Methods and apparatus to facilitate single sign-on services

US9686265B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9686265-B2
Application numberUS-201113992971-A
CountryUS
Kind codeB2
Filing dateDec 28, 2011
Priority dateDec 28, 2011
Publication dateJun 20, 2017
Grant dateJun 20, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods, articles of manufacture and apparatus are disclosed to facilitate single sign-on services. An example method includes monitoring web session activity for an indication of entry of first credentials, identifying an SSO framework associated with the device in response to detecting a context event indicative of web session termination, querying the SSO framework for second credentials associated with the web session, and configuring SSO services on the device when the second credentials are absent from the SSO framework.

First claim

Opening claim text (preview).

What is claimed is: 1. A method to configure single sign-on (SSO) services for a user device, comprising: monitoring, by executing a computer readable instruction with at least one processor, web session activity on the user device for an indication of entry of first credentials; in response to detecting a context event indicative of termination of a web session corresponding to the web session activity by a user of the user device, discovering, by executing a computer readable instruction with the at least one processor, a presence of an inactive SSO framework contained on the user device, the context event being at least one of a selection of a log off button of a website associated with the web session, a minimization of a user interface of a web browser associated with the web session, or a period of inactivity of an input device of the user device during the web session; querying, by executing a computer readable instruction with the at least one processor, the discovered SSO framework for second credentials associated with the web session; querying, by executing a computer readable instruction with the at least one processor, the discovered SSO framework for an indication of a decline request, the decline request to suppress one or more user prompts; in response to detecting an absence of the decline request, identifying, by executing a computer readable instruction with the at least one processor, a credential field type associated with the web session; and configuring, by executing a computer readable instruction with the at least one processor, the SSO services on the user device when the second credentials are absent from the discovered SSO framework. 2. A method as described in claim 1 , further including suppressing one or more user prompts in response to detecting the decline request. 3. A method as described in claim 1 , wherein the credential field type includes at least one of a username field, a password field, or a challenge question field. 4. A method as described in claim 1 , wherein the credential field type is defined by a plug-in associated with the web session. 5. A method as described in claim 1 , further including comparing the credential field type with the first credentials to determine whether authentication requirements for the web session are satisfied. 6. A method as described in claim 5 , further including suppressing a credential entry prompt and invoking a permission prompt when the credential field type matches the first credentials. 7. A method as described in claim 5 , further including identifying a missing credential field type when the credential field type does not match the first credentials. 8. A method as described in claim 1 , further including querying the discovered SSO framework for a permission detail, wherein the configuring of the SSO services on the user device is in response to detecting the permission detail. 9. A method as described in claim 8 , wherein the permission detail indicates at least one of expiration of a credential associated with the discovered SSO framework, modification of an Internet protocol address associated with the user device, deletion of a cookie associated with the user device, or deletion of a temporary file associated with the user device. 10. An apparatus to configure single sign-on (SSO) services for a user device, comprising: a credential input monitor to monitor a web session on the user device for an indication of entry of first credentials; a context event monitor to detect at least one of a selection of a log off button of a website associated with the web session, a minimization of a user interface of a web browser associated with the web session, or a period of inactivity of an input device of the user device during the web session; and an SSO framework interface to: discover a presence of an inactive SSO framework contained on the user device in response to the at least one of the selection, the minimization, or the period of inactivity; query the discovered SSO framework for second credentials associated with the web session; query the discovered SSO framework for an indication of a decline request, the decline request to suppress one or more user prompts; in response to detecting an absence of the decline request, identify a credential field type associated with the web session; and configure the SSO services on the user device when the second credentials are absent from the discovered SSO framework, at least one of the credential input monitor, the context event monitor and the SSO framework interface implemented by a logic circuit. 11. An apparatus as described in claim 10 , further including an extender prompt engine to suppress one or more user prompts in response to detecting the decline request. 12. An apparatus as described in claim 10 , wherein the credential input monitor is to detect at least one of a username field, a password field, or a challenge question field. 13. An apparatus as described in claim 10 , further including a plug-in associated with the web session to provide authentication field requirements. 14. An apparatus as described in claim 10 , further including a credential comparator to compare the credential field type with the first credentials to determine whether authentication requirements for the web session are satisfied. 15. A tangible computer readable medium comprising instructions that, when executed, cause a user device to, at least: monitor a web session on the user device for entry of first credentials; discover the presence of an inactive single sign-on (SSO) framework contained on the user device in response to detecting at least one of a selection of a log off button of a website associated with the web session, a minimization of a user interface of a web browser associated with the web session, or a period of inactivity of an input device of the user device during the web session; query the discovered SSO framework for second credentials associated with the web session; query the discovered SSO framework for an indication of a decline request, the decline request to suppress one or more user prompts; in response to detecting an absence of the decline request, identify a credential field type associated with the web session; and configure SSO services on the user device when the second credentials are absent from the discovered SSO framework. 16. A tangible computer readable medium as described in claim 15 , further including instructions that, when executed, cause the user device to suppress one or more user prompts in response to detecting the decline request. 17. A tangible computer readable medium as described in claim 15 , further including instructions that, when executed, cause the user device to identify at least one of a username field, a password field, or a challenge question field. 18. A tangible computer readable medium as described in claim 15 , further including instructions that, when executed, cause the user device to identify the credential field type from a plug-in associated with the web session. 19. A tangible computer readable medium as described in claim 15 , further including instructions that, when executed, cause the user device to compare the credential field type with the first credentials to determine whether authentication requirements for the web session are satisfied. 20. A tangible computer readable medium as described in claim 19 , further including instructions that, when executed, cause the user device to suppress a credential entry pr

Assignees

Inventors

Classifications

  • providing single-sign-on or federations · CPC title

  • where a single sign-on provides access to a plurality of computers · CPC title

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9686265B2 cover?
Methods, articles of manufacture and apparatus are disclosed to facilitate single sign-on services. An example method includes monitoring web session activity for an indication of entry of first credentials, identifying an SSO framework associated with the device in response to detecting a context event indicative of web session termination, querying the SSO framework for second credentials ass…
Who is the assignee on this patent?
Bilgen Aras, Ketrenos James P, Intel Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/0815. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 20 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).