WO2010033633A2 - Method and system for enabling access to a web service provider through login based badges embedded in a third party site - Google Patents
Method and system for enabling access to a web service provider through login based badges embedded in a third party site Download PDFInfo
- Publication number
- WO2010033633A2 WO2010033633A2 PCT/US2009/057207 US2009057207W WO2010033633A2 WO 2010033633 A2 WO2010033633 A2 WO 2010033633A2 US 2009057207 W US2009057207 W US 2009057207W WO 2010033633 A2 WO2010033633 A2 WO 2010033633A2
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- party site
- service provider
- web service
- user
- login
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/41—User authentication where a single sign-on provides access to a plurality of computers
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/33—User authentication using certificates
- G06F21/335—User authentication using certificates for accessing specific resources, e.g. using Kerberos tickets
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
Definitions
- the present invention relates to the use of Internet badges which enable content from a badge provider site to be displayed on a third party site.
- Internet badges are often used by web service providers to collect information from or display information on third party sites.
- the web service provider could provide the badge or the badge may be built by a badge provider who uses the web service to store information provided through the badge or display information in the badge provided by the web service.
- Yahoo! Shopping may list tens of thousands of third party on-line shopping sites, and a user may be directed to one of such third party sites if he is interested in purchasing something from a third party site.
- Yahoo! Shopping may only want to list third party sites providing good services, and may want to collect user feedback to rate the third party sites.
- Yahoo! Shopping may collect such information through badges embedded in the third party sites, and may also display the current overall rating of a third party site and/or user ratings, if users have already rated the third party site through the same or different badge.
- Fig. 1 illustrates a currently available system for using a login based badge embedded in a third party site to collect information.
- a login based badge 102 from a web service provider 101 may be embedded in a third party site 103 (e.g., my.domain.com) through a badging server 104 and a computer network 105, so as to collect users' comments on the third party site 103.
- the badging server 104 may provide a visual interface (i.e., the badge 102) to the web service provider 101 that can be embedded in the third party site 103.
- the login based badge 102 may be displayed on the third party site 103, e.g., after a user has used the service of the third party site 103.
- the badge 102 may collect the login information through the third party site 103 and then either passes this information to the badging server 104 which in turn may route the login information to the web service provider 101 or the badge 102 may directly contact the web service provider 101 for the purpose of storing/displaying information.
- the user If the user is authenticated, he may be directed from the third party site to the web service provider 101 which displays a number of questions for rating the third party site 103, and the badge 102 may communicate with the web service provider 101 directly for saving and displaying information.
- FIG. 1 illustrates a currently available system for using a login based badge embedded in a third party site to collect information.
- FIG. 2 illustrates a system for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
- FIG. 3A illustrates a flow chart of a method for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
- Fig. 3B illustrates a flow chart of a method for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
- Fig. 4 illustrates a flow chart of a method for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
- the present invention provides a system and method which may allow a user to login to a web service provider from a third party site without leaking the user's login information to the third party site.
- a service request interceptor may authenticate the third party site to make sure that a service request is from a third party site registered with the web service provider or its associated sites, and then instruct a badging server to send an HTML markup to the third party site to enable a login page of the web service provider to be displayed as a pop up window, outside of the third party site.
- the service request interceptor may check whether the user has already logged into the web service provider, and authenticate a user to make sure that the user is registered with the web service provider. Since the user may interact with the web service provider directly, the third party site may be bypassed and users' credentials may be better protected.
- Fig. 2 illustrates a system for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
- the exemplary system may be used by a web service provider 201 (e.g., a rating service site) to collect user inputs via a login based badge 202 embedded in a third party site 203 (e.g., my.domain.com listed on Yahoo! Small Business) to rate services of the third party sites.
- the rating service site may be a part of another web service provider, e.g., Yahoo!, Yahoo! Shopping or Yahoo! Small Business, or be associated with the another web service provider.
- the rating service site and its associated sites may share user login information, and accordingly may be regarded as one badge provider.
- the third party site 203 may embed the login based badge 202 in its web pages.
- the badging server 204 may send an HTML markup to enable the login based badge 202 to be incorporated in the third party site 203.
- the login based badge 202 may be displayed after a user has used the service provided by the third party site 203.
- the badging server 204 may send an HTML markup to the third party site 203 to enable the login page for the rating service site to be displayed as a pop up window, outside of the third party site 203.
- the service request interceptor 206 may send instructions to the badging server 204 for sending the HTML markup of the login page for the rating service site after determining that a user is interested in rating the service of the third party site 203.
