Oracle Corporation
SINGLE SIGN-ON TECHNIQUES USING CLIENT SIDE ENCRYPTION AND DECRYPTION

Last updated:

Abstract:

An access management system (AMS) is disclosed that includes SSO capabilities for providing users secure access to protected resources within an enterprise using encryption keys generated by a client application. The AMS receives a request from a client application for a user to access a protected resource. In certain examples, the request comprises a client application identifier, a session identifier and a client public encryption key. The AMS determines if the session identifier points to a valid session and upon determining that the session identifier corresponds to a valid session, transmits information associated with the valid session to the client application. In certain examples, the information associated with the valid session is encrypted using the client public encryption key. Based on information associated with the valid session received from the client application, the AMS determines whether to grant or deny a user access to a protected resource within the enterprise.

Status:
Application
Type:

Utility

Filling date:

13 Feb 2020

Issue date:

19 Aug 2021