Secure computing resource enhanced single sign-on process

By generating and verifying signature certificates in the authentication system, the problem of users having to enter credentials multiple times is solved, enabling single sign-on for secure computing resources, improving efficiency and security, and reducing the number of times users need to enter credentials and security risks.

CN117178518BActive Publication Date: 2026-07-31MICROSOFT TECHNOLOGY LICENSING LLC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
MICROSOFT TECHNOLOGY LICENSING LLC
Filing Date
2022-04-22
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

In existing authentication systems, users need to enter credentials multiple times to access distributed computing resources of different systems or levels, resulting in inefficiency, increased security risks, and a poor user experience.

Method used

By processing secure data such as credentials, tokens, and certificates at specific computing entities, generating and verifying signature certificates, a single sign-on process is implemented, reducing the number of times users need to enter information and improving security and efficiency.

Benefits of technology

It enables single sign-on to secure computing resources, saving computing resources, improving security and efficiency, reducing the number of user inputs, and reducing security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117178518B_ABST
    Figure CN117178518B_ABST
Patent Text Reader

Abstract

The techniques disclosed herein provide an enhanced single sign-on process for secure computing resources such as virtual machines or hosted applications. In some configurations, this technique processes different types of security data, such as credentials, tokens, certificates, and reference objects, at a specific computing entity within the system to provide a single sign-on process for granting access to the secure computing resource from a client computing device. In one illustrative example, selected types of security data, such as certificates, are generated from tokens and claims at a specific computing resource, such as an agent operating on a virtual machine. In another example, a signed version of the certificate can be stored and verified at the virtual machine. By generating certificates at such a specific computing resource, the computing resource can use a secure single sign-on process to verify a person's credentials without requiring the person to provide credentials multiple times.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] There are many different types of authentication systems that can use a person's electronic credentials to grant access to different systems or different levels of distributed computing systems. In some cases, authentication systems can grant access to virtual machines, server-based applications, and other services using only a single set of credentials. Despite the many advancements in authentication systems, there remain many scenarios where users cannot seamlessly use a single set of credentials to provide access to different systems or different levels of distributed computing systems.

[0002] In an illustrative example, when a person uses a client computing device to access a virtual machine running on a server, the user may be required to perform multiple manual steps to provide credentials at multiple levels of the platform. First, the user may need to log in to the client device, which may require the user to provide their credentials, such as an identifier and password, smart card, etc. Then, once logged in to the client device, the user may again have to manually enter their credentials to access services provided by the server, such as virtual machine and application services. This requirement results in redundant manual input, which, in addition to exposing the system to greater security risks, significantly hinders service adoption.

[0003] In some existing systems, tokens can be used to grant access to multiple components of a computing system. In such systems, a token is generated when a user provides a set of credentials (referred to herein as “credentials”). Tokens can be used to grant access to applications and other resources on the computing device. Tokens can also be duplicated to grant lower-level access to the operating system. While existing systems offer flexibility, tokens cannot provide access to all aspects of a distributed computing system, such as virtual machines running on remote servers. Therefore, requiring users to re-enter their credentials when attempting to access such resources can negatively impact the user experience.

[0004] This disclosure addresses these and other technical challenges. Summary of the Invention

[0005] The techniques disclosed herein provide an enhanced single sign-on process for secure computing resources such as virtual machines or hosted applications. In some configurations, this technique processes different types of security data, such as credentials, tokens, certificates, and reference objects, at a specific computing entity within the system to provide a single sign-on process for granting access to the secure computing resource from a client computing device. In one illustrative example, selected types of security data, such as certificates, are generated from tokens and claims at a specific computing resource, such as an agent operating on a virtual machine. In another example, a signed version of the certificate can be stored and verified at the virtual machine. By generating certificates at such a specific computing resource, the computing resource can use a secure single sign-on process to verify a person's credentials without requiring the person to provide credentials multiple times.

[0006] In an illustrative example, when credentials are received at an identity provider, the system can generate a token. This token and claim can be transmitted to a specific computing resource, such as a virtual machine, where an agent on that virtual machine processes the token to generate a certificate. In response to the detection of one or more criteria, a certificate can be transmitted to a certificate authority, where it can be signed. The signed certificate can then be transmitted to an agent, which routes it to the computing resource, where the agent can process the signed certificate into a security object. The security object can then be inserted into the connection between the client computing device and the computing resource to allow secure access to the computing resource from the client computing device.

[0007] By reading the following detailed description and reviewing the associated drawings, the features and technical advantages explicitly described above will become clear. This summary is provided to introduce a set of concepts in a simplified form, which will be further described in the detailed description below. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to help determine the scope of the claimed subject matter. The term "technology" may, for example, refer to systems(s), methods(s), computer-readable instructions(s), modules(s), algorithms, hardware logic, and / or operations(s), as permitted in the context described above and throughout this document. Attached Figure Description

[0008] Detailed embodiments are described with reference to the accompanying drawings. In the drawings, the leftmost numeral(s) of the reference numeral(s) identifies the drawing in which the reference numeral(s) first appear. Identical reference numerals in different drawings indicate similar or identical items. References to individual items within a plurality of items can be made using reference numerals with letters from a alphabetical sequence to refer to each individual item. General references to these items can be made using specific reference numerals without a letter sequence.

[0009] Figure 1This is a system block diagram of a single sign-on process for secure computing resources used in an authentication system.

[0010] Figure 2A This illustrates various aspects of the single sign-on process for secure computing resources in the first state of the single sign-on process of the authentication system.

[0011] Figure 2B This illustrates various aspects of the single sign-on process for secure computing resources in the second state of the single sign-on process of the authentication system.

[0012] Figure 2C This illustrates various aspects of the single sign-on process for secure computing resources in the third state of the single sign-on process of the authentication system.

[0013] Figure 2D This illustrates various aspects of the single sign-on process for secure computing resources in the fourth state of the single sign-on process of the authentication system.

[0014] Figure 2E This illustrates various aspects of the single sign-on process for secure computing resources in the fifth state of the single sign-on process of the authentication system.

[0015] Figure 3A This paper illustrates various aspects of a reference object's single sign-on process using secure computing resources in the first state of the single sign-on process of an authentication system.

[0016] Figure 3B This illustrates various aspects of a reference object's single sign-on process using secure computing resources in the second state of the single sign-on process of an authentication system.

[0017] Figure 3C This illustrates various aspects of a reference object's single sign-on process system that utilizes secure computing resources in the third state of the single sign-on process of an authentication system.

[0018] Figure 3D This illustrates various aspects of a reference object's single sign-on process using secure computing resources in the fourth state of the single sign-on process of an authentication system.

[0019] Figure 3E This illustrates various aspects of a reference object's single sign-on process using secure computing resources in the fifth state of the single sign-on process of an authentication system.

[0020] Figure 3FThis illustrates various aspects of a reference object's single sign-on process using secure computing resources in the sixth state of the single sign-on process of an authentication system.

[0021] Figure 4 This is a flowchart illustrating various aspects of the routines used to enable the techniques disclosed herein.

