IL287448A

Intermediary handling of identity services to guard against client-side attack vectors

Abstract

This record has no abstract on file.

IL287448A, drawing sheet 1
Sheet 1 of 5

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 2 independent, 18 dependent

  1. 1
    A method performed by an intermediary server, the intermediary server being deployed on a network path in between a client and a host associated with a relying party, the intermediary server being remote from the client, the method comprising:establishing a secure session on a resource domain with a client;within the secure session, receiving a request for a resource hosted under the resource domain;proxying the request for the resource from the client to a relying party (RP) host acting as origin for the resource domain;intercepting a redirect sent from the RP host to redirect the client from the resource domain to an identity services provider (IdP) domain, said interception performed to prevent the redirect from reaching the client;in response to intercepting the redirect, prompting the client for a client credential, said prompting occurring within the secure session on the resource domain;independent of the client, performing the following actions: receiving the client credential within the secure session on the resource domain, following the redirect to contact an IdP host on the IdP domain, and providing the client credential to the IdP host to obtain an identity assertion from the IdP host, and sending the assertion to the relying party to obtain therefrom a resource domain credential for the client, the resource domain credential being distinct from the client credential;once the resource domain credential for the client is obtained, associating the resource domain credential with the resource domain secure session between the client and the intermediary server, where said associating comprises any of: a. storing the resource domain credential on the intermediary server on behalf of the client, and b. storing the resource domain credential on the client under the resource domain;after said association of the resource domain credential with the resource domain secure session between the client and the intermediary: proxying a request from the client to the RP host for the resource and including the resource domain credential with the proxied request.
  2. 11
    An apparatus comprising:an intermediary server deployed on a network path in between a client and a host associated with a relying party, the intermediary server deployed remote from the client;the intermediary server comprising one or more processors and memory holding instructions that when executed on the one or more processors cause the intermediary server to: establish a secure session on a resource domain with a client;within the secure session, receive a request for a resource hosted under the resource domain;proxy the request for the resource from the client to a relying party (RP) host acting as origin for the resource domain;intercept a redirect sent from the RP host to redirect the client from the resource domain to an identity services provider (IdP) domain, said interception performed to prevent the redirect from reaching the client;in response to intercepting the redirect, prompt the client for a client credential, said prompting occurring within the secure session on the resource domain;independent of the client, perform the following actions: receiving the client credential within the secure session on the resource domain, follow the redirect to contact an IdP host on the IdP domain, and providing the client credential to the IdP host to obtain an identity assertion from the IdP host;and send the assertion to the relying party to obtain therefrom a resource domain credential for the client, the resource domain credential being distinct from the client credential;once the resource domain credential for the client is obtained, associate the resource domain credential with the resource domain secure session between the client and the intermediary server, where said associating comprises any of: store the resource domain credential on the intermediary server on behalf of the client, and store the resource domain credential on the client under the resource domain;after said association of the resource domain credential with the resource domain secure session between the client and the intermediary: proxy a request from the client to the RP host for the resource and including the resource domain credential with the proxied request.