Invention Grant
US09356928B2 Mechanisms to use network session identifiers for software-as-a-service authentication
有权
使用网络会话标识符进行软件即服务认证的机制
- Patent Title: Mechanisms to use network session identifiers for software-as-a-service authentication
- Patent Title (中): 使用网络会话标识符进行软件即服务认证的机制
-
Application No.: US14572075Application Date: 2014-12-16
-
Publication No.: US09356928B2Publication Date: 2016-05-31
- Inventor: Nathan Sowatskey , Nancy Cam-Winget , Susan E. Thomson , David Jones , Morteza Ansari , Klaas Wierenga , Joseph Salowey
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Techniques are provided for authenticating a subject of a client device to access a software-as-a-service (SaaS) server. A network access device receives a request from a client device to establish a network session and transfers identity information of the subject, the client device and the network session to a session directory database. A request is sent to access an application on a SaaS server. If it does not contain an identity assertion that identifies the subject, the request is redirected to an identity provider device, to provide identity assertion services to the subject. A network session identifier is inserted into the request by a network access device and the request is forwarded to the identity provider device. The identity provider device uses the network session identifier to query the session directory database for the identity information to be used for a security assertion of the subject to the SaaS server.
Public/Granted literature
- US20150106617A1 Mechanisms to Use Network Session Identifiers for Software-As-A-Service Authentication Public/Granted day:2015-04-16
Information query