[0022] Figure 5 This is a computer architecture diagram, which illustrates the computer hardware and software architecture used in computing systems capable of realizing various aspects of the technologies and sciences presented in this article.

[0023] Figure 6 This is a diagram illustrating the distributed computing environment that enables the various aspects of the technologies and sciences presented in this article.

[0024] Figure 7 This is a computer architecture diagram illustrating the computing device architecture of computing devices capable of realizing the various aspects of the technologies and sciences presented in this article. Detailed Implementation

[0025] The disclosed techniques improve the efficiency, security, and functionality of authentication systems by providing single sign-on flow access to secure computing resources such as virtual machines, remote virtual machines, or hosted applications. The techniques disclosed herein process different types of security data, such as credentials, tokens, certificates, and reference objects, at specific computing entities within the system to provide a single sign-on flow for granting access to secure computing resources from client computing devices. The disclosed techniques address several technical problems associated with certain authentication systems. For example, the disclosed techniques address the problem that tokens cannot provide access to all aspects of distributed computing systems, such as virtual machines running on remote servers. As described in more detail below, the disclosed techniques can also improve security by reducing the amount of manual user input (i.e., hacker surface opportunities) required to gain access to resources through single sign-on flow authentication. The disclosed techniques can also save computing resources, such as processing cycles, memory resources, and networking resources, by requiring only a single username and password input from the user to gain access to remote virtual machines.

[0026] Traditionally, authentication systems exist where users may have to enter credentials multiple times to gain access to resources associated with the system. For example, a user must enter a username and password to access the authentication system. Then, the user must also re-enter the username and password to access certain resources associated with the authentication system. This traditional approach leads to inefficiency in authentication systems by requiring users to enter credentials multiple times to gain access to resources. It also increases the security risk of authentication systems by increasing the amount of user input required to gain access to resources (i.e., the opportunity for hackers to exploit). Furthermore, it reduces the functionality of authentication systems by requiring users to enter credentials multiple times to gain access to resources.

[0027] The single sign-on process features disclosed herein offer several benefits (e.g., technical effects) to improving the efficiency, security, and functionality of authentication systems by providing single sign-on access to secure computing resources. The disclosed technique saves computational resources, such as processing cycles, memory resources, and networking resources, of the authentication system by requiring only a single username and password input from the user to gain access to secure computing resources. The disclosed technique also improves the security of the authentication system by reducing the number of user inputs required to gain access to resources (i.e., hacker surface opportunities). The disclosed technique further improves the efficiency and security of the authentication system by automating the user associated with token access to secure computing resources. Figures 1 to 7 An authentication system with single sign-on process features is shown, and the various operational states of the single sign-on process of the authentication system are described.

[0028] Now for reference Figure 1 The following shows and describes various aspects of the single sign-on process for secure computing resources used to authenticate system features. Figure 1 A system 100, including infrastructure 101 and services 103, is illustrated for providing a single sign-on process between secure computing resources 124 (such as virtual machines 124A or hosted applications 124B) and client devices 102. Client device 102 may also be referred to as a "client" or "client device".

[0029] Typically, client device 102 may include a computing device. Examples of computing devices include server computers, mobile phones, PDAs, smartphones, desktop computers, netbooks, tablets, and / or laptops. Client device 102 may include an agent that allows client device 102 to identify remote computers, virtual machines, or computing devices over a network connection. The agent also allows client device 102 to identify applications on the computing device over the network connection.

[0030] Infrastructure 101 may include gateway 111, agent 112, and database 113. Typically, gateway 111 may include a remote desktop gateway that provides a secure connection to the server via the Remote Desktop Protocol using Secure Sockets Layer (SSL). Agent 112 may typically include a remote desktop agent. A remote desktop agent is software that allows client devices 102 to access various types of server-hosted desktops and applications. Database 113 may typically include user information, such as user configuration data. For example, when a user wants to access secure computing resource 124, they can provide information during the configuration phase. Users can indicate their preferred specific identity provider or certificate authority. In this process, database 113 may store these preferences, along with the network address of each preferred resource and the client's address information.

[0031] Service 103 may include Infrastructure as a Service (IaaS). Typically, IaaS can include online services that provide high-level APIs to dereference various low-level details of the underlying network infrastructure, such as physical compute resources, location, data partitioning, scaling, security, backup, etc. Hypervisors (such as Xen, Oracle VirtualBox, Oracle VM, KVM, VMware ESX / ESXi, or Hyper-V, LXD) run virtual machines as guests. Hypervisor pools within cloud operating systems can support a large number of virtual machines and can scale services up and down according to different customer needs.

[0032] Service 103 may include secure computing resources 124, which may be virtual machine 124A, application 124B, or other computing resources used for processing or storing data. Virtual machine 124A may include an instance of an operating system running in a secure environment, separate from other operating system instances running in other secure environments. Application 124B may include applications running on the service, such as calendar applications, word processing applications, etc.

[0033] Service 103 may include identity provider 121. Typically, identity provider 121 may include Active Directory Federation Service Server (ADFS). ADFS can provide users with single sign-on access to certain systems and certain applications located across organizational boundaries. ADFS can use federated identities to link users across multiple identity management systems.

[0034] Service 103 may include access to Certificate Authority 123. Certificate Authority 123 can be accessed locally or remotely. Typically, Certificate Authority 123 is the entity that issues digital certificates. Signing certificate 157 is an example of a digital certificate. A digital certificate proves the validity of information in the certificate. For example, this information could be the username of credential 151, or the username and password of credential 151, or any other type of credential. A digital certificate can also prove ownership of the public key through the naming subject of the certificate. This allows other dependent parties to rely on the signature or assertions about the private key corresponding to the certified public key. Certificate Authority 123 acts as a trusted third party trusted by the certificate's subject, owner, and parties relying on the certificate.

[0035] like Figure 2A As shown, in the first phase of the single sign-on process, identity provider 121 receives a set of credentials 151 from client device 102. Credentials 151 from client device 102 are transmitted to identity provider 121. Typically, credentials 151 identify the user of client device 102 to identity provider 121. Credentials 151 may include a username and password.

[0036] The first phase may also include, in response to determining that credential set 151 meets one or more criteria, generating a token 152 indicating the validity of credential set 151, which defines a claim 153 for a single sign-on process associated with the user of credential set 151. In an implementation, identity provider 121 may generate the token 152 and claim 153 associated with credential 151. Claim 153 is included within token 152. Token 152 may be an alphanumeric string used in token-based authentication. For example, a user may authenticate once using a username and password and then receive token 152 in return. The received token 152 can then be used on behalf of the user when authenticating to certain resources.

[0037] Statement 153 can provide information about credential 151. For example, statement 153 may include the username or username and password for credential 151. Statement 153 may also inform identity provider 121 that token 152 has been logged into or communicated with identity provider 121 during previous communications. Statement 153 may also inform identity provider 121 that token 152 can be exchanged for a login certificate because it has been logged into or communicated with identity provider 121 in the past. Certificate 155 may also be referred to as a login certificate.