- the service request interceptor 206 may determine that a user is interested in rating the third party site 203 if there is an input on the login based badge 202 displayed on the third party site 203.
- the user input may be, e.g., a click on the login based badge 202, or a letter typed in a window on the login based badge 202.
- the service request interceptor 206 may authenticate the third party site to make sure that a rating request is from a third party site registered with the rating service site.
- a third party site may need to register with the web service provider to use the login based badge, and a secret may be shared between the third party site and the web service provider.
- a rating request may be sent from the third party site 203 to the rating service site.
- a signature based on the shared secret may be generated at the third party site 203 and sent together with the rating request.
- the service request interceptor 206 may intercept the rating request and authenticate the third party site 203 through signature verification based on shared secrets.
- the service request interceptor 206 may send instructions to the badging server 204 when the third party site 203 is registered with the rating service site, and may inform the user if the third party site 203 is not registered with rating service site.
- the service request interceptor 206 may check whether the user has already logged into the rating service site, and may send the instructions to the badging server 204 when the user is not logged into the rating service site.
- the service request interceptor 206 may further authenticate a user to make sure that the user is registered with the rating service site. The user authentication may be based on verification of the user's login information. [0018] Before sending the instructions to the badging server 204, the service request interceptor 206 may further determine whether the user has already rated the third party site 203, and may send the instructions when the user has not rated the third party site 203.
- the service request interceptor 206 may direct a user to the rating service site after authenticating the third party site and/or the user, so that the user may provide his rating inputs there.
- the service request interceptor 206 may be a plug-in at the web service provider 201.
- Fig. 3A illustrates a flow chart of a method for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
- the method may be used in the system shown in Fig. 2.
- the login based badge 202 may be embedded in the third party site 203 (e.g., my.domain.com listed on Yahoo! Small Business) via the badging server 204, so that the web service provider 201 , a rating service site in this example, may collect user feedback on services of the third party site 203.
- the third party site 203 e.g., my.domain.com listed on Yahoo! Small Business
- the third party site 203 may register with the rating service site, or its associated sites, and a shared secret may be issued to the third party site 203.
- the shared secret may be used by the third party site 203 to generate a signature that may be sent along with a rating request to the rating service site for authenticating the third party site 203.
- the secret may be saved in a server running the third party site 203.
- a login based badge may be incorporated in the third party site 203.
- the third party site 203 may configure the login based badge to harmonize it with other parts of the third party site 203, and add the login based badge 202 to the third party site 203.
- the third party site 203 may be loaded in a browser upon a user's request.
- the login based badge 202 may be displayed on the third party site 203.
- the login based badge 202 may be displayed on the third party site 203 after a user has used the service provided by the third party site 203.
- the third party site may be loaded in the user's browser. After the badge is loaded, user may click on the badge, and the rating request may be sent by the user's browser to the badging server 204.
- the service request interceptor 206 may determine whether the user has indicated that he is interested in rating services of the third party site 203. In one embodiment, the service request interceptor 206 may detect whether there is any input on the login based badge 202. If the user clicks on the login based badge 202 or type in a window on the login based badge 202, the service request interceptor 206 may decide that the user is interested in rating services of the third party site 203.
- the procedure may end at 399. Otherwise, at 306, the third party site 203 may send a rating request to the badging server 204 along with a signature generated at the third party site server based on the shared secret.
- the rating request may include identification of the third party site, the target of rating, a time stamp and a signature.
- the signature may be generated using javascript or PHP code. In one example, the signature may be:
- the rating request from the user's browser to the badging server 204 may be intercepted by the service request interceptor 206.
- the service request interceptor 206 may verify the signature to make sure that the rating request is from a third party site registered with the rating service site.
- the service request interceptor 206 may use parameters in the rating request (e.g., the identification of the third party site 203) and the share secret saved at the web service provider 201 to generate a signature again, and compare the generated signature and the signature received together with the rating request. If the generated signature and the received signature do not match each other, the service request interceptor 206 may inform the user at 350, and the procedure may return to 304. Otherwise, the service request interceptor 206 may decide that the third party site 203 is a registered third party site, and the procedure may proceed to 309. It should be understood that 308 may be performed earlier in the procedure, e.g., before the badge is loaded at 304 to ensure that a registered site is requesting for the badge.
- the service request interceptor 206 may determine whether the user has already logged into the rating service site. If the user has already logged into the rating service site, at 310, the service request interceptor 206 may determine whether the user has already rated the third party site 203. If the user has already rated the third party site 203, he may be so informed at 350 and the procedure may return to 304. In one embodiment, the user's rating may be displayed. If the user has not rated the third party site 203 yet, the procedure may proceed to 313, which will be described below.
