EP2008398A2

Enhanced security for electronic communications

Abstract

This record has no abstract on file.

Term

0.5 yearsto projected expiry

Projected expiry 29 March 2027, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

21 claims: 3 independent, 18 dependent

  1. 1
    Claims of equivalent WO 2007123705 A2 CLAIMS What is claimed is:1. A method for a computing system supporting a single sign-on service, the method comprising: registering a first service with the single sign-on service, the registering including: receiving a shared secret access key available to the first service;and receiving a unique non-secret identifier associated with the shared secret access key;receiving at least one sign-on message from the first service, for a user of the first service who is attempting to sign-on via the single sign-on service, the at least one sign-on message including: multiple parameters to identify the user;an identifier of the first service;and a digital signature generated using the shared secret access key of the first service and the at least one sign-on message;and verifying an identity of the first service based at least in part on the digital signature included in the at least one sign-on message.
  2. 11
    A computer program for performing any of the methods of claims 1 to 10.
  3. 12
    A computing system supporting a single sign-on service, comprising:means for registering a first service with the single sign-on service, by: receiving a shared secret access key available to the first service;and receiving a unique non-secret identifier associated with the shared secret access key;means for receiving at least one sign-on message from the first service for a user attempting to sign-on via the single sign-on service, the at least one sign-on message including: multiple parameters to identify the user;an identifier of the first service;and a digital signature generated using the shared secret access key of the first service and the at least one sign-on message;and means for verifying an identity of the first service based at least in part on the digital signature included in the at least one sign-on message.