[0038] Now for reference Figure 2BIn the second phase of the single sign-on process, a token 152 is transmitted to client device 102, wherein client device 102 is configured to communicate the token 152 with a request 154 to initiate a single sign-on process for accessing secure computing resource 124 of service 103. In the implementation, token 152 and claim 153 are transmitted to client device 102. Communication to client device 102 may also include transmitting the identified resource associated with token 152.

[0039] Now for reference Figure 2C In the third phase of the single sign-on process, a request 154 from client device 102 to access secure computing resource 124 of service 103 is received at proxy 112. Request 154 includes a token 152 that defines the single sign-on process. In some implementations, client device 102 makes request 154 through proxy 112 to access secure computing resource 124 associated with token 152. In some implementations, receiving request 154 may also initiate a predetermined location to send a request to obtain a certificate 155 signature. For example, the URL of identity provider 121 may be provided as the location to send the request to obtain a certificate 155 signature. The predetermined location may be provided by a user, an internal source, or an external source.

[0040] The third phase can also respond to the determination request 154, which includes a token 152 and a claim 153 generated by the identity provider 121, by causing the secure computing resource 124 to generate a certificate 155 from the token 152, wherein the secure computing resource 124 is configured to send the certificate 155 and the token 152 to the identity provider 121. In some implementations, the request 154 via the proxy 112 can cause the secure computing resource 124 to generate the certificate 155 based on the claim 153. The claim can provide the entity for the certificate 155. The certificate 155 can provide identifying information about the entity. For example, the certificate 155 can provide information that the entity is a username or username and password from credential 151. The generation of the certificate 155 can cause the certificate 155, the token 152, and the claim 153 to be sent to the identity provider 121. The identity provider 121 can be predetermined by the client. The identity provider 121 can also register to be able to request a signed certificate on behalf of a user ID based on the token 152.

[0041] Now for reference Figure 2DIn the fourth phase of the single sign-on process, the identity provider 121 verifies the token 152 and sends the certificate 155 to the certificate authority 123 to generate a signed certificate 157 from the certificate 155, wherein the certificate authority 123 includes security data provided by the user for signing the certificate 155. In the implementation, the identity provider 121 verifies the token 152. After successful verification of the token 152, the certificate 155 is sent to the certificate authority 123. The certificate authority 123 verifies the certificate 155 and generates the signed certificate 157. The signed certificate 157 is then sent to the secure computing resource 124.

[0042] Now for reference Figure 2E In the fifth phase of the single sign-on process, a signing certificate 157 is sent to secure computing resource 124. The signing certificate 157 enables client device 102 to access secure computing resource 124 via connection 202 without requiring client device 102 to resubmit the credential set 151 used to access secure computing resource 124. In this implementation, the signing certificate 157 is inserted into connection 202. Connection 202 enables communication between secure computing resource 124 and client device 102. For example, connection 202 can be a secure, encrypted connection between secure computing resource 124 and client device 102. Inserting the signing certificate 157 into connection 202 enables client device 102 to access secure computing resource 124 via connection 202 without requiring client device 102 to resubmit the credential set 151 used to access secure computing resource 124.

[0043] Now, referring to alternative embodiments of a single sign-on process for secure computing resources used in an authentication system, features are shown and described below. Figures 3A to 3F An embodiment of a single sign-on process that can be used in a multi-tenant system is shown, in which a reference object can be used to establish a connection.

[0044] like Figure 3A As shown, in the first phase of the single sign-on process, identity provider 121 receives a set of credentials 151 from client device 102. Credentials 151 from client device 102 are transmitted to identity provider 121. Credentials 151 identify the user of client device 102 to identity provider 121. Credentials 151 may include a username and password.

[0045] The first phase may also include, in response to determining that the credential set 151 meets one or more criteria, generating a token 152 indicating the validity of the credential set 151, which defines a claim 153 for a single sign-on process associated with the user of the credential set 151. In an implementation, the identity provider 121 may generate the token 152 and claim 153 associated with the credential 151. The claim 153 is included within the token 152. The token 152 may be an alphanumeric string used in token-based authentication. For example, a user may authenticate once using a username and password and then receive a token 152 in return. The received token 152 can then be used on behalf of the user when authenticating to certain resources.

[0046] Statement 153 can provide information about credential 151. For example, statement 153 may include the username or username and password for credential 151. Statement 153 may also inform identity provider 121 that token 152 has been logged into or communicated with identity provider 121 during previous communications. Statement 153 may also inform identity provider 121 that token 152 can be exchanged for a login certificate because it has been logged into or communicated with identity provider 121 in the past. Certificate 155 may also be referred to as a login certificate.

[0047] Now for reference Figure 3B In the second phase of the single sign-on process, a token 152 is transmitted to client device 102, which is configured to communicate the token 152 with a request 154 to initiate a single sign-on process for accessing secure computing resource 124 of service 103. In this implementation, token 152 and a claim 153 are transmitted to client device 102. Communication to client device 102 may also include transmitting the identified resource associated with token 152.

[0048] Now for reference Figure 3C In the third phase of the single sign-on process, a request 154 from client device 102 to access secure computing resource 124 of service 103 is received at proxy 112. Request 154 includes a token 152 that defines the single sign-on process claim 153. In some implementations, client device 102 makes request 154 through proxy 112 to access secure computing resource 124 associated with token 152. In some implementations, receiving request 154 may also initiate a predetermined location to send a request to obtain a signing certificate 155. For example, the URL of identity provider 121 may be provided as the location to send the request to initiate obtaining a signing certificate 155. The predetermined location may be provided by a user, an internal source, or an external source.

[0049] The third phase can also respond to the determination request 154, which includes a token 152 and a claim 153 generated by the identity provider 121, by causing the secure computing resource 124 to generate a certificate 155 from the token 152, wherein the secure computing resource 124 is configured to transmit the certificate 155 to the agent 112. In the implementation, the request 154 from the agent 112 causes the secure computing resource 124 to generate the certificate 155 based on the claim 153. The claim can provide the entity of the certificate 155. The certificate 155 can provide identification information about the entity. For example, the certificate 155 can provide information that the entity is a username or username and password from credential 151.

[0050] In the implementation, the generation of certificate 155 causes certificate 155, token 152, and claim 153 to be transmitted back to agent 112. When the system supports a multi-tenant cloud (not shown), communication via agent 112 can be used. A multi-tenant cloud is a cloud computing architecture that allows customers to share computing resources in a public or private cloud. Each tenant's data is isolated and remains invisible to other tenants.

[0051] Now for reference Figure 3D In the fourth phase of the single sign-on process, agent 112 sends certificate 155 to identity provider 121, which then verifies token 152 and sends certificate 155 to certificate authority 123 to generate a signing certificate 157 from certificate 155. Certificate authority 123 includes secure data provided by the user for signing certificate 155. In this implementation, agent 112 transmits certificate 155, token 152, and statement 153 to identity provider 121. Identity provider 121 can be pre-determined by the client. Identity provider 121 can also register to request a signing certificate on behalf of the user ID based on token 152.

[0052] In the implementation, identity provider 121 verifies token 152. After successful verification of token 152, certificate 155 is sent to certificate authority 123. Certificate authority 123 verifies certificate 155 and generates a signature certificate 157. Signature certificate 157 is sent to secure computing resource 124.

