Secure single sign-on to software applications

After an initial user sign-on with an identity provider, and in response to an intention of the user to use a third-party application executing on a client device of the user and requiring user sign-on, the identity provider provides a client script to the third-party application. The client script...

Full description

Saved in:
Bibliographic Details
Main Authors Makhani, Naveed, Powell, Marc, Belote, Thomas M, Karaa, Hassen, Garg, Ankit, Wang, Christine, Jayaraman, Vinoth, Shen, Shaolin
Format Patent
LanguageEnglish
Published 05.11.2019
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:After an initial user sign-on with an identity provider, and in response to an intention of the user to use a third-party application executing on a client device of the user and requiring user sign-on, the identity provider provides a client script to the third-party application. The client script facilitates user and application authentication and invokes a trusted broker application that interacts with the identity provider to enable the user to use the third-party application. The use of the trusted broker application provided by the identity provider frees the authors of third-party applications from the need to modify their applications to explicitly sign in with the identify provider. For enhanced security, conformance to an organizational security policy is verified at time of sign-on, and an authenticatable link is used to invoke the third-party application to foil attempts by malicious software to substitute another application.
Bibliography:Application Number: US201715687528