发明授权
- 专利标题: Method and apparatus for facilitating single sign-on
- 专利标题(中): 促进单点登录的方法和装置
-
申请号: US11285642申请日: 2005-11-21
-
公开(公告)号: US07761911B2公开(公告)日: 2010-07-20
- 发明人: Baogang Song
- 申请人: Baogang Song
- 申请人地址: US CA Redwood Shores
- 专利权人: Oracle International Corporation
- 当前专利权人: Oracle International Corporation
- 当前专利权人地址: US CA Redwood Shores
- 代理机构: Park, Vaughan & Fleming LLP
- 主分类号: G06F7/04
- IPC分类号: G06F7/04 ; G06F15/16 ; G06F17/30 ; H04L29/06
摘要:
One embodiment of the present invention provides a system that facilitates single sign-on of a client, wherein single sign-on allows the client to provide authentication credentials once during a computing session and to access multiple resources without re-authenticating. The system operates by receiving a domain cookie forwarded from the client by an application server at a single sign-on server, wherein the domain cookie includes a domain identifier and an encrypted secret path, and wherein the domain cookie can only be retrieved by servers whose domain matches the domain identifier in the domain cookie. The system then decrypts the encrypted secret path to reveal an unencrypted secret path. Next, the system redirects the client to the unencrypted secret path, wherein the unencrypted secret path is a path that terminates on the single sign-on server. Upon redirection, the system sends a request to the client from the single sign-on server requesting a domain-token cookie, wherein the domain-token cookie includes the domain identifier, a clear secret path, and encrypted information, wherein the request includes the clear secret path, and wherein the domain-token cookie can only be retrieved from the client if the client determines that the unencrypted secret path and the clear secret path match. Finally, upon receiving the domain-token cookie from the client at the single sign-on server, the system authenticates the client.
公开/授权文献
- US20070118890A1 Method and apparatus for facilitating single sign-on 公开/授权日:2007-05-24
信息查询