[0053] The fourth stage may also include transmitting the signing certificate 157 to the secure computing resource 124, causing the secure computing resource 124 to generate a reference object 158 ​​configured to provide access to the secure computing resource 124. Upon receiving the signing certificate 157, the secure computing resource 124 generates the reference object 158 ​​based on the signing certificate 157. The reference object 158 ​​is an identifier of the signing certificate 157. In some implementations, the reference object 158 ​​may include the serial number of the signing certificate 157. The reference object 158 ​​is used to locate the signing certificate 157 of the secure computing resource 124.

[0054] Now for reference Figure 3E In the fifth stage of the single sign-on process, reference object 158 ​​communicates with gateway 111. In one implementation, reference object 158 ​​is transmitted to gateway 111.

[0055] Now for reference Figure 3F In the sixth stage of the single sign-on process, where gateway 111 is configured to insert reference object 158 ​​into connection 202 between client device 102 and secure computing resource 124, allowing access to secure computing resource 124 without requiring the user to provide a set of credentials 151 for accessing secure computing resource 124, wherein inserting reference object 158 ​​causes reference object 158 ​​to be transmitted to secure computing resource 124 for verification. Connection 202 is communication between secure computing resource 124 and client device 102. For example, connection 202 could be a secure, encrypted connection using a remote desktop protocol over HTTPS.

[0056] Gateway 111 can establish connection 202 between client device 102 and secure computing resource 124. Reference object 158 ​​is inserted into connection 202. Inserting reference object 158 ​​into connection 202 enables client device 102 to access secure computing resource 124 through connection 202 using reference object 158, without requiring client device 102 to resubmit credentials 151 for accessing secure computing resource 124.

[0057] Now go to Figure 4 The following shows and describes aspects of routine 400 for providing single sign-on process access to secure computing resources. It should be understood that the operations of the methods disclosed herein are not presented in any particular order, and it is possible and contemplated to perform some or all of the operations in one of several alternative orders. For ease of description and illustration, these operations have been presented in the order of demonstration. Operations may be added, omitted, and / or performed simultaneously without departing from the scope of the appended claims.

[0058] It should also be understood that the method shown can end at any time and does not need to be fully executed. Some or all of the operations of the method and / or substantially equivalent operations can be performed by executing computer-readable instructions contained on a computer storage medium as defined below. The term "computer-readable instructions" and its variations as used herein are widely used to include routines, applications, application modules, program modules, programs, components, data structures, algorithms, etc. Computer-readable instructions can be implemented on a variety of system configurations, including single-processor or multi-processor systems, minicomputers, mainframe computers, personal computers, handheld computing devices, microprocessor-based programmable consumer electronics, combinations thereof, etc.

[0059] Therefore, it should be understood that the logical operations described herein are implemented as (1) a sequence of actions or program modules implemented by a computer running on a computing system and / or (2) as interconnected machine logic circuits or circuit modules within the computing system. The implementation is a matter of choice depending on the performance and other requirements of the computing system. Therefore, the logical operations described herein are referred to differently as states, operations, structural devices, actions, or modules. These operations, structural devices, actions, and modules can be implemented in software, firmware, dedicated digital logic, and any combination thereof.

[0060] For example, the operation of routine 400 is described herein as being implemented at least in part by a module that performs the features disclosed herein, which may be a dynamic link library (DLL), a static link library, a function generated by an application programming interface (API), a compiled program, an interpreted program, a script, or any other set of executable instructions. Data may be stored in a data structure within one or more memory components. Data can be retrieved from a data structure by addressing a link or reference to the data structure.

[0061] Although the illustrations below refer to the components in the accompanying drawings, it should be understood that the operation of routine 400 can also be implemented in many other ways. For example, routine 400 can be implemented at least in part by the processor or local circuitry of another remote computer. Furthermore, one or more operations of routine 400 can alternatively or additionally be implemented at least in part by a chipset that works alone or in combination with other software modules. In the examples described below, one or more modules of the computing system can receive and / or process the data disclosed herein. Any services, circuits, or applications suitable for providing the techniques disclosed herein can be used in the operations described herein.

[0062] refer to Figure 4 Routine 400 begins at operation 402, where identity provider 121 generates token 152, which defines claim 153 for a single sign-on process derived from credential 151. Operation 402 may involve receiving credential set 151 from client device 102 at identity provider 121. Identity provider 121 generates token 152 indicating the validity of credential set 151 in response to determining that credential set 151 meets one or more criteria. Token 152 defines claim 153 for a single sign-on process associated with user of credential set 151.

[0063] In the implementation, identity provider 121 can generate a token 152 and a claim 153 associated with credential 151. Claim 153 is included within token 152. Token 152 can be an alphanumeric string used in token-based authentication.

[0064] Next, at operation 404, virtual machine 124A generates certificate 155 from token 152 at virtual machine 124A. Operation 404 may involve determining a request 154 that includes token 152 generated by identity provider 121 and claim 153, causing virtual machine 124A to generate certificate 155 from token 152.

[0065] In the implementation, request 154 from proxy 112 causes virtual machine 124A to generate certificate 155 based on claim 153. Claim 153 can provide the entity of certificate 155. Certificate 155 can provide identification information about the entity. For example, certificate 155 can provide information that the entity is a username or username and password from credential 151.

[0066] Next, at operation 406, certificate authority 123 signs certificate 155 in response to a request to connect to virtual machine 124A. Operation 406 may involve, in response to a request to connect to virtual machine 124A, causing agent 112 to send certificate 155 to identity provider 121, causing identity provider 121 to verify token 152, and sending certificate 155 to certificate authority 123 to generate a signed certificate 157 from certificate 155.

[0067] In the implementation, identity provider 121 verifies token 152. After successful verification of token 152, certificate 155 is sent to certificate authority 123. Certificate authority 123 verifies certificate 155 and generates a signing certificate 157. Signing certificate 157 is sent to virtual machine 124A.

[0068] Next, at operation 408, virtual machine 124A generates reference object 158 ​​from signing certificate 157. Operation 408 may involve causing virtual machine 124A to generate reference object 158 ​​configured to provide access to virtual machine 124A. After receiving signing certificate 157, virtual machine 124A generates reference object 158 ​​based on signing certificate 157. Reference object 158 ​​is an identifier of signing certificate 157.

[0069] In some implementations, reference object 158 ​​may include the serial number of signing certificate 157. Reference object 158 ​​is used to locate the signing certificate 157 of virtual machine 124A.

[0070] Next, in operation 410, where connection 202 is used, reference object 158 ​​is used to allow access to virtual machine 124A using a single sign-on process. Operation 410 may involve enabling reference object 158 ​​to communicate with gateway 111.

[0071] In this implementation, reference object 158 ​​is transmitted to gateway 111. Gateway 111 is configured to insert reference object 158 ​​into connection 202 between client device 102 and virtual machine 124A, allowing access to virtual machine 124A without requiring the user to provide a set of credentials 151 for accessing virtual machine 124A. The insertion of reference object 158 ​​enables communication between reference object 158 ​​and virtual machine 124A used to authenticate reference object 158. Connection 202 is the communication between virtual machine 124A and client device 102. For example, connection 202 could be a secure, encrypted connection using a remote desktop protocol over HTTPS.