- a login page for the web service provider 201 may be displayed at 31 1.
- the service request interceptor 206 may pass the user's login status to the badging server 204 or the web service provider 201 , which may then inform the badge 202 that the user has not logged in.
- the badging server 204 may indicate to the badge 202 that a new browser window should be loaded with the login page for the rating service site.
- the badge 202 may receive an HTML markup from the badging server 204 and cause a login page for the rating service site to be loaded in a new window, asking the user to enter his credentials.
- the login page for the rating service site may be displayed as a pop-up window. Consequently, the user may bypass the third party site 203 and provide his login information directly to the rating service site. The user may clearly see from the login page loaded or the URL displayed that he is entering his credentials only at the web service provider site.
- the service request interceptor 206 may validate the user by checking his login information and cookies. If the user is not a registered user, he may be so informed at 350, and the procedure may return to 304. If the user is a registered user, at 313, the service request interceptor 206 may direct the user to the rating service site and submit the user provided information thereto. In one embodiment, the service request interceptor 206 may also receive the user's rating inputs and forward the rating inputs to the web service provider 201. The procedure may then return to 304.
- the described embodiments relate to rating the service of a third party site
- the system and method described may be used to rate a product on a third party site, or may be in any situation where one web site embeds a login based badge in a second web site and collects user credentials via the login based badge.
- embodiments of the present invention may ensure that credentials are supplied by the user only at the service site and not directly in the login based badge.”
- Fig. 3A is only an example, and is not used to limit the sequence of the steps.
- 309 and 310 may be performed when the badge is first displayed, e.g., before 304, as shown in Fig. 3B.
- the service request interceptor 206 may determine whether the user has already logged into the rating service site 201. If not, the process may proceed to 304.
- the service request interceptor 206 may determine whether the user has already rated the third party site 203. If yes, the user's rating may be displayed at 360. If the user has not rated the third party site yet, the process may proceed to 305.
- 305 may be performed after 308, and may come either if the user has not logged in or if the user has logged in but has not yet rated the service.
- the service request interceptor 206 may determine whether the user has already logged into the rating service site 201 at 320. If the user has not logged in, the process may proceed to 31 1. Otherwise, the process may proceed to 313.
- Fig. 4 illustrates a flow chart of a method for displaying a login based badge according to one embodiment of the present invention.
- the method may be used in the system shown in Fig. 2, and may be performed between 303 and 304 in the process shown in Fig. 3A.
- a request for a login based badge may be sent from the third party site to the badge provider, or the rating service provider 201 in this example.
- the badging server 204 may determine whether the request to load the badge is from a registered third party site. If yes, the badge may be sent to the third party site and displayed there at 304. Otherwise, the badging server 204 may send an error response indicating that the badge is being loaded by an unauthorized site.
- the method may also be performed between 303 and 309 in the process shown in Fig. 3B.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Information Transfer Between Computers (AREA)
Abstract
A system and method which may allow a user to login a web service provider from a third party site without leaking the users login information to the third party site. A service request interceptor may authenticate the third party site to make sure that a service request is from a third party site registered with the web service provider or its associated sites, and then instruct a badging server to send an HTML markup to the third party site to enable a login page of the web service provider to be displayed as a pop up window, outside of the third party site. Before sending the instructions to the badging server, the service request interceptor may check whether the user has already logged in the web service provider, and authenticate a user to make sure that the user is registered with the web service provider. Since the user may interact with the web service provider directly, the third party site may be bypassed and users credentials may be better protected.
Description
Method and System for Enabling Access to a Web Service Provider Through Login Based Badges Embedded in a Third Party Site
Background Field of the Invention
[0001] The present invention relates to the use of Internet badges which enable content from a badge provider site to be displayed on a third party site.
Description of Related Art
[0002] Internet badges are often used by web service providers to collect information from or display information on third party sites. The web service provider could provide the badge or the badge may be built by a badge provider who uses the web service to store information provided through the badge or display information in the badge provided by the web service. In one example, Yahoo! Shopping may list tens of thousands of third party on-line shopping sites, and a user may be directed to one of such third party sites if he is interested in purchasing something from a third party site. Yahoo! Shopping may only want to list third party sites providing good services, and may want to collect user feedback to rate the third party sites. Yahoo! Shopping may collect such information through badges embedded in the third party sites, and may also display the current overall rating of a third party site and/or user ratings, if users have already rated the third party site through the same or different badge.
