Invention Grant
- Patent Title: SSO functionality by means of a temporary password and out-of-band communications
-
Application No.: US15685794Application Date: 2017-08-24
-
Publication No.: US10063539B2Publication Date: 2018-08-28
- Inventor: Heather M. Hinton , Kelly Malone
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Schmeiser, Olsen & Watts, LLP
- Agent William Hartwell
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N7/00

Abstract:
A system and method for using a single-use password to add SSO functionality to a service of a Service Provider belonging to an F-SSO federation that does not support F-SSO functionality for the service. In response to receiving notification from an Identity Provider that a user has requested access to the service, the Service Provider uses information provided by the Identity Provider to identify and authenticate the user, and then uses standard API calls to create and send a temporary password to the user. This password may be created as a function of the user's physical location or IP address and may be communicated out-of-band. Upon determining that the user has correctly returned the temporary password to the Service Provider, the Service Provider generates and sends the user a strong single-use password through a secure in-band communication, through which the user may access the service.
Public/Granted literature
- US20170353447A1 SSO FUNCTIONALITY BY MEANS OF A TEMPORARY PASSWORD AND OUT-OF-BAND COMMUNICATIONS Public/Granted day:2017-12-07
Information query