Using a service-provider password to simulate f-sso functionality

US2019199707A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2019199707-A1
Application numberUS-201916291075-A
CountryUS
Kind codeA1
Filing dateMar 4, 2019
Priority dateNov 24, 2015
Publication dateJun 27, 2019
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method for using a Service-Provider password to simulate F-SSO functionality. A processor receives from an F-SSO Identity Provider authentication data for a user who has requested access to a secured service. The service is managed by an F-SSO Service Provider that does not offer F-SSO functionality for that service. Upon receiving the data, the processor redirects the user to an SU-F-SSO portal of the Service Provider, which uses the received authentication data to authenticate the user. The processor sends the user an on-demand password and, when the user uses that password to sign on, the processor matches the entered password with a stored copy of the password that was sent to the user. If they match, the processor grants the user access to the requested service. In some embodiments, the on-demand password may be a single-use password or may be sent to the user via an out-of-band communication.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method for simulating Federated Single Sign-On (SU-F-SSO) functionality, the method comprising: a processor of a computerized single-use SU-F-SSO system receiving, from an Identity Provider of an F-SSO federation, a notification that a user has submitted a single sign-on request for a secured service of a Service Provider, where an existing single sign-on authentication procedure of the identity Provider authenticates a requestor's identity and identifies that the requestor is authorized to access the secured service by comparing information comprised by the requestor's single sign-on request with a set of trusted data retrieved from a federated server of the F-SSO federation, and where the Identity Provider, as a function of the authenticating has previously: sent a response to the Service Provider indicating that the Identity Provider has authenticated the user, notified the processor that the Identity Provider has authenticated the user, and redirected the user to a SU-F-SSO endpoint managed by Service Provider; the processor identifying and authenticating the user privileges as a function of the notification; the processor creating an on-demand password; the processor storing a copy of the on-demand password in an information repository secured by the Service Provider; the processor transmitting the on-demand password to the user; and the processor redirecting the user to the Service Provider's local logon portal, where the user is granted single-sign on access to multiple services of the Service Provider in response to the user's submission of the on-demand password to the local logon portal. 2 . The method of claim 1 , where the on-demand password is limited to a single use. 3 . The method of claim 1 , where the on-demand password is subject to constraints selected from the group consisting of: limiting the on-demand password to a certain number of uses; limiting the password to use during a single session of the secured service; limiting the password to use during a specified period of time; limiting the password to use during a specified period of time after the first use of the password; and requiring the user to perform an additional authentication procedure when entering the password. 4 . The method of claim 1 , where the on-demand password is transmitted to the user through an out-of-band communications method. 5 . The method of claim 4 , where the out-of-band communications method comprises a communication sent to a user-controlled destination that is not part of an F-SSO protocol exchange, where the out-of-band communication is selected from a group consisting of: a voice message; a fax; an SMS text message; an email message; a communication to a social-media service; an instant message; and a communication sent through the Internet to a software program running on a device that is accessible to the user. 6 . The method of claim 1 , where the notification is received in response to: the processor, responding to a detection by the processor that the user has requested access to the secured service from a local portal under control of the Service Provider, redirecting the user to a local portal under control of the Identity Provider, in; and the processor requesting that the Identity Provider identify and authenticate the user. 7 . The method of claim 1 , where the notification is received in response to a detection by the Identity Provider that the user has requested access to the secured service from a local portal under control of the Identity Provider. 8 . The method of claim 1 , where the Service Provider is a cloud-computing service provider, the secured service is a cloud-based service deployed and controlled by the Service Provider on a cloud-computing platform provided by the Service Provider, and the Identity Provider is a client of the Service Provider that controls an application deployed on the cloud-computing platform provided by the Service Provider. 9 . The method of claim 1 , where the notification comprises an F-SSO message that comprises an authentication token. 10 . The method of claim 9 , where the F-SSO message and authentication token are formatted as one or more SAML assertions. 11 . The method of claim 1 , further comprising providing at least one support service for at least one of creating, integrating, hosting, maintaining, and deploying computer-readable program code in the computer system, where the computer-readable program code in combination with the computer system is configured to implement the receiving, the identifying and authenticating, the creating, the storing, the transmitting, and the redirecting. 12 . A single-use SU-F-SSO system comprising a processor, a memory coupled to the processor, and a computer-readable hardware storage device coupled to the processor, the storage device containing program code configured to be run by the processor via the memory to implement a method for simulating Federated Single Sign-On (SU-F-SSO) functionality, the method comprising: the processor receiving, from an Identity Provider of an F-SSO federation, a notification that a user has submitted a single sign-on request for a secured service of a Service Provider, where an existing single sign-on authentication procedure of the Identity Provider authenticates a requestor's identity and identifies that the requester is authorized to access the secured service by comparing information comprised by the requestor's single sign-on request with a set of trusted data retrieved from a federated server of the F-SSO federation, and where the Identity Provider, as a function of the authenticating has previously: sent a response to the Service Provider indicating that the Identity Provider has authenticated the user, notified the processor that the Identity Provider has authenticated the user, and redirected the user to a SU-F-SSO endpoint managed by Service Provider; the processor identifying and authenticating the user privileges as a function of the notification; the processor creating an on-demand password; the processor storing a copy of the on-demand password in an information repository secured by the Service Provider; the processor transmitting the on-demand password to the user; and the processor redirecting the user to the Service Provider's local logon portal, where the user is granted single-sign on access to multiple services of the Service Provider in response to the user's submission of the on-demand password to the local logon portal. 13 . The system of claim 12 , where the on-demand password is limited to a single use. 14 . The system of claim 12 , where the on-demand password is subject to constraints selected from a group consisting of: limiting the on-demand password to a certain number of uses; limiting the password to use during a single session of the secured service; limiting the password to use during a specified period of time; limiting the password to use during a specified period of time after the first use of the password; and requiring the user to perform an additional authentication procedure when entering the password. 15 . The system of claim 12 , where the on-demand password is transmitted to the user through an out-of-band communications method, and where the out-of-band communications method comprises a communication sent to a user-controlled destination that is not part of an F-SSO protocol exchange, where the out-of-band communication is selected from a group consisting of: a voice message; a fax; an SMS text message; an email message; a communication to a soc

Assignees

Inventors

Classifications

  • providing single-sign-on or federations · CPC title

  • for controlling access to devices or network resources · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2019199707A1 cover?
A system and method for using a Service-Provider password to simulate F-SSO functionality. A processor receives from an F-SSO Identity Provider authentication data for a user who has requested access to a secured service. The service is managed by an F-SSO Service Provider that does not offer F-SSO functionality for that service. Upon receiving the data, the processor redirects the user to an S…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L63/0815. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jun 27 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).