[0003] Fig. 1 illustrates a currently available system for using a login based badge embedded in a third party site to collect information. As shown, a login based badge 102 from a web service provider 101 (e.g., a rating service site associated with Yahoo! or Yahoo! Shopping) may be embedded in a third party site 103 (e.g., my.domain.com) through a badging server 104 and a computer network 105, so as to collect users' comments on the third party site 103. The badging server 104 may provide a visual interface (i.e., the badge 102) to the web service provider 101 that can be embedded in the third party site 103. The login based badge 102 may be displayed on the third party site 103, e.g., after a user has used the service of the third party site 103. When a user types in his login information for the rating service site through the badge 102, the badge 102 may collect the login information through the third party site 103 and then either
passes this information to the badging server 104 which in turn may route the login information to the web service provider 101 or the badge 102 may directly contact the web service provider 101 for the purpose of storing/displaying information. If the user is authenticated, he may be directed from the third party site to the web service provider 101 which displays a number of questions for rating the third party site 103, and the badge 102 may communicate with the web service provider 101 directly for saving and displaying information.
[0004] Since users' login information for the rating service site is collected through the third party site, there may be a question of trust on the third party site from the users' perspective, and there may be chances of misuse of user credentials given through the third party site. Therefore, it may be desirable to provide a system and method which may allow a web service provider to collect user input from a third party site via a login based badge while keeping users' credentials confidential.
BRIEF DESCRIPTION OF THE DRAWING FIGURES
[0005] Embodiments of the present invention are described herein with reference to the accompanying drawings, similar reference numbers being used to indicate functionally similar elements.
[0006] Fig. 1 illustrates a currently available system for using a login based badge embedded in a third party site to collect information.
[0007] Fig. 2 illustrates a system for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
[0008] Fig. 3A illustrates a flow chart of a method for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
[0009] Fig. 3B illustrates a flow chart of a method for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
[0010] Fig. 4 illustrates a flow chart of a method for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention.
DETAILED DESCRIPTION
[0011] The present invention provides a system and method which may allow a user to login to a web service provider from a third party site without leaking the user's login information to the third party site. A service request interceptor may authenticate the third party site to make sure that a service request is from a third party site registered with the web service provider or its associated sites, and then instruct a badging server to send an HTML markup to the third party site to enable a login page of the web service provider to be displayed as a pop up window, outside of the third party site. Before sending the instructions to the badging server, the service request interceptor may check whether the user has already logged into the web service provider, and authenticate a user to make sure that the user is registered with the web service provider. Since the user may interact with the web service provider directly, the third party site may be bypassed and users' credentials may be better protected. Advantages of the present invention will become apparent from the following detailed description.
[0012] Fig. 2 illustrates a system for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention. The exemplary system may be used by a web service provider 201 (e.g., a rating service site) to collect user inputs via a login based badge 202 embedded in a third party site 203 (e.g., my.domain.com listed on Yahoo! Small Business) to rate services of the third party sites. The rating service site may be a part of another web service provider, e.g., Yahoo!, Yahoo! Shopping or Yahoo! Small Business, or be associated with the another web service provider. The rating service site and its associated sites may share user login information, and accordingly may be regarded as one badge provider.
[0013] The third party site 203 may embed the login based badge 202 in its web pages. The badging server 204 may send an HTML markup to enable the login based badge 202 to be incorporated in the third party site 203. The login based badge 202 may be displayed after a user has used the service provided by the third party site 203. Upon instructions from a service request interceptor 206, the badging server 204 may send an
HTML markup to the third party site 203 to enable the login page for the rating service site to be displayed as a pop up window, outside of the third party site 203.
[0014] The service request interceptor 206 may send instructions to the badging server 204 for sending the HTML markup of the login page for the rating service site after determining that a user is interested in rating the service of the third party site 203. The service request interceptor 206 may determine that a user is interested in rating the third party site 203 if there is an input on the login based badge 202 displayed on the third party site 203. The user input may be, e.g., a click on the login based badge 202, or a letter typed in a window on the login based badge 202.
[0015] Before sending the instructions to the badging server 204, the service request interceptor 206 may authenticate the third party site to make sure that a rating request is from a third party site registered with the rating service site. In one embodiment, a third party site may need to register with the web service provider to use the login based badge, and a secret may be shared between the third party site and the web service provider. When there is a user input on the login based badge 202 displayed on the third party site 203, a rating request may be sent from the third party site 203 to the rating service site. A signature based on the shared secret may be generated at the third party site 203 and sent together with the rating request. The service request interceptor 206 may intercept the rating request and authenticate the third party site 203 through signature verification based on shared secrets. The service request interceptor 206 may send instructions to the badging server 204 when the third party site 203 is registered with the rating service site, and may inform the user if the third party site 203 is not registered with rating service site.
