US2004003081A1PendingUtilityA1

System and method for providing program credentials

Assignee: MICROSOFT CORPPriority: Jun 26, 2002Filed: Jun 26, 2002Published: Jan 1, 2004
Est. expiryJun 26, 2022(expired)· nominal 20-yr term from priority
H04L 63/0815
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system for providing a client's credentials to a computer program comprises a database remote from the client and a single signon server module. The single signon server module can receive a request for the client's credentials from the computer program, determine whether the client's credentials are stored in the database, and send the client's credentials from the database to the computer program in response to a determination that the client's credentials are stored in the database. The single signon server module can store the client's credentials in the database in response to a determination that the client's credentials are not stored in the database. The single signon server module can encrypt the client's credentials prior to storing the client's credentials in the database and can decrypt the client's credentials prior to sending the client's credentials to the computer program.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A computer-implemented method for providing a client's credentials to a computer program, comprising the steps of: 
 storing the client's credentials in a location remote from the client;    receiving a request for the client's credentials from the computer program; and    sending the client's credentials from the remote location to the computer program in response to the computer program's request.    
     
     
         2 . The method according to  claim 1 , further comprising the step of determining whether the client's credentials are stored in the remote location, 
 wherein said sending step is performed in response to a determination that the client's credentials are stored in the remote location.    
     
     
         3 . The method according to  claim 2 , further comprising the step of encrypting the client's credentials prior to said storing step.  
     
     
         4 . The method according to  claim 3 , further comprising the step of decrypting the client's credentials prior to said sending step.  
     
     
         5 . The method according to  claim 1 , further comprising the step of determining whether the client's credentials are stored in the remote location, 
 wherein said storing step is performed in response to a determination that the client's credentials are not stored in the remote location.    
     
     
         6 . The method according to  claim 5 , wherein said storing step comprises the steps of: 
 requesting the client's credentials from the client;    inputting the client's credentials; and    storing the client's credentials in the remote location.    
     
     
         7 . The method according to  claim 6 , wherein said storing step further comprises the step of encrypting the client's credentials.  
     
     
         8 . The method according to  claim 7 , further comprising the step of decrypting the client's credentials prior to said sending step.  
     
     
         9 . The method according to  claim 1 , further comprising the step of determining whether the computer program comprises a group computer program, 
 wherein the client's credentials comprise a group's credentials for the group computer program, and    wherein said sending step comprises sending the group's credentials from the remote location to the computer program in response to a determination that the computer program comprises the group computer program.    
     
     
         10 . The method according to  claim 9 , further comprising the step of determining whether the client is a member of the group, 
 wherein said sending step is performed in response to a determination that the client is a member of the group.    
     
     
         11 . A computer-readable medium having computer-executable instructions for performing the steps recited in  claim 1 .  
     
     
         12 . A system for providing a client's credentials to a computer program, comprising: 
 a database remote from the client; and    a single signon server module capable of 
 receiving a request for the client's credentials from the computer program,  
 determining whether the client's credentials are stored in said database, and  
 sending the client's credentials from said database to the computer program in response a determination that the client's credentials are stored in said database.  
   
     
     
         13 . The system according to  claim 12 , wherein said single signon server module is further capable of storing the client's credentials in said database in response to a determination that the client's credentials are not stored in said database.  
     
     
         14 . The system according to  claim 13 , wherein said single signon server module is further capable of encrypting the client's credentials prior to storing the client's credentials in said database.  
     
     
         15 . The system according to  claim 14 , further comprising a master secret server module capable of storing a master secret, 
 wherein said single signon server module uses the master secret to encrypt the client's credentials.    
     
     
         16 . The system according to  claim 14 , wherein said single signon server module uses a secret provided by the client to encrypt the client's credentials.  
     
     
         17 . The system according to  claim 14 , wherein said single signon server module is further capable of decrypting the client's credentials prior to sending the client's credentials to the computer program.  
     
     
         18 . The system according to  claim 12 , wherein said single signon server module is further capable of determining whether the computer program comprises a group computer program, 
 wherein the client's credentials comprise a group's credentials for the group computer program, and    wherein said single signon sever module sends the group's credentials from said database to the computer program in response to a determination that the computer program comprises the group computer program.    
     
     
         19 . The system according to  claim 18 , wherein said single signon server module is further capable of determining whether the client is a member of the group, and 
 wherein said single signon server module sends the group's credentials to the computer program in response to a determination that the client is a member of the group.    
     
     
         20 . A computer-readable medium for providing a client's credentials to a computer program, said medium having computer-executable instructions for performing the steps comprising: 
 receiving a request for the client's credentials from the computer program;    determining whether the client's credentials are stored in a location remote from the client;    storing the client's credentials in the remote location in response to a determination that the client's credentials are not stored in the remote location; and    sending the client's credentials from the remote location to the computer program in response to the computer program's request.    
     
     
         21 . The computer-readable medium according to  claim 20 , said medium having further computer-executable instructions for performing the step comprising encrypting the client's credentials prior to said storing step.  
     
     
         22 . The computer-readable medium according to  claim 21 , said medium having further computer-executable instructions for performing the step comprising decrypting the client's credentials prior to said sending step.  
     
     
         23 . The computer-readable medium according to  claim 20 , said medium having further computer-executable instructions for performing the step comprising determining whether the computer program comprises a group computer program, 
 wherein the client's credentials comprise a group's credentials for the group computer program, and    wherein said sending step comprises sending the group's credentials from the remote location to the computer program in response to a determination that the computer program comprises a group computer program.

Join the waitlist — get patent alerts

Track US2004003081A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.