the cloud identity provider portal computer, and wherein the authentication request message and authentication response message are encrypted using a public key included in the key pair.

9. A client computer comprising:

a processor; and

a computer-readable medium including instructions that, when executed by the processor, cause the processor to:

obtain a sign-up request, the sign-up request for requesting to sign up a new account to a cloud infrastructure console;

receive, from a sign on portal, an authentication request message;

forward the authentication request message to authenticate the new account using data included in the sign-up request;

receive an authentication response message indicating the authentication of the new account;

forward the authentication response message to the sign on portal;

receive, from the sign on portal, a security token and an identity token;

provide the security token and the identity token to the cloud infrastructure console;

receive a Secure Password Authentication (SPA) message from the cloud infrastructure console; and

access a secure page at the cloud infrastructure console based at least in part on the SPA message.

10. The client computer of claim 9 , wherein the processor is further caused to:

receive, from the cloud infrastructure console, a redirect message identifying a sign on portal, wherein redirect message is received responsive to determining that the new account is not authenticated; and

forward the redirect message to the sign on portal, wherein the authentication response message is received from the sign on portal responsive to a time duration between the obtaining of the sign-up request and the forwarding of the redirect message to the sign on portal being within a threshold time duration.

11. The client computer of claim 10 , wherein the processor is further caused to:

receive, from the cloud identity provider portal computer, a first redirect message identifying the cloud infrastructure console; and

forward the first redirect message to the cloud infrastructure console, wherein the first redirect message identifying the cloud infrastructure console includes a query string specifying a tenant and a provider for access to cloud identity provider portal computer, and wherein the query string is passed in the redirect message identifying the sign on portal, and wherein the sign on portal generates the authentication request message using the query string.

12. The client computer of claim 9 , wherein a client web browser is configured to obtain a cookie from the cloud identity provider portal computer with a server side session ID to maintain a server side session with the cloud identity provider portal computer during authentication of the new account.

13. The client computer of claim 12 , wherein the client web browser is configured to send the cookie to the cloud identity provider portal computer when the authentication request message is forwarded to the cloud identity provider portal computer, wherein the cloud identity provider portal computer is configured to identify a sign up session with the client web browser using the cookie identifying a session ID specifying the sign up session.

14. The client computer of claim 9 , wherein the authentication request message and the authentication response message are formatted in a Security Assertion Markup Language (SAML).

15. The client computer of claim 9 , wherein the processor is further caused to:

receiving, by the client computer, a first redirect message identifying the cloud infrastructure console;

forwarding the first redirect message to the cloud infrastructure console;

responsive to receiving the first redirect message from the cloud infrastructure console, storing a key pair included in the first redirect message at an indexed database; and

responsive to receiving the security token and the identity token from the sign on portal, storing the security token and the identity token at the indexed database.

16. A non-transitory computer-readable medium including stored thereon a sequence of instructions that, when executed by one or more processors of a client computer causes the one or more processors to execute the sequence of instructions to perform operations comprising:

obtaining, by a client computer, a sign-up request, the sign-up request for requesting to sign up a new account to a cloud infrastructure console;

receiving, from a sign on portal, an authentication request message;

forwarding, by the client computer, the authentication request message to authenticate the new account using data included in the sign-up request;

receiving, by the client computer, an authentication response message indicating the authentication of the new account;

forwarding, by the client computer, the authentication response message to the sign on portal;

receiving, from the sign on portal, a security token and an identity token;

providing, by the client computer, the security token and the identity token to the cloud infrastructure console;

receiving, by the client computer, a Secure Password Authentication (SPA) message from the cloud infrastructure console; and

accessing, by the client computer, a secure page at the cloud infrastructure console based at least in part on the SPA message.

17. The non-transitory computer-readable medium of claim 16 , wherein a client web browser is configured to obtain a cookie from the cloud identity provider portal computer with a server side session ID to maintain a server side session with the cloud identity provider portal computer during authentication of the new account.

18. The non-transitory computer-readable medium of claim 17 , wherein the client web browser is configured to send the cookie to the cloud identity provider portal computer when the authentication request message is forwarded to the cloud identity provider portal computer, wherein the cloud identity provider portal computer is configured to identify a sign up session with the client web browser using the cookie identifying a session ID specifying the sign up session.

19. The non-transitory computer-readable medium of claim 16 , wherein the authentication request message and the authentication response message are formatted in a Security Assertion Markup Language (SAML).

