×

Mechanisms to Use Network Session Identifiers for Software-As-A-Service Authentication

  • US 20150106617A1
  • Filed: 12/16/2014
  • Published: 04/16/2015
  • Est. Priority Date: 10/27/2011
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • at a network access device of a network, receiving a request from a client device to access an identity provider device that provides identity assertion services to the client device, wherein the identity assertion services include identity and context information associated with a subject of the client device;

    obtaining a unique network session identifier that identifies a network session and the subject of the client device that has authenticated with the network access device to access the network session;

    inserting the network session identifier into the request from the client device to access the identity provider device such that the network session identifier is available only to the identity provider device and the network session identifier is not revealed to the subject of the client device; and

    forwarding the request with the inserted network session identifier to the identity provider device, wherein the identity provider device generates an encrypted security assertion of an identity of the subject associated with the network session, wherein the encrypted security assertion is signed using a certificate shared by the identity provider device and a server, and the identity provider device forwards the encrypted security assertion to the client device for insertion into a request from the client device to access the server.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×