Invention Grant
- Patent Title: Method and system for authenticating a rich client to a web or cloud application
-
Application No.: US12966165Application Date: 2010-12-13
-
Publication No.: US09699168B2Publication Date: 2017-07-04
- Inventor: Olgierd Stanislaw Pieczul , Mark Alexander McGloin , Mary Ellen Zurko , David Scott Kern , Brent Allan Hepburn
- Applicant: Olgierd Stanislaw Pieczul , Mark Alexander McGloin , Mary Ellen Zurko , David Scott Kern , Brent Allan Hepburn
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent David B. Woycechowsky; David H. Judson; Jeffrey S. LaBaw
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08 ; G06F21/31 ; G06F21/62 ; H04L9/32

Abstract:
A rich client performs single sign-on (SSO) to access a web- or cloud-based application. According to the described SSO approach, the rich client delegates to its native application server the task of obtaining a credential, such as a SAML assertion. The native server, acting on behalf of the user, obtains an assertion from a federated identity provider (IdP) that is then returned to the rich client. The rich client provides the assertion to a cloud-based proxy, which presents the assertion to an identity manager to attempt to prove that the user is entitled to access the web- or cloud-based application using the rich client. If the assertion can be verified, it is exchanged with a signed token, such as a token designed to protect against cross-site request forgery (CSRF). The rich client then accesses the web- or cloud-based application making a REST call that includes the signed token. The application, which recognizes the request as trustworthy, responds to the call with the requested data.
Public/Granted literature
- US20120151568A1 Method and system for authenticating a rich client to a web or cloud application Public/Granted day:2012-06-14
Information query