20. The non-transitory computer-readable medium of claim 16 , wherein the process further includes:

receiving, from a cloud identity provider portal computer, a first redirect message identifying the cloud infrastructure console;

forwarding the first redirect message to the cloud infrastructure console;

responsive to receiving the first redirect message from the cloud infrastructure console, storing a key pair included in the first redirect message at an indexed database; and

responsive to receiving the security token and the identity token from the sign on portal, storing the security token and the identity token at the indexed database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2023
From: WANG, CHUANG; NAGARAJA, GIRISH; AHMED, GHAZANFAR; JAIN, DIVYA; LIN, WEISONG; GUO, ZHENG; FRANCO, ROBERTO ANTHONY; NEWMAN, PHILIP KEVIN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 065910/0134 →
Continuity (3)
Continuation 17463493 · Aug 31, 2021
Provisional Application 63142828 · Jan 28, 2021
Related Publication 20240121233A1 · Apr 11, 2024
References Cited (28)
US 8589442B2 · Wu et al. · 2013 [cited by applicant]
US 8707409B2 · Shah et al. · 2014 [cited by applicant]
US 9043886B2 · Srinivasan et al. · 2015 [cited by applicant]
US 9560036B2 · Hinton et al. · 2017 [cited by applicant]
US 9774581B2 · Leicher et al. · 2017 [cited by applicant]
US 10049349B1 · Grassadonia · 2018 [cited by examiner]
US 10287180B1 · Kurani · 2019 [cited by examiner]
US 11784995B1 · Slowiak · 2023 [cited by examiner]
US 20100293029A1 · Olliphant · 2010 [cited by examiner]
US 20120072979A1 · Cha · 2012 [cited by examiner]
US 20120239560A1 · Pourfallah · 2012 [cited by examiner]
US 20130086670A1 · Vangpat et al. · 2013 [cited by applicant]
US 20130104202A1 · Yin · 2013 [cited by examiner]
US 20170295165A1 · Cicchitto et al. · 2017 [cited by applicant]
US 20200034518A1 · Mezzalira · 2020 [cited by examiner]
EP 2336886A2 · 2011 [cited by applicant]
KR 20000058925A · 2000 [cited by applicant]
WO 2013165274A2 · 2013 [cited by applicant]
WO 2017084569A1 · 2017 [cited by applicant]
“Configure SAML Single Sign-on for Chrome Devices”, Google Chrome Enterprise Help, Available Online at: https://support.google.com/chrome/a/answer/6060880?hl=en, Accessed from Internet on Feb. 4, 2021, pp. 1-2. [cited by applicant]
“How to Configure Automatic Login to Web Portals”, Broadcom, Available Online at: https://techdocs.broadcom.com/us/en/symantec-security-software/identity-securityhow-to-configure-automatic-login-to-web-portals.html, Sep… [cited by applicant]
“Identity Federation in AWS”, Amazon, Available Online at: https://aws.amazon.com/identity/federation/, Accessed from Internet on Feb. 4, 2021, pp. 1-3. [cited by applicant]
“Spring Security—Auto Login User After Registration”, Baeldung, Available Online at: https://www.baeldung.com/spring-security-auto-login-user-after-registration, Jun. 28, 2020, 5 pages. [cited by applicant]
“TIBCO Cloud Federated Authentication”, TIBCO Cloud, Available Online at: https://account.cloud.tibco.com/cloud/docs/accounts/manageldap/, Accessed from Internet on Jan. 29, 2021, pp. 1-4. [cited by applicant]
“What is Self-Service Sign-up for Azure Active Directory?”, Microsoft, Available Online at: https://docs.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-self-service-signup, Dec. 2, 2020, pp. 1-4. [cited by applicant]
U.S. Appl. No. 17/463,493, “Notice of Allowance”, mailed Nov. 29, 2023, 9 pages. [cited by applicant]
FOSTER , “Automatic Post-Registration Sign-in with Identity Server”, Available Online at: https://benfoster.io/blog/identity-server-post-registration-sign-in/, Sep. 3, 2016, pp. 1-9. [cited by applicant]
GENNARO , “How to Set Up a Registration Redirect in WordPress”, WPForms, Available Online at: https://wpforms.com/how-to-set-up-wordpress-registration-redirects-complete-guide/, Dec. 3, 2020, pp. 1-16. [cited by applicant]