[0016] Before sending the instructions to the badging server 204, the service request interceptor 206 may check whether the user has already logged into the rating service site, and may send the instructions to the badging server 204 when the user is not logged into the rating service site.
[0017] Before sending the instructions to the badging server 204, the service request interceptor 206 may further authenticate a user to make sure that the user is registered with the rating service site. The user authentication may be based on verification of the user's login information.
[0018] Before sending the instructions to the badging server 204, the service request interceptor 206 may further determine whether the user has already rated the third party site 203, and may send the instructions when the user has not rated the third party site 203.
[0019] The service request interceptor 206 may direct a user to the rating service site after authenticating the third party site and/or the user, so that the user may provide his rating inputs there.
[0020] The service request interceptor 206 may be a plug-in at the web service provider 201.
[0021] Fig. 3A illustrates a flow chart of a method for enabling access to a web service provider through a badge embedded in a third party site according to one embodiment of the present invention. The method may be used in the system shown in Fig. 2. The login based badge 202 may be embedded in the third party site 203 (e.g., my.domain.com listed on Yahoo! Small Business) via the badging server 204, so that the web service provider 201 , a rating service site in this example, may collect user feedback on services of the third party site 203.
[0022] At 301 , the third party site 203 may register with the rating service site, or its associated sites, and a shared secret may be issued to the third party site 203. The shared secret may be used by the third party site 203 to generate a signature that may be sent along with a rating request to the rating service site for authenticating the third party site 203. The secret may be saved in a server running the third party site 203.
[0023] At 302, a login based badge may be incorporated in the third party site 203. The third party site 203 may configure the login based badge to harmonize it with other parts of the third party site 203, and add the login based badge 202 to the third party site 203.
[0024] At 303, the third party site 203 may be loaded in a browser upon a user's request.
[0025] At 304, the login based badge 202 may be displayed on the third party site 203. In one embodiment, the login based badge 202 may be displayed on the third party site 203 after a user has used the service provided by the third party site 203. In one embodiment, when the user requests for the third party site (where the badge is embedded), the third party site may be loaded in the user's browser. After the badge is
loaded, user may click on the badge, and the rating request may be sent by the user's browser to the badging server 204.
[0026] At 305, the service request interceptor 206 may determine whether the user has indicated that he is interested in rating services of the third party site 203. In one embodiment, the service request interceptor 206 may detect whether there is any input on the login based badge 202. If the user clicks on the login based badge 202 or type in a window on the login based badge 202, the service request interceptor 206 may decide that the user is interested in rating services of the third party site 203.
[0027] If the user is not interested in rating services of the third party site 203, the procedure may end at 399. Otherwise, at 306, the third party site 203 may send a rating request to the badging server 204 along with a signature generated at the third party site server based on the shared secret. The rating request may include identification of the third party site, the target of rating, a time stamp and a signature. The signature may be generated using javascript or PHP code. In one example, the signature may be:
Signature = 8e7cab296d86242d385ab12d9131 1166,
and the rating request may be:
http://api. ratings, yahoo. com/Widget?domain=my. domain. com&target=my_service&ts=1 1 852723272&sig=8e7cab296d86242d385ab12d91311 166
[0028] At 307, the rating request from the user's browser to the badging server 204 may be intercepted by the service request interceptor 206.
[0029] At 308, the service request interceptor 206 may verify the signature to make sure that the rating request is from a third party site registered with the rating service site. In one embodiment, the service request interceptor 206 may use parameters in the rating request (e.g., the identification of the third party site 203) and the share secret saved at the web service provider 201 to generate a signature again, and compare the generated
signature and the signature received together with the rating request. If the generated signature and the received signature do not match each other, the service request interceptor 206 may inform the user at 350, and the procedure may return to 304. Otherwise, the service request interceptor 206 may decide that the third party site 203 is a registered third party site, and the procedure may proceed to 309. It should be understood that 308 may be performed earlier in the procedure, e.g., before the badge is loaded at 304 to ensure that a registered site is requesting for the badge.
[0030] At 309, the service request interceptor 206 may determine whether the user has already logged into the rating service site. If the user has already logged into the rating service site, at 310, the service request interceptor 206 may determine whether the user has already rated the third party site 203. If the user has already rated the third party site 203, he may be so informed at 350 and the procedure may return to 304. In one embodiment, the user's rating may be displayed. If the user has not rated the third party site 203 yet, the procedure may proceed to 313, which will be described below.
