IP Library Granted Patent US 8,990,911
Granted Patent B2
US 8,990,911 · App. 12/410,971 · Granted Mar 24, 2015

System and method for single sign-on to resources across a network

Inventors: Eric Olden (Lyons, CO); Darren C. Platt (Longmont, CO); Coby Royer (Boulder, CO); Keshava Berg (Lafayette, CO); Joseph H. Wallingford, III (Longmont, CO)
Assignee: EMC Corporation
H04L63/0815H04L63/20H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,990,911
App. No.
12/410,971
Filed
Mar 25, 2009
Granted
Mar 24, 2015
Kind
B2
Art Unit
2492
USPC
726/8
Abstract

Systems, methods and apparatus for providing single sign on across a plurality of resources is disclosed. An exemplary method includes receiving a request from a user to access a particular one of the plurality of resources; establishing an SSO session for the user if an SSO session has not been established; determining if the user has been authenticated to the particular resource, and if not, retrieving credentials for the user that are specific to the resource; presenting the credentials to the resource so as to create a session with the resource; and presenting a user interface for a customer to configure which of the plurality of resources can be accessed by users.

Claims (32)

1. A method for providing single sign-on across a plurality of resources, comprising:

receiving a request from a user to access a particular resource of the plurality of resources;

establishing a single sign-on (SSO) session for the user if an SSO session has not been established;

determining if the user has been authenticated to the particular resource, and if not, retrieving credentials for the user that are specific to the particular resource from a credential store, the credential store including a plurality of different credential sets for the user corresponding to different ones of the plurality of resources;

providing a token to a software client of the user;

operatively presenting the credentials retrieved from the credential store to the particular resource so as to create a session with the particular resource;

presenting a first user interface for a customer to configure access policies that define which of the plurality of resources can be accessed by the user;

discovering an authentication subsystem of the particular resource by simulating

a) an end user using a browser, and

b) the browser interacting with the particular resource;

communicating with the authentication subsystem to authenticate the user;

connecting to one or more user stores to retrieve attributes relating to the user;

utilizing the attributes to evaluate the access policies to determine whether or not the user should be granted access to the particular resource;

receiving the request from the user as a proxy address that differs from the actual address of the particular resource;

presenting a second user interface to allow the user to set credentials in the credential store relative to the particular resource;

using characteristics of the request to determine which of a plurality of authentication subsystems to use; and

wherein at least a portion of the characteristics of the request comprises one or more results of a previous authentication attempt for the same request with another one of the plurality of authentication subsystems.

2. The method of claim 1 , wherein the second user interface allows the user to set credentials in the credential store relative to the plurality of resources, and wherein the second user interface is different from the first user interface.

3. The method of claim 1 , including programmatically setting credentials relative to at least one of the plurality of resources.

4. The method of claim 1 , wherein the step of receiving the request from the user as a proxy address that differs from the actual address of the particular resource is performed by a Hypertext Transfer Protocol (HTTP) proxy.

5. The method of claim 4 , including creating the session with the particular resource utilizing the security assertion mark-up language (SAML) protocol.

6. The method of claim 1 , wherein the simulating of

the browser interacting with the particular resource includes simulating the browser interacting with a website.

7. The method of claim 1 , including:

receiving, from a remote resource location, the access policies; and

using the access policies in connecting to the one or more user stores to retrieve the attributes relating to the user.

8. The method of claim 7 , further comprising:

interacting with authentication handlers; and

dropping cookies for multiple domains so that subsequent requests from the user are recognized as coming from the user, even if the user requests resources from different domains, so as to allow the session to span multiple domains.

9. The method of claim 1 , including name-space-mapping to map the user's identity across user stores by:

providing a third-party user store user interface; and

automatically transforming data stored in the third-party user store for use in another resource.

Assignments (11)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2014
From: SYMPLIFIED, INC.
To: EMC CORPORATION
Reel/Frame 033351/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2009
From: PLATT, DARREN C; ROYER, COBY; BERG, KESHAVA; WALLINGFORD, JOSEPH H; OLDEN, ERIC
To: SYMPLIFEID, INC
Reel/Frame 022748/0362 →
Continuity (3)
Provisional Application 61040673 · Mar 30, 2008
Provisional Application 61094972 · Sep 7, 2008
Related Publication 20090249439A1 · Oct 1, 2009