System, method and apparatus for federated single sign-on services
Abstract
The advent of new and sophisticated web services provided by Service Providers to users, services that individually require authentication of user and authorization of access, brings the needs for a new service to facilitate such authentication and access, a service referred to as Single Sign-On (SSO). The basic principle behind SSO is that users are authenticated once at a particular level, and then access all their subscribed services accepting that level of authentication. The present invention provides a system, method and apparatus wherein a cellular Federation of mobile network operators becomes an SSO authentication authority for subscribers of this Federation accessing Service Providers having such agreement with a mobile network operator of the Federation. In accordance with this invention, mobile network operators can leverage their operator-subscriber trust relationship in order to act as SSO authentication authority for those subscribers accessing Service Providers in a service domain other than the mobile network domain.
Claims
exact text as granted — not AI-modified1 - 33 . (canceled)
34 . An Authentication Broker included in a telecommunication system providing Single Sign-On services to a user accessing selected Service Providers, the user having a subscription with a first mobile network operator, and each selected Service Provider being associated with a second mobile network operator, said Authentication Broker comprising:
an Authentication Broker Web Front End that includes a first interfacing means and a second interfacing means for interfacing with said user and a selected Service Provider, respectively; the first interfacing means for communicating with a user having a subscription with a first mobile network operator; the second interfacing means for communicating with a Service Provider associated with a second mobile network operator; a broker channel formed from said first and second interfacing means for enabling the Authentication Broker to redirect said user to said user's Home network, and for resolving said user's Home network for said Service Provider, respectively.
35 . The Authentication Broker of claim 34 further comprising storage for all the Authentication Providers in the cellular Federation on a per mobile network operator basis, each mobile network operator included in the cellular Federation.
36 . An Authentication Provider included in a telecommunication system providing Single Sign-On services to a user accessing selected Service Providers, the user having a subscription with a first mobile network operator, and each selected Service Provider being associated with a second mobile network operator, said Authentication Provider comprising:
a front channel including a Web Front End that comprises first interfacing means for enabling an authentication session between said user and said Authentication Provider; and back channel including a Protocol Binding that comprises second interfacing means for exchanging information related to user authentication assertion between said Authentication Provider and a selected Service Provider that the user is accessing.
37 . The Authentication Provider of claim 36 , wherein the front channel further comprises a Session Manager and storage for handling session status for the user, and a Front End Authentication server for carrying out a specific authentication mechanism for the user.
38 . A telecommunication system for providing Single Sign-On services to a first user for accessing at least one Service Provider, the user having a subscription with a first mobile network operator, said system comprising:
a first mobile network operated by a first operator; an Authentication Provider belonging to said first mobile network is entitled to authenticate said first user towards said at least one Service Provider, said Authentication Provider generating an authentication assertion valid for said first user to access at least one Service Provider and returning an artifact with said assertion back to said first user; and wherein said at least one Service Provider is providing services to said first user once said first user is authenticated by said Authentication Provider, said at least one Service Provider redirecting an access request from said first user towards said Authentication Provider; wherein said at least one Service Provider is receiving the authentication assertion included in said artifact presented by said first user; wherein said at least one Service Provider is requesting verification of the authentication assertion towards said Authentication Provider; and wherein said Authentication Provider is directly accessed without involving an Authentication Broker.
39 . The telecommunication system of claim 38 , wherein at least one of said Service Providers having entry point agreements with said first mobile network operator is requesting validation of the authentication assertion for said user towards said Authentication Provider without involving said Authentication Broker.
40 . A telecommunication system for providing Single Sign-On services to a first user for accessing at least one Service Provider, the user having a subscription with a first mobile network operator, said system comprising:
a first mobile network operated by a first operator; an Authentication Provider belonging to said first mobile network is entitled to authenticate said first user towards said at least one Service Provider, said Authentication Provider generating an authentication assertion valid for said first user to access at least one Service Provider and returning an artifact with said assertion back to said first user; and means for issuing a Single Sign-On authentication request from said user towards said Authentication Provider, when said user accesses the selected Service Provider and is redirected towards the Authentication Provider for authentication; means for receiving the artifact with the authentication assertion; means for presenting the received authentication artifact to the at least one Service Provider; wherein said at least one Service Provider is providing services to said first user once said first user is authenticated by said Authentication Provider, said at least one Service Provider redirecting an access request from said first user towards said Authentication Provider; wherein said at least one Service Provider is receiving the authentication assertion included in said artifact presented by said first user; and wherein said at least one Service Provider is requesting verification of the authentication assertion towards said Authentication Provider.
41 . A telecommunication system for providing Single Sign-On services to a first user for accessing at least one Service Provider, the user having a subscription with a first mobile network operator, said system comprising:
a first mobile network operated by a first operator; an Authentication Provider belonging to said first mobile network is entitled to authenticate said first user towards said at least one Service Provider, said Authentication Provider generating an authentication assertion valid for said first user to access at least one Service Provider and returning an artifact with said assertion back to said first user; and wherein said at least one Service Provider is providing services to said first user once said first user is authenticated by said Authentication Provider, said at least one Service Provider redirecting an access request from said first user towards said Authentication Provider; wherein said at least one Service Provider is receiving the authentication assertion included in said artifact presented by said first user; wherein said at least one Service Provider is requesting verification of the authentication assertion towards said Authentication Provider; and wherein said user is identified between said Authentication Provider and the at least one Service Provider by means of a shared identity independently of the authentication identity used between said user and said Authentication Provider, and independently of the user identity used between said user and said at least one Service Provider.Join the waitlist — get patent alerts
Track US2007184819A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.