Simulated sso functionality by means of multiple authentication procedures and out-of-band communications

US2018302398A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2018302398-A1
Application numberUS-201816011769-A
CountryUS
Kind codeA1
Filing dateJun 19, 2018
Priority dateNov 24, 2015
Publication dateOct 18, 2018
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method for using a single-use password to add SSO functionality to a service of a Service Provider belonging to an F-SSO federation that does not support F-SSO functionality for the service. In response to receiving notification from an Identity Provider that a user has requested access to the service, the Service Provider uses information provided by the Identity Provider to identify and authenticate the user, and then uses standard API calls to create and send a temporary password to the user. This password may be created as a function of the user's physical location or IP address and may be communicated out-of-band. Upon determining that the user has correctly returned the temporary password to the Service Provider, the Service Provider generates and sends the user a strong single-use password through a secure in-band communication, through which the user may access the service.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for using an out-of-band password to provide enhanced SSO functionality, the method comprising: a processor of a computer system receiving notice of a user's access request from an Identity Provider (IDP) of a Federated Single Sign-On (F-SSO) federation, where the access request requests access to a service provided by a Service Provider (SP) of the federation, and where the federation does not support Single Sign-On functionality for that service; the processor, in response to receiving the notice, identifying and authenticating the user; the processor, in response to the authentication, sending a temporary password to the user through an out-of-band communications mechanism; the processor directing the user to sign onto the service by entering the temporary password and concurrently performing an additional authentication procedure; the processor detecting that the user has correctly entered the temporary password and performed the additional authentication procedure; the processor generating a single-use password; the processor communicating the single-use password to the user on a device under control of the Service Provider through a secured communication in a medium under control of the Service Provider; and the processor requiring the user to replace the temporary password with the single-use password when further accessing the service. 2 . The method of claim 1 , where the temporary password is subject to constraints selected from the group consisting of: limiting the temporary password to a certain number of uses; limiting the temporary password to use during a single session of the secured service; limiting the temporary password to use during a specified period of time; and limiting the temporary password to use during a specified duration of time after the first use of the temporary password. 3 . The method of claim 1 , where the out-of-band communications mechanism is selected from the group consisting of: transmitting the password to a smartphone or mobile device by means of a Short Messaging Service (SMS) text message, where the smartphone or mobile device is distinct from the computer system; transmitting to a smartphone or mobile device a Web page that identifies the password, where the smartphone or mobile device is distinct from the computer system; transmitting to a smartphone or mobile device, by means of a Short Messaging Service (SMS), a text message that identifies a URL of a Web page that identifies the password, where the smartphone or mobile device is distinct from the computer system; and reading the password, by means of a synthesized voice, to the user during a phone call initiated by the user. 4 . The method of claim 2 , where the out-of-band communication mechanism comprises a communication sent to a destination that is not part of the F-SSO federation and that is not under control of the Service Provider, and where the out-of-band communication is selected from a group consisting of: a voice message; a fax; an SMS text message; an email message; a communication to a social-media service; an instant message; and a communication sent through the Internet to a software program running on a device that is accessible to the user. 5 . The method of claim 1 , where the identifying and validating the user comprises: the processor, in response to the receiving notice, requesting that the IDP identify and authenticate the user; the processor redirecting the user to a portal under control of the IDP; the processor receiving authentication data from the IDP, and the processor redirecting the user to a portal under control of the SP. 6 . The method of claim 1 , further comprising: the processor storing a copy of the temporary password in an enterprise directory under control of the SP; the processor, upon receiving from the user the response to the sending, where the response is a password entered by the user, attempting to match the entered password with the password stored in the enterprise directory; and the processor, deeming the user to have been identified and authenticated as a result of having successfully matched the entered password to the stored password. 7 . The method of claim 1 , where the Service Provider is an Information as a Service cloud-service provider, the service is a cloud-based service deployed and controlled by the Service Provider on cloud infrastructure under control of the Service Provider, and the IDP is a client of the Service Provider that controls an application deployed on cloud infrastructure under control of the Service Provider. 8 . The method of claim 1 , further comprising: the processor selecting the temporary password as a function of the user's location, where the user's location comprises an Internet Protocol address of a device by which the user entered the sign-on request. 9 . The method of claim 1 , further comprising providing at least one support service for at least one of creating, integrating, hosting, maintaining, and deploying computer-readable program code in the computer system, where the computer-readable program code in combination with the computer system is configured to implement the receiving notice, the identifying and authenticating, the sending, the detecting, the generating, the communicating, and the requiring. 10 . A system for using an out-of-band password to provide enhanced SSO functionality comprising a processor, a memory coupled to the processor, and a computer-readable hardware storage device coupled to the processor, the storage device containing program code configured to be run by the processor via the memory to implement a method for using an out-of-band password to provide enhanced SSO functionality, the method comprising: a processor of a computer system receiving notice of a user's access request from an Identity Provider (IDP) of a Federated Single Sign-On (F-SSO) federation, where the access request requests access to a service provided by a Service Provider (SP) of the federation, and where the federation does not support Single Sign-On functionality for that service; the processor, in response to receiving the notice, identifying and authenticating the user; the processor, in response to the authentication, sending a temporary password to the user through an out-of-band communications mechanism; the processor directing the user to sign onto the service by entering the temporary password and concurrently performing an additional authentication procedure; the processor detecting that the user has correctly entered the temporary password and performed the additional authentication procedure; the processor generating a single-use password; the processor communicating the single-use password to the user on a device under control of the Service Provider through a secured communication in a medium under control of the Service Provider; and the processor requiring the user to replace the temporary password with the single-use password when further accessing the service. 11 . The system of claim 10 , where the temporary password is subject to constraints selected from the group consisting of: limiting the temporary password to a certain number of uses; limiting the temporary password to use during a single session of the secured service; limiting the temporary password to use during a specified period of time; and limiting the temporary password to use during a specified duration of time after the first use of the temporary password. 12 . The system of claim 10 , where the out-of-band communications method is selected from the group consisting of: transmitting the password to a s

Assignees

Inventors

Classifications

  • using time-dependent-passwords, e.g. periodically changing passwords · CPC title

  • for controlling access to devices or network resources · CPC title

  • providing single-sign-on or federations · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2018302398A1 cover?
A system and method for using a single-use password to add SSO functionality to a service of a Service Provider belonging to an F-SSO federation that does not support F-SSO functionality for the service. In response to receiving notification from an Identity Provider that a user has requested access to the service, the Service Provider uses information provided by the Identity Provider to ident…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L63/0846. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Oct 18 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).