[0031] If the user has not logged in the rating service site yet, a login page for the web service provider 201 , the rating service site in this embodiment, may be displayed at 31 1. In one embodiment, the service request interceptor 206 may pass the user's login status to the badging server 204 or the web service provider 201 , which may then inform the badge 202 that the user has not logged in. The badging server 204 may indicate to the badge 202 that a new browser window should be loaded with the login page for the rating service site. The badge 202 may receive an HTML markup from the badging server 204 and cause a login page for the rating service site to be loaded in a new window, asking the user to enter his credentials. In one embodiment, the login page for the rating service site may be displayed as a pop-up window. Consequently, the user may bypass the third party site 203 and provide his login information directly to the rating service site. The user may clearly see from the login page loaded or the URL displayed that he is entering his credentials only at the web service provider site.
[0032] At 312, the service request interceptor 206 may validate the user by checking his login information and cookies. If the user is not a registered user, he may be so informed at 350, and the procedure may return to 304. If the user is a registered user, at 313, the service request interceptor 206 may direct the user to the rating service site and submit the user provided information thereto. In one embodiment, the service request
interceptor 206 may also receive the user's rating inputs and forward the rating inputs to the web service provider 201. The procedure may then return to 304.
[0033] Although the described embodiments relate to rating the service of a third party site, the system and method described may be used to rate a product on a third party site, or may be in any situation where one web site embeds a login based badge in a second web site and collects user credentials via the login based badge. In such cases, embodiments of the present invention may ensure that credentials are supplied by the user only at the service site and not directly in the login based badge."
[0034] It should be understood that the flow chart in Fig. 3A is only an example, and is not used to limit the sequence of the steps. In one embodiment, 309 and 310 may be performed when the badge is first displayed, e.g., before 304, as shown in Fig. 3B. After the third party site 203 is loaded in a browser upon a user's request at 303, the service request interceptor 206 may determine whether the user has already logged into the rating service site 201. If not, the process may proceed to 304.
[0035] If the user has already logged into the rating service site 201 , at 310, the service request interceptor 206 may determine whether the user has already rated the third party site 203. If yes, the user's rating may be displayed at 360. If the user has not rated the third party site yet, the process may proceed to 305.
[0036] In one embodiment, 305 may be performed after 308, and may come either if the user has not logged in or if the user has logged in but has not yet rated the service.
[0037] In one embodiment, after 308, the service request interceptor 206 may determine whether the user has already logged into the rating service site 201 at 320. If the user has not logged in, the process may proceed to 31 1. Otherwise, the process may proceed to 313.
[0038] Fig. 4 illustrates a flow chart of a method for displaying a login based badge according to one embodiment of the present invention. The method may be used in the system shown in Fig. 2, and may be performed between 303 and 304 in the process shown in Fig. 3A. As shown, at 401 , a request for a login based badge may be sent from the third party site to the badge provider, or the rating service provider 201 in this example. At 402, the badging server 204 may determine whether the request to load the badge is from a registered third party site. If yes, the badge may be sent to the third
party site and displayed there at 304. Otherwise, the badging server 204 may send an error response indicating that the badge is being loaded by an unauthorized site. The method may also be performed between 303 and 309 in the process shown in Fig. 3B.
[0039] Several features and aspects of the present invention have been illustrated and described in detail with reference to particular embodiments by way of example only, and not by way of limitation. Those of skill in the art will appreciate that alternative implementations and various modifications to the disclosed embodiments are within the scope and contemplation of the present disclosure. Therefore, it is intended that the invention be considered as limited only by the scope of the appended claims.
Claims
1. A method of enabling access to a web service provider from a third party site through a login based badge, wherein the login based badge is embedded in the third party site, the method comprising:
intercepting a service request from the third party site to the web service provider;
authenticating the third party site; and
displaying a login page of the web service provider, wherein the login page is displayed independent of the third party site.
2. The method of claim 1 , further comprising: determining whether a user is interested in the service provided by the web service provider.
3. The method of claim 2, further comprising: determining that a user is interested in the service provided by the web service provider if the login based badge is clicked on.
4. The method of claim 2, further comprising: determining that a user is interested in the service provided by the web service provider if the login based badge is typed on.
5. The method of claim 1 , wherein the third party site is authenticated through signature verification.
6. The method of claim 5, wherein the signature is generated based on a secret shared between the third party site and the web service provider.
7. The method of claim 1 , further comprising: determining whether a user has already logged into the web service provider, and displaying the login page of the web service provider when the user has not logged in.
