发明名称 Client and server group SSO with local openID
摘要 A user of a mobile communications device may access services in a target domain using a source domain identity that is used to access services in a source domain. To enable such a use of the source domain identity in the target domain, the source domain identity may first be enrolled in the target domain. The enrollment may be facilitated by an enrollment entity at the target domain, such as a gateway or an OpenID server for example. The enrollment entity may establish a secure channel with the user's device for enabling enrollment of the source domain identity. Once enrolled, the source domain identity may be used for authentication of the user in the target domain. Enrollment of the source domain identity and/or authentication of the user based on the enrolled source domain identity may be implemented using a local OpenID provider (OP) residing on the user's device.
申请公布号 US9237142(B2) 申请公布日期 2016.01.12
申请号 US201213978219 申请日期 2012.01.06
申请人 InterDigital Patent Holdings, Inc. 发明人 Cha Inhyok;Schmidt Andreas;Leicher Andreas
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Baker & Hostetler LLP 代理人 Baker & Hostetler LLP
主权项 1. A computer-implemented method for enabling authentication of a user of a user device via an identity of a user that has been authenticated for use in a source domain, the method comprising: receiving the user's authenticated source domain identity at a target domain, wherein the user's authenticated source domain identity enables the user to access a source domain service at the source domain; enrolling the user's authenticated source domain identity at the target domain, wherein the enrollment of the user's authenticated source domain identity enables the user to access a target domain service being provided at the target domain using the user's authenticated source domain identity; and authenticating, via an identity provider residing locally on the user device, the user for the access to the target domain service using the enrolled user's authenticated source domain identity, wherein authenticating the user for the access to the target domain service further comprises: deriving a signing key based on a key that is shared with the identity provider; and sending the signing key to a service provider of the target domain service.
地址 Wilmington DE US