CA3073086C

Extending single-sign-on to relying parties of federated logon providers

Abstract

Aspects of the disclosure relate to extending single-sign-on to relying parties for federated logon providers. An enterprise identity provider server may receive a first authentication token previously issued to an enterprise server by the enterprise identity provider server. Subsequently, the enterprise identity provider server may retrieve, from a token store, a second authentication token associated with a federated identity service provided by a federated identity provider server. The enterprise identity provider server may refresh the second authentication token with the federated identity service provided by the federated identity provider server to obtain a refreshed authentication token. Finally, the enterprise identity provider server may send the refreshed authentication token to the enterprise server, which may enable user devices managed by the enterprise server to access one or more resources provided by a third party system using the federated identity service.

CA3073086C, drawing sheet 1
Sheet 1 of 12

Term

11.9 yearsleft in the term

Expires 13 August 2038.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

26 claims: 20 independent, 6 dependent

  1. 1
    An enterprise identity provider server comprising:at least one processor;a communication interface;memory storing instructions that, when executed by the at least one processor, cause the enterprise identity provider server to: receive, via the communication interface, from an enterprise server integrated with an enterprise identity service provided by the enterprise identity provider server, a first authentication token previously issued to the enterprise server by the enterprise identity provider server;in response to receiving the first authentication token, retrieve, from a token store maintained by the enterprise identity provider server, a second authentication token associated with a federated identity service provided by a federated identity provider server;refresh the second authentication token with the federated identity service provided by the federated identity provider server to obtain a refreshed authentication token;and send, via the communication interface, to the enterprise server, the refreshed authentication token, wherein sending the refreshed authentication token to the enterprise server enables user devices manages by the enterprise server to access one or more resources provided by a third party system using the federated identity service.
  2. 3
    The enterprise identity provider server of daim 1 or 2, wherein the memory stores additional instructions that, when executed by the at least one processor, cause the enterprise identity provider server to:store, in the token store, the second authentication token and a reference associating the second authentication token with the first authentication token.
  3. 4
    The enterprise identity provider server of any one of claims 1-3, wherein the memory stores additional instructions that, when executed by the at least one processor, cause the enterprise identity provider server to:in response to refreshing the second authentication token, store, in the token store, the refreshed authentication token and a reference associating the refreshed authentication token with the first authentication token.
  4. 5
    The enterprise identity provider server of any one of claims 1 -4, wherein refreshing the second authentication token further causes the enterprise identity provider server to:send, via the communication interface, a request to the federated identity provider server to regenerate the second authentication token, wherein the federated identity provider server generates the refreshed authentication token;and receive, via the communication interface, the refreshed authentication token from the federated identity provider server.
  5. 7
    The enterprise identity provider server of any one of claims 1 -6, wherein the memory stores additional instructions that when executed by the at least one processor, cause the enterprise identity provider server to:receive, via the communication interface, a request from the enterprise server to access the one or more resources provided by the third party system using the federated identity service;and redirect, via the communication interface, the request from the enterprise server to the federated identity service provided by the federated identity provider server.
  6. 8
    The enterprise identity provider server of any one of claims 1-7, wherein the first authentication token enables the user devices managed by the enterprise server to have singlesign-on access to one or more resources using an enterprise identity service provided by the enterprise identity provider server.
  7. 9
    The enterprise identity provider server of any one of claims 1 -8, wherein the second authentication token enables the user devices managed by the enterprise server to have single-sign-on access to the third party system using the federated identity service.
  8. 10
    The enterprise identity provider server of any one of claims 1-9, wherein retrieving the second authentication token further causes the enterprise identity provider server to:retrieve, from the token store, the second authentication token based on a reference associating the second authentication token with the first authentication token.
  9. 11
    A method comprising:at an enterprise identity provider server comprising at least one processor, memory, and a communication interface: Date Reçue/Date Received 2021-08-19 receiving, via the communication interface, from an enterprise server integrated with an enterprise identity service provided by the enterprise identity provider server, a first authentication token previously issued to the enteiprise server by the enterprise identity provider server;in response to receiving the first authentication token, retrieving, from a token store maintained by the enterprise identity provider server, a second authentication token associated with a federated identity service provided by a federated identity provider server;refreshing the second authentication token with the federated identity service provided by the federated identity provider server to obtain a refreshed authentication token;and sending, via the communication interface, to the enterprise server, the refreshed authentication token, wherein sending the refreshed authentication token to the enterprise server enables user devices managed by the enterprise server to access one or more resources provided by a third party system using the federated identity service.
