Invention Grant
- Patent Title: Protecting sensitive information in single sign-on (SSO) to the cloud
-
Application No.: US16295090Application Date: 2019-03-07
-
Publication No.: US11044236B2Publication Date: 2021-06-22
- Inventor: Leonid Rodniansky
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method to protect sensitive information during a single sign-on (SSO) process flow initiated from a client and directed to an authorization server configured to issue an access token upon verification of a credential. The technique leverages a first proxy that monitors a packet flow issued from the authorization server, and a second proxy that monitors a redirect packet flow issued from the client (in response to the packet flow). A message that includes the access token is modified by the first proxy to include a data string, and the modified message is delivered to the client; concurrently, the first proxy provides the data string/access token pair to the second proxy. When the client receives the modified message, it issues a response (that includes the data string) back to a resource server. As the response traverses the second proxy, it removes the data string and re-inserts the access token, and the resulting modified response is forwarded to the resource server.
Public/Granted literature
- US20200287885A1 Protecting sensitive information in single sign-on (SSO) to the cloud Public/Granted day:2020-09-10
Information query