8. The method of claim 1 , further comprising: receiving login information of a user at the login page and determining whether the user is a registered user based on the login information.
9. The method of claim 1 , further comprising: displaying a web page of the web service provider.
10. The method of claim 1 , wherein the web service provider receives user ratings on services provided by the third party site.
11. The method of claim 10, further comprising: determining whether a user has already rated the third party site.
12. The method of claim 11 , further comprising: displaying the user's ratings if the user has already rated the third party site.
13. The method of claim 1 , further comprising: sending an HTML markup to the third party site to enable displaying of the login page of the web service provider.
14. The method of claim 1 , wherein the login page of the web service provider is displayed as a pop-up window.
15. A system for enabling access to a web service provider from a third party site through a login based badge, wherein the login based badge is embedded in the third party site, the system comprising:
a badging server for embedding the login based badge in the third party site; and
a service request interceptor, coupled between the badging server and the web service provider, intercepting a service request from the third party site to the web service provider and authenticating the third party site.
16. The system of claim 15, wherein the badging server sends an HTML markup to the third party site to enable displaying of the login page of the web service provider in response to instructions from the service request interceptor.
17. The system of claim 15, wherein the service request interceptor authenticates the third party site through signature verification.
18. A computer program product comprising a computer-readable medium having instructions which, when performed by a computer, perform a method of enabling access to a web service provider from a third party site through a login based badge, wherein the login based badge is embedded in the third party site, the method comprising:
intercepting a service request from the third party site to the web service provider;
authenticating the third party site; and
displaying a login page of the web service provider, wherein the login page is displayed independent of the third party site.
19. The computer program product of claim 18, wherein the third party site is authenticated through signature verification.
20. The computer program product of claim 18, wherein the method further comprises: determining whether a user has already logged into the web service provider, and displaying the login page of the web service provider when the user has not logged in.
21. The computer program product of claim 18, wherein the method further comprises: sending an HTML markup to the third party site to enable displaying of the login page of the web service provider.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US12/212,581 | 2008-09-17 | ||
| US12/212,581 US20100071046A1 (en) | 2008-09-17 | 2008-09-17 | Method and System for Enabling Access to a Web Service Provider Through Login Based Badges Embedded in a Third Party Site |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| WO2010033633A2 true WO2010033633A2 (en) | 2010-03-25 |
| WO2010033633A3 WO2010033633A3 (en) | 2010-07-01 |
Family
ID=42008438
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2009/057207 Ceased WO2010033633A2 (en) | 2008-09-17 | 2009-09-16 | Method and system for enabling access to a web service provider through login based badges embedded in a third party site |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20100071046A1 (en) |
| TW (1) | TWI397297B (en) |
| WO (1) | WO2010033633A2 (en) |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7950047B2 (en) * | 2008-02-22 | 2011-05-24 | Yahoo! Inc. | Reporting on spoofed e-mail |
| US8700892B2 (en) | 2010-03-19 | 2014-04-15 | F5 Networks, Inc. | Proxy SSL authentication in split SSL for client-side proxy agent resources with content insertion |
| US9053304B2 (en) | 2012-07-13 | 2015-06-09 | Securekey Technologies Inc. | Methods and systems for using derived credentials to authenticate a device across multiple platforms |
| US9524198B2 (en) | 2012-07-27 | 2016-12-20 | Google Inc. | Messaging between web applications |
| CN104253686B (en) * | 2013-06-25 | 2017-12-29 | 华为技术有限公司 | Method, equipment and the system that account logs in |
| US9172697B1 (en) | 2013-09-16 | 2015-10-27 | Kabam, Inc. | Facilitating users to obfuscate user credentials in credential responses for user authentication |
| US10397199B2 (en) | 2016-12-09 | 2019-08-27 | Microsoft Technology Licensing, Llc | Integrated consent system |
| CN118449782B (en) * | 2024-07-05 | 2024-09-06 | 成都数之联科技股份有限公司 | Application request processing method, device, equipment and medium based on heaven and earth micro-service |
Family Cites Families (17)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5790677A (en) * | 1995-06-29 | 1998-08-04 | Microsoft Corporation | System and method for secure electronic commerce transactions |