[0072] Figure 5 Details of an exemplary computer architecture 500 capable of executing the program components described herein are shown. Therefore, Figure 5 The computer architecture 500 shown illustrates the architecture of a server computer, mobile phone, PDA, smartphone, desktop computer, netbook computer, tablet computer, and / or laptop computer. Computer architecture 500 can be used to execute any aspect of the software components presented herein.

[0073] Figure 5 The computer architecture 500 shown includes a central processing unit 502 (“CPU”), system memory 504 (including random access memory 506 (“RAM”) and read-only memory (“ROM”) 508), and a system bus 510 coupling the memory 504 to the CPU 502. A basic input / output system is stored in the ROM 508, which contains basic routines such as those that facilitate the transfer of information between elements within the computer architecture 500 during startup. The computer architecture 500 also includes a mass storage device 512 for storing an operating system 507, other data, and one or more applications. The mass storage device 512 may also store other items, such as a database 113.

[0074] Mass storage device 512 is connected to CPU 502 via a mass storage controller (not shown) connected to bus 510. Mass storage device 512 and its associated computer-readable media provide non-volatile storage for computer architecture 500. Although the description of computer-readable media contained herein refers to mass storage devices such as solid-state drives, hard disks, or CD-ROM drives, those skilled in the art will understand that computer-readable media can be any available computer storage or communication medium accessible by computer architecture 500.

[0075] Communication media include computer-readable instructions, data structures, program modules, or other data in modulated data signals, such as carrier waves or other transmission mechanisms, and include any transmission medium. The term "modulated data signal" refers to a signal whose one or more characteristics are altered or set in a manner that encodes information in the signal. By way of example and not limitation, communication media include wired media such as wired networks or direct wired connections, and wireless media such as acoustic, RF, infrared, and other wireless media. Any combination of the foregoing should also be included within the scope of computer-readable media.

[0076] By way of example and not limitation, one or more computer storage media may include volatile and non-volatile, removable and non-removable media implemented by any method or technology for storing information such as computer-readable instructions, data structures, program modules or other data. For example, computer media includes, but is not limited to, RAM, ROM, EPROM, EEPROM, flash memory or other solid-state memory technologies, CD-ROM, digital versatile disc (DVD), HD-DVD, Blu-ray or other optical storage, cassette tape, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible by computer architecture 800. For the purposes of the claims, the phrases “non-transient computer storage medium,” “computer storage medium,” “computer-readable storage medium,” and variations thereof do not include waves, signals and / or other transient and / or intangible communication media themselves.

[0077] Depending on the configuration, computer architecture 500 can operate in a networked environment using a logical connection to a remote computer via network 556 and / or another network (not shown). Computer architecture 500 can be connected to network 556 via network interface unit 514 connected to bus 510. It should be understood that network interface unit 514 can also be used to connect to other types of networks and remote computer systems. Computer architecture 500 may also include an input / output controller 516 for receiving and processing input from various other devices, including a keyboard, mouse, or electronic pen. Figure 5 (Not shown in the image). Similarly, the input / output controller 516 can output to a display screen, printer, or other type of output device (not shown in the image). Figure 5 (The output is not shown in the image.)

[0078] It should be understood that the software components described herein, when loaded into and executed, can transform the CPU 502 and the entire computer architecture 500 from a general-purpose computing system into a dedicated computing system customized to facilitate the functions presented herein. The CPU 502 can be composed of any number of transistors or other discrete circuit elements, which can individually or collectively present any number of states. More specifically, in response to executable instructions contained within the software modules disclosed herein, the CPU 502 can operate as a finite state machine. These computer-executable instructions can transform the CPU 502 by specifying how it transitions between states, thereby transforming the transistors or other discrete hardware elements constituting the CPU 502.

[0079] Encoding the software modules presented herein can also alter the physical structure of the computer-readable medium presented herein. In different implementations of this specification, the specific transformation of the physical structure can depend on various factors. Examples of these factors may include, but are not limited to, the technology used to implement the computer-readable medium, whether the computer-readable medium is primary or secondary storage, etc. For example, if the computer-readable medium is implemented as a semiconductor-based memory, the software disclosed herein can be encoded on the computer-readable medium by transforming the physical state of the semiconductor memory. For example, the software can transform the state of transistors, capacitors, or other discrete circuit elements constituting the semiconductor memory. The software can also transform the physical state of these components to store data thereon.

[0080] As another example, the computer-readable medium disclosed herein can be implemented using magnetic or optical techniques. In such an implementation, when software is encoded therein, the software presented herein can alter the physical state of the magnetic or optical medium. These transformations may include altering the magnetic properties of a specific location within a given magnetic medium. These transformations may also include altering the physical characteristics or properties of a specific location within a given optical medium to change the optical properties of those locations. Other transformations of the physical medium are also possible without departing from the scope and spirit of this description; the foregoing examples are provided only for the convenience of this discussion.

[0081] In light of the above, it should be understood that many types of physical transformations occur in computer architecture 500 in order to store and execute the software components presented herein. It should also be understood that computer architecture 500 may include other types of computing devices, including handheld computers, embedded computer systems, personal digital assistants, and other types of computing devices known to those skilled in the art. It is also contemplated that computer architecture 500 may not include… Figure 5 All components shown may include Figure 5 Other components not explicitly shown in the document, or those that can be utilized with Figure 5 The architecture shown is completely different.

[0082] Figure 6 An illustrative distributed computing environment 600 capable of executing the software components described herein is depicted. Therefore, Figure 6 The distributed computing environment 600 shown can be used to execute any aspect of the software components presented herein. For example, the distributed computing environment 600 can be used to execute various aspects of the software components described herein.

[0083] According to various implementations, the distributed computing environment 600 includes a computing environment 602 that operates on, communicates with, or partially operates on the network 604. The network 604 may be, or may include, the above-mentioned references. Figure 5 Network 556 is described. Network 604 may also include various access networks. One or more client devices 606A to 606N (hereinafter collectively and / or simply referred to as "client 606", and also referred to herein as computing devices) can be accessed via network 604 and / or other connections ( Figure 5 (Not shown) communicates with computing environment 602. In one illustrated configuration, client 606 includes computing device 606A, such as a laptop computer, desktop computer, or other computing device; tablet or rack-mount computing device (“tablet computing device”) 606B; mobile computing device 606C, such as a mobile phone, smartphone, or other mobile computing device; server computer 606D; and / or other devices 606N. It should be understood that any number of clients 606 may communicate with computing environment 602. This document references... Figure 5 and Figure 6 Two example computing architectures for client 606 are illustrated and described herein. It should be understood that the client 606 and computing architectures illustrated and described herein are illustrative and should not be construed as being limited in any way.

