Patent · US Active

Mechanisms to use network session identifiers for software-as-a-service authentication

US9356928B2 · kind B2 · utility

0Cited by
7References
16Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 16, 2014
Grant dateMay 31, 2016
Priority date
Expiry dateDec 16, 2034

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/08
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Techniques are provided for authenticating a subject of a client device to access a software-as-a-service (SaaS) server. A network access device receives a request from a client device to establish a network session and transfers identity information of the subject, the client device and the network session to a session directory database. A request is sent to access an application on a SaaS server. If it does not contain an identity assertion that identifies the subject, the request is redirected to an identity provider device, to provide identity assertion services to the subject. A network session identifier is inserted into the request by a network access device and the request is forwarded to the identity provider device. The identity provider device uses the network session identifier to query the session directory database for the identity information to be used for a security assertion of the subject to the SaaS server.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.