| US6985953B1 (en) * | 1998-11-30 | 2006-01-10 | George Mason University | System and apparatus for storage and transfer of secure data on web |
| US6339773B1 (en) * | 1999-10-12 | 2002-01-15 | Naphtali Rishe | Data extractor |
| US7155739B2 (en) * | 2000-01-14 | 2006-12-26 | Jbip, Llc | Method and system for secure registration, storage, management and linkage of personal authentication credentials data over a network |
| US7191467B1 (en) * | 2002-03-15 | 2007-03-13 | Microsoft Corporation | Method and system of integrating third party authentication into internet browser code |
| US7500262B1 (en) * | 2002-04-29 | 2009-03-03 | Aol Llc | Implementing single sign-on across a heterogeneous collection of client/server and web-based applications |
| AU2003261124A1 (en) * | 2002-07-02 | 2004-01-23 | America Online Incorporated | Seamless cross-site user authentication status detection and automatic login |
| AU2002364902A1 (en) * | 2002-10-18 | 2004-05-13 | American Express Travel Related Services Company, Inc. | Device independent authentication system and method |
| US7305470B2 (en) * | 2003-02-12 | 2007-12-04 | Aol Llc | Method for displaying web user's authentication status in a distributed single login network |
| US7788485B2 (en) * | 2003-08-07 | 2010-08-31 | Connell John M | Method and system for secure transfer of electronic information |
| US7444519B2 (en) * | 2003-09-23 | 2008-10-28 | Computer Associates Think, Inc. | Access control for federated identities |
| WO2006020095A2 (en) * | 2004-07-16 | 2006-02-23 | Geotrust, Inc. | Security systems and services to provide identity and uniform resource identifier verification |
| KR100718440B1 (en) * | 2005-08-10 | 2007-05-14 | 서울신용평가정보 주식회사 | Authentication agent method, server and system using identification code |
| KR100820327B1 (en) * | 2006-02-22 | 2008-04-08 | 김용태 | System and method for providing live content implemented on the homepage |
| US7912762B2 (en) * | 2006-03-31 | 2011-03-22 | Amazon Technologies, Inc. | Customizable sign-on service |
| US7565332B2 (en) * | 2006-10-23 | 2009-07-21 | Chipin Inc. | Method and system for providing a widget usable in affiliate marketing |
| US7917754B1 (en) * | 2006-11-03 | 2011-03-29 | Intuit Inc. | Method and apparatus for linking businesses to potential customers through a trusted source network |
-
2008
- 2008-09-17 US US12/212,581 patent/US20100071046A1/en not_active Abandoned
-
2009
- 2009-09-01 TW TW098129361A patent/TWI397297B/en active
- 2009-09-16 WO PCT/US2009/057207 patent/WO2010033633A2/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| TWI397297B (en) | 2013-05-21 |
| WO2010033633A3 (en) | 2010-07-01 |
| US20100071046A1 (en) | 2010-03-18 |
| TW201014303A (en) | 2010-04-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US8683201B2 (en) | Third-party-secured zones on web pages | |
| US20100071046A1 (en) | Method and System for Enabling Access to a Web Service Provider Through Login Based Badges Embedded in a Third Party Site | |
| CN106716960B (en) | User authentication method and system | |
| US8775245B2 (en) | Secure coupon distribution | |
| JP4856755B2 (en) | Customizable sign-on service | |
| US9825917B2 (en) | System and method of dynamic issuance of privacy preserving credentials | |
| US9641513B2 (en) | Methods and systems for controlling mobile terminal access to a third-party server | |
| US7793095B2 (en) | Distributed hierarchical identity management | |
| US8826395B2 (en) | Method of improving online credentials | |
| US20090300097A1 (en) | Systems and methods for facilitating clientless form-filling over a network | |
| CN106716918A (en) | User authentication method and system | |
| US20150180857A1 (en) | Simple user management service utilizing an access token | |
| US8275991B2 (en) | On-line membership verification | |
| US20040128390A1 (en) | Method and system for user enrollment of user attribute storage in a federated environment | |
| US8595815B2 (en) | System and method for selectively granting access to digital content | |
| CN104579671B (en) | Auth method and system | |
| WO2007037703A1 (en) | Human factors authentication | |
| US20100192068A1 (en) | Method and apparatus to perform online credential reporting | |
| US20140298443A1 (en) | System and method of extending a host website | |
| JP4758575B2 (en) | User authentication method and user authentication system | |
| KR20140081041A (en) | Authentication Method and System for Service Connection of Internet Site using Phone Number | |
| CN105429934B (en) | Method and apparatus, readable storage medium storing program for executing, the terminal of HTTPS connectivity verification | |
| US20090164477A1 (en) | Method of electronic sales lead verification | |
| US20120151560A1 (en) | Portable Identity Rating | |
| US20140143539A1 (en) | Web tokens with a signature of a web page visitor |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 09815145 Country of ref document: EP Kind code of ref document: A2 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 09815145 Country of ref document: EP Kind code of ref document: A2 |