[0084] In the illustrated configuration, computing environment 602 includes application server 608, data storage device 610, and one or more network interfaces 612. Depending on the implementation, the functionality of application server 608 may be provided by one or more server computers that perform or communicate with network 604 as part of network 604. Application server 608 may host various services, virtual machines, portals, and / or other resources. In the illustrated configuration, application server 608 hosts one or more virtual machines 614 for hosting applications or other functions. Depending on the implementation, virtual machine 614 hosts one or more applications and / or software modules to enable efficient testing as disclosed herein. It should be understood that this configuration is illustrative and should not be construed as limiting in any way. Application server 608 also hosts or provides access to one or more portals, linked pages, websites, and / or other information (“website portals”) 616.

[0085] Depending on the implementation, application server 608 may also include one or more email services 618 and one or more messaging services 620. Email service 618 may include email (“email”) service. Email service 618 may also include various personal information management (“PIM”) and presence services, including but not limited to calendar service, contact management service, collaboration service and / or other services. Messaging service 620 may include, but is not limited to, instant messaging service, chat service, forum service and / or other communication services.

[0086] Application server 608 may also include one or more social networking services 622. Social networking service 622 may include various social networking services, including but not limited to services for sharing or posting status updates, instant messaging, links, photos, videos, and / or other information; services for commenting on or displaying interest in articles, products, blogs, or other resources; and / or other services. In some configurations, social networking service 622 is provided or included by or is part of Facebook Social Networking Service, LinkedIn Professional Networking Service, MySpace Social Networking Service, Foursquare Geographic Networking Service, YAMMER Office Colleague Networking Service, etc. In other configurations, social networking service 622 is provided by other services, sites, and / or providers that may or may not be explicitly referred to as social networking providers. For example, some websites allow users to interact with each other during various activities and / or contexts via email, chat services, and / or other means, such as reading published articles, commenting on goods or services, posting, collaborating, playing games, etc. Examples of such services include, but are not limited to, Microsoft's Windows LIVE and XBOX LIVE services from Redmond, Washington. Other services are possible and anticipated.

[0087] Social networking service 622 may also include commenting, blogging, and / or microblogging services. Examples of such services include, but are not limited to, Yelp commenting service, Kudzu commenting service, OfficeTalk enterprise microblogging service, Twitter messaging service, Google Buzz service, and / or other services. It should be understood that the above list of services is not exhaustive, and for the sake of brevity, many additional and / or alternative social networking services 622 are not mentioned herein. Therefore, the above configuration is illustrative and should not be construed as being limited in any way. Depending on the implementation, social networking service 622 may host one or more applications and / or software modules for providing the functionality described herein. For example, any of application servers 608 may communicate with or facilitate the functionality and features described herein. For example, social networking applications, email clients, messaging clients, or browsers running on a telephone or any other client 606 may communicate with network service 622 and even partially facilitate the above references. Figure 6 The functions described herein. Any device or service described herein can be used as a resource to supplement data, including email servers, storage servers, etc.

[0088] like Figure 6 As shown, application server 608 can also host other services, applications, portals, and / or other resources (“other resources”) 624. Other resources 624 may include, but are not limited to, document sharing, presentation, or any other functionality. Therefore, it can be understood that computing environment 602 can provide integration with various email, messaging, social networks, and / or other services or resources based on the concepts and techniques disclosed herein.

[0089] As described above, computing environment 602 may include data storage device 610. Depending on the implementation, the functionality of data storage device 610 may be provided by one or more databases operating on or communicating with network 604. The functionality of data storage device 610 may also be provided by one or more server computers configured to host data for computing environment 602. Data storage device 610 may include, host, or provide one or more physical or virtual data storage devices 626A-626N (collectively and / or collectively referred to as “data storage” 626). Data storage 626 is configured to host data and / or other data used or created by application server 608. Although not explicitly stated... Figure 6 As shown, data storage 626 can also host or store web page documents, Word documents, presentation documents, data structures, algorithms executed by the recommendation engine, and / or other data used by any application or other module. Aspects of data storage 626 can be associated with services used for storing files.

[0090] The computing environment 602 can communicate with or be accessed by the network interface 612. The network interface 612 may include various types of network hardware and software for supporting communication between two or more computing devices, including but not limited to computing devices and servers. It should be understood that the network interface 612 can also be used to connect to other types of networks and / or computer systems.

[0091] It should be understood that the distributed computing environment 600 described herein can provide any number of virtual computing resources and / or other distributed computing functions to any aspect of the software elements described herein, and these virtual computing resources and / or other distributed computing functions can be configured to perform any aspect of the software components disclosed herein. According to various implementations of the concepts and techniques disclosed herein, the distributed computing environment 600 provides the software functions described herein as a service to computing devices. It should be understood that computing devices can include real or virtual machines, including but not limited to server computers, network servers, personal computers, mobile computing devices, smartphones, and / or other devices. Therefore, various configurations of the concepts and techniques disclosed herein enable any device configured to access the distributed computing environment 600 to utilize the functions described herein to provide aspects of the techniques disclosed herein. In a particular example, as described above, the techniques described herein can be at least partially implemented through... Figure 6 It is implemented by working in conjunction with a web browser application on an application server 608.

[0092] Now go to Figure 7 This document describes an illustrative computing device architecture 700 for a computing device capable of executing various software components described herein to enable the techniques disclosed herein. The computing device architecture 700 is suitable for computing devices that facilitate mobile computing in part due to form factor, wireless connectivity, and / or battery-powered operation. In some configurations, the computing device includes, but is not limited to, mobile phones, tablet devices, portable video game devices, etc. The computing device architecture 700 can be applied to... Figure 1 and Figure 6 Any computing device shown. Furthermore, aspects of the computing device architecture 700 can be applied to traditional desktop computers, portable computers (e.g., telephones, laptops, notebooks, ultra-portable computers, and netbooks), server computers, and such as those referenced herein. Figure 1 and Figure 6 Other computer systems described. For example, the single-touch and multi-touch aspects disclosed below can be applied to desktop computers that use touchscreens or certain other touch devices such as touch trackpads or touch mice.

[0093] Figure 7The computing device architecture 700 shown includes a processor 702, a memory component 704, a network connectivity component 706, a sensor component 708, an input / output (“I / O”) component 710, and a power supply component 712. In the illustrated configuration, the processor 702 communicates with the memory component 704, the network connectivity component 706, the sensor component 708, the input / output (“I / O”) component 710, and the power supply component 712. Although no connections are shown between the various components in Figure 12, these components can interact to perform device functions. In some configurations, these components are arranged to communicate via one or more buses (not shown).

[0094] Processor 702 includes a central processing unit (“CPU”) configured to process data, execute computer-executable instructions for one or more applications, and communicate with other components of computing device architecture 700 to perform the various functions described herein. Processor 702 can be used to perform aspects of the software components presented herein, particularly those that utilize touch input in at least part.

[0095] In some configurations, processor 702 includes a graphics processing unit (“GPU”) configured to accelerate operations performed by the CPU, including but not limited to operations performed by general scientific and / or engineering computing applications and graphics-intensive computing applications such as high-resolution video (e.g., 720p, 1080p, and higher resolution), video games, and 3D (“3D”) modeling applications. In some configurations, processor 702 is configured to communicate with a discrete GPU (not shown). In any case, the CPU and GPU can be configured according to a co-processing CPU / GPU computing model, wherein the sequential portions of the application are executed on the CPU, while the computationally intensive portions are accelerated by the GPU.

