×

System and method for single sign-on session management without central server

  • US 9,185,105 B2
  • Filed: 05/04/2011
  • Issued: 11/10/2015
  • Est. Priority Date: 02/19/2002
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for single sign-on session management, the method comprising:

  • receiving by a first plug-in module residing on a first processor controlled web server, a request to grant a client browser access to a protected resource accessible from the first processor controlled web server, the request comprising a session credential associated with a decryption key, the session credential including at least a session start timestamp and a maximum session idle time for a session initiated prior to the request and in response to authentication of the customer browser at a second plug-in module of another web server for access to another of the protected resources;

    decrypting the session credential using the decryption key and checking for validity of the session credential with the first plug-in module;

    granting the request if the session credential is validated and updating a time value of the session credential; and

    when the session credential is not validated, establishing a new session credential at the plug-in module located on the first processor controlled web server,wherein each of the first plug-in module and the second plug-in module are configured to establish and validate session credentials independently without redirecting the customer browser to a central sign-on server.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×