  10. 14
    The method of any one of claims 11-13, further comprising:in response to refreshing the second authentication token, storing, in the token store, the refreshed authentication token and a reference associating the refreshed authentication token with the first authentication token. Date Reçue/Date Received 2021-08-19
  11. 15
    The method of any one of claims 11-14, wherein refreshing the second authentication token further comprises:sending, via the communication interface, a request to the federated identity provider server to regenerate the second authentication token, wherein the federated identity provider server generates the refreshed authentication token;receiving, via the communication interface, the refreshed authentication token from the federated identity provider server;and updating the token store with the refreshed authentication token and a reference associating the refreshed authentication token with the first authentication token.
  12. 16
    The method of any one of claims 11-15, further comprising:receiving, via the communication interface, a request from the enterprise server to access the one or more resources provided by the third party system using the federated identity service;and redirecting, via the communication interface, the request from the enterprise server to the federated identity service provided by the federated identity provider server.
  13. 17
    The method of any one of claims 11-16, wherein the first authentication token enables the user devices managed by the enterprise server to have single-sign-on access to one or more resources using an enterprise identity service provided by the enterprise identity provider server.
  14. 18
    The method of any one of claims 11-17, wherein the second authentication token enables the user devices managed by the enterprise server to have single-sign-on access to the third party system using the federated identity service. Date Reçue/Date Received 2021-08-19
  15. 19
    The method of any one of claims 11-18, further comprising:retrieving, from a token store, the second authentication token based on a reference associating the second authentication token to the first authentication token.
  16. 20
    One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, memory, and a communication interface, cause the computing platform to:receive, via the communication interface, from an enterprise server integrated with an enterprise identity service provided by an enterprise identity provider server, a first authentication token previously issued to the enterprise server by the enterprise identity provider server;in response to receiving the first authentication token, retrieve, from a token store maintained by the enterprise identity provider server, a second authentication token associated with a federated identity service provided by a federated identity provider server;refresh the second authentication token with the federated identity service provided by the federated identity provider server to obtain a refreshed authentication token;and send, via the communication interface, to the enterprise server, the refreshed authentication token, wherein sending the refreshed authentication token to the enterprise server enables user devices managed by the enterprise server to access one or more resources provided by a third party system using the federated identity service.
  17. 21
    A method comprising:at an enterprise identity provider server comprising at least one processor, memory, and a communication interface: receiving, via the communication interface, from an enterprise server, a first request to access a first set of resources, wherein the first request includes a first authentication token previously issued to the enterprise server by the enterprise identity provider server, wherein the first authentication token enables single-sign-on access to the first set of resources of an enterprise system by user devices managed by the Date Reçue/Date Received 2021-08-19 enterprise server, the access enabled by the first authentication token including use of an enterprise identity service provided by the enterprise identity provider server;receiving, via the communication interface, a second request from the enterprise server to access a second set of resources provided by a third party system using a federated identity service;in response to receiving the second request and based on the first authentication token, retrieving, from a token store, a second authentication token associated with the federated identity service provided by a federated identity provider server;sending, via the communication interface, a request to the federated identity provider server to regenerate the second authentication token;receiving, via the communication interface, a refreshed authentication token from the federated identity provider server;and sending, via the communication interface and to the enteiprise server, the refreshed authentication token, wherein sending the refreshed authentication token to the enterprise server enables the user devices managed by the enterprise server to access the second set of resources provided by the third party system using the federated identity service.
  18. 24
    The method of any one of claims 21-23, wherein the first set of resources are different from the second set of resources. Date Reçue/Date Received 2021-08-19
  19. 25
    The method of any one of claims 21 -24, wherein sending the request to the federated identity provider server to regenerate the second authentication token comprises:determining a lifetime of the second authentication token;and sending the request to the federated identity provider server to regenerate the second authentication token based on the determination.
  20. 26
    The method of any one of claims 21-25, wherein a lifetime of the first authentication token is independent from a lifetime of the second authentication token.
Independent claims20