[0096] In some configurations, processor 702, together with one or more other components described below, is a system-on-a-chip (“SoC”) or is included therein. For example, an SoC may include processor 702, a GPU, one or more of network connectivity components 706, and one or more of sensor components 708. In some configurations, processor 702 is fabricated in part using package-on-package (“PoP”) integrated circuit packaging technology. Processor 702 may be a single-core or multi-core processor.

[0097] Processor 702 can be built based on the ARM architecture, which is licensed from ARM Holdings in Cambridge, UK. Alternatively, processor 702 can be built based on the x86 architecture, for example, from Intel Corporation in Mountain View, California, and other companies. In some configurations, processor 702 is a SNAPDRAGON SoC available from QUALCOMM in San Diego, California; a TEGRA SoC available from NVIDIA in Santa Clara, California; a HUMMINGBIRD SoC available from SAMSUNG in Seoul, South Korea; an Open Multimedia Application Platform (“OMAP”) SoC available from Texas Instruments in Dallas, Texas; a custom version of any of the above SoCs; or a proprietary SoC.

[0098] Memory component 704 includes random access memory (“RAM”) 714, read-only memory (“ROM”) 716, integrated storage memory (“integrated storage device”) 718, and removable storage memory (“removable storage device”) 720. In some configurations, RAM 714 or a portion thereof, ROM 716 or a portion thereof, and / or some combination of RAM 714 and ROM 716 are integrated in processor 702. In some configurations, ROM 716 is configured to store firmware, an operating system or a portion thereof (e.g., an operating system kernel), and / or a bootloader to load the operating system kernel from integrated storage device 718 and / or removable storage device 720.

[0099] Integrated storage device 718 may include solid-state memory, hard disk drive, or a combination of solid-state memory and hard disk drive. Integrated storage device 718 may be soldered or otherwise connected to a logic board on which processor 702 and other components described herein may also be connected. Therefore, integrated storage device 718 is integrated into a computing device. Integrated storage device 718 is configured to store an operating system or portions thereof, applications, data, and other software components described herein.

[0100] Removable storage device 720 may include solid-state storage, hard disk drive (HDD), or a combination of solid-state storage and HDD. In some configurations, removable storage device 720 is provided in place of integrated storage device 718. In other configurations, removable storage device 720 is configured as an additional, optional storage device. In some configurations, removable storage device 720 is logically combined with integrated storage device 718, such that the total available storage capacity is available as the total combined storage capacity. In some configurations, the user is shown the total combined capacity of integrated storage device 718 and removable storage device 720, rather than the individual storage capacities of integrated storage device 718 and removable storage device 720.

[0101] The removable storage device 720 is configured to be inserted into a removable storage memory slot (not shown) or other mechanism, through which the removable storage device 720 is inserted and secured, facilitating communication between the removable storage device 720 and other components of a computing device, such as processor 702. The removable storage device 720 can be implemented in various memory card formats, including but not limited to PC cards, compact flash memory cards, memory sticks, secure digital cards (“SD”), mini SD, micro SD, universal integrated circuit cards (“UICC”) (e.g., user identity modules (“SIM” or universal SIM (“USIM”)), proprietary formats, etc.

[0102] It is understood that one or more of the memory components 704 may store an operating system. Depending on the configuration, the operating system includes, but is not limited to, Windows Mobile OS from Microsoft Corporation in Redmond, Washington; Windows Phone OS from Microsoft Corporation; Windows from Microsoft Corporation; Palm WebOS from Hewlett-Packard Corporation in Palo Alto, California; Blackberry OS from Research in Motion Limited in Waterloo, Ontario, Canada; iOS from Apple Inc. in Cupertino, California; and Android OS from Google Inc. in Mountain View, California. Other operating systems are expected.

[0103] Network connectivity component 706 includes a wireless wide area network component (“WWAN component”) 722, a wireless local area network component (“WLAN component”) 724, and a wireless personal area network component (“WPAN component”) 726. Network connectivity component 706 facilitates communication to and from network 756 or another network, which may be a WWAN, WLAN, or WPAN. Although only network 756 is shown, network connectivity component 706 can facilitate communication with networks including... Figure 6 Simultaneous communication with multiple networks, including network 656. For example, network connectivity component 706 can facilitate simultaneous communication with multiple networks via one or more of WWAN, WLAN, or WPAN.

[0104] Network 756 may be or may include a WWAN, such as a mobile telecommunications network that provides voice and / or data services to a computing device utilizing computing device architecture 700 via a WWAN component 722 using one or more mobile telecommunications technologies. Mobile telecommunications technologies may include, but are not limited to, Global System for Mobile Communications (“GSM”), Code Division Multiple Access (“CDMA”) ONE, CDMA7000, Universal Mobile Telecommunications System (“UMTS”), Long Term Evolution (“LTE”), and Global Interoperability for Microwave Access (“WiMAX”). Furthermore, network 756 may utilize various channel access methods (which may or may not be used by the aforementioned standards), including but not limited to Time Division Multiple Access (“TDMA”), Frequency Division Multiple Access (“FDMA”), CDMA, Wideband CDMA (“W-CDMA”), Orthogonal Frequency Division Multiplexing (“OFDM”), Space Division Multiple Access (“SDMA”), etc. Data communications can be provided using General Packet Radio Service (“GPRS”), Enhanced Evolved Global Data Rate (“EDGE”), including High-Speed ​​Downlink Packet Access (“HSDPA”), Enhanced Uplink (“EUL”) or otherwise referred to as High-Speed ​​Uplink Packet Access (“HSUPA”), Evolved HSPA (“HSPA+”), LTE, and various other current and future wireless data access standards. Network 756 can be configured to provide voice and / or data communications using any combination of the above technologies. Network 756 can be configured or adapted to provide voice and / or data communications according to future generation technologies.

[0105] In some configurations, WWAN component 722 is configured to provide dual multi-mode connectivity to network 756. For example, WWAN component 722 can be configured to provide connectivity to network 756, where network 756 provides services via GSM and UMTS technologies or some other combination of technologies. Alternatively, multiple WWAN components 722 can be used to perform this function and / or provide additional functionality to support other incompatible technologies (i.e., technologies that cannot be supported by a single WWAN component). WWAN component 722 can facilitate similar connectivity to multiple networks (e.g., UMTS and LTE networks).

[0106] Network 756 may be a WLAN operating according to one or more Institute of Electrical and Electronics Engineers (“IEEE”) 802.11 standards, such as IEEE 802.11a, 802.11b, 802.11g, 802.11n, and / or future 802.11 standards (collectively referred to herein as Wi-Fi). Draft 802.11 standards are anticipated. In some configurations, the WLAN is implemented using one or more wireless Wi-Fi access points. In some configurations, the one or more wireless Wi-Fi access points are another computing device connected to a WWAN used as a Wi-Fi hotspot. WLAN component 724 is configured to connect to network 756 via the Wi-Fi access points. This connection may be protected by various encryption technologies, including but not limited to Wi-Fi Protected Access (“WPA”), WPA2, Wired Equivalent Privacy (“WEP”), etc.

[0107] Network 756 may be a WPAN operating according to the Infrared Data Association (“IrDA”), Bluetooth, Wireless Universal Serial Bus (“USB”), Z-Wave, ZigBee, or some other short-range wireless technology. In some configurations, WPAN component 726 is configured to facilitate communication via the WPAN with other devices such as peripherals, computers, or other computing devices.

[0108] Sensor assembly 708 includes a magnetometer 728, an ambient light sensor 730, a proximity sensor 732, an accelerometer 734, a gyroscope 736, and a global positioning system sensor (“GPS sensor”) 738. Other sensors, such as, but not limited to, temperature sensors or impact detection sensors, are also expected to be integrated into the computing device architecture 700.

[0109] Magnetometer 728 is configured to measure the strength and direction of a magnetic field. In some configurations, magnetometer 728 provides measurements to a compass application stored in a component of memory assembly 704 to provide the user with accurate orientation in a reference frame including basic directions such as north, south, east, and west. Similar measurements can be provided to navigation applications that include a compass component. Other uses of the measurements obtained by magnetometer 728 are also contemplated.

[0110] Ambient light sensor 730 is configured to measure ambient light. In some configurations, ambient light sensor 730 provides measurements to an application stored in a component of memory component 704 to automatically adjust the brightness of the display (as described below) to compensate for low-light and high-light environments. Other uses for the measurements obtained by ambient light sensor 730 are also anticipated.

[0111] The proximity sensor 732 is configured to detect the presence of an object or thing near the computing device without direct contact. In some configurations, the proximity sensor 732 detects the presence of a user's body (e.g., a user's face) and provides that information to an application stored within a component of memory component 704, which uses the proximity information to enable or disable certain functions of the computing device. For example, a phone application may automatically disable the touchscreen (as described below) in response to receiving proximity information, so that the user's face does not inadvertently end a call or enable / disable other functions within the phone application during a call. Other uses of the proximity detected by the proximity sensor 732 are also anticipated.

[0112] Accelerometer 734 is configured to measure appropriate acceleration. In some configurations, the output from accelerometer 734 is used by an application as an input mechanism to control certain functions of the application. For example, the application could be a video game where a character, part of it, or an object is moved or otherwise manipulated in response to input received via accelerometer 734. In some configurations, the output from accelerometer 734 is provided to the application for switching between lateral and longitudinal modes, calculating coordinate acceleration, or detecting falls. Other uses of accelerometer 734 are also anticipated.

[0113] The gyroscope 736 is configured to measure and maintain orientation. In some configurations, the output from the gyroscope 736 is used by the application as an input mechanism to control certain functions of the application. For example, the gyroscope 736 can be used to accurately identify motion within a 3D environment of a video game application or some other application. In some configurations, the application utilizes the outputs from the gyroscope 736 and the accelerometer 734 to enhance control over certain functions of the application. Other uses of the gyroscope 736 are anticipated.

[0114] GPS sensor 738 is configured to receive signals from GPS satellites for calculating location. The location calculated by GPS sensor 738 can be used by any application that needs or benefits from location information. For example, the location calculated by GPS sensor 738 can be used with navigation applications to provide directions from that location to a destination or from a destination to that location. Furthermore, GPS sensor 738 can be used to provide location information to external location-based services (e.g., E911 services). GPS sensor 738 can utilize one or more of network connectivity components 706 to obtain location information generated via Wi-Fi, WiMAX, and / or cellular triangulation techniques to assist GPS sensor 738 in achieving location positioning. GPS sensor 738 can also be used in assisted GPS (“A-GPS”) systems. GPS sensor 738 can also operate in conjunction with other components such as processor 702 to generate positioning data for computing device 700.

[0115] I / O component 710 includes a display 740, a touchscreen 742, a data I / O interface component (“data I / O”) 744, an audio I / O interface component (“audio I / O”) 746, a video I / O interface component (“video I / O”) 748, and a camera 750. In some configurations, the display 740 and the touchscreen 742 are combined. In some configurations, two or more of the data I / O component 744, the audio I / O component 746, and the video I / O component 748 are combined. I / O component 710 may include a discrete processor configured to support the various interfaces described below, or may include processing functions built into processor 702.

[0116] Display 740 is an output device configured to present information in a visual form. Specifically, display 740 can display graphical user interface (“GUI”) elements, text, images, videos, notifications, virtual buttons, virtual keyboards, message sending and receiving data, Internet content, device status, time, date, calendar data, preferences, map information, location information, and any other information that can be presented visually. In some configurations, display 740 is a liquid crystal display (“LCD”) using any active or passive matrix technology and any backlight technology (if used). In some configurations, display 740 is an organic light-emitting diode (“OLED”) display. Other types of displays are anticipated.

[0117] Touchscreen 742, also referred to herein as a "touch-enabled screen," is an input device configured to detect the presence and location of a touch. Touchscreen 742 may be a resistive touchscreen, a capacitive touchscreen, a surface acoustic wave touchscreen, an infrared touchscreen, an optical imaging touchscreen, a dispersive signal touchscreen, an acoustic pulse identification touchscreen, or may utilize any other touchscreen technology. In some configurations, touchscreen 742 is integrated as a transparent layer on top of display 740, allowing a user to interact with objects or other information presented on display 740 using one or more touches. In other configurations, touchscreen 742 is a touchpad integrated onto the surface of a computing device excluding display 740. For example, a computing device may have a touchscreen integrated on top of display 740 and a touchpad on a surface opposite display 740.

[0118] In some configurations, touchscreen 742 is a single-touch touchscreen. In other configurations, touchscreen 742 is a multi-touch touchscreen. In some configurations, touchscreen 742 is configured to detect discrete touches, single-touch gestures, and / or multi-touch gestures. For convenience, these are collectively referred to herein as gestures. Several gestures will now be described. It should be understood that these gestures are illustrative and not intended to limit the scope of the appended claims. Furthermore, the described gestures, additional gestures, and / or alternative gestures can be implemented in software used with touchscreen 742. Therefore, developers can create gestures specific to particular applications.

[0119] In some configurations, the touchscreen 742 supports tap gestures, whereby a user taps the touchscreen 742 once on an item presented on the display 740. Tap gestures can be used for various reasons, including but not limited to, opening or launching anything the user taps. In some configurations, the touchscreen 742 supports double-tap gestures, whereby a user taps the touchscreen 742 twice on an item presented on the display 740. Double-tap gestures can be used for various reasons, including but not limited to zooming in or out in stages. In some configurations, the touchscreen 742 supports tap and hold gestures, whereby a user taps the touchscreen 742 and holds the touchscreen for at least a predetermined time. Tap and hold gestures can be used for various reasons, including but not limited to opening a context-specific menu.

[0120] In some configurations, the touchscreen 742 supports panning gestures, where a user places their finger on the touchscreen 742 and maintains contact with it while moving their finger across it. Panning gestures can be used for a variety of reasons, including but not limited to moving across a screen, image, or menu at a controlled speed. Multi-finger panning gestures are also expected. In some configurations, the touchscreen 742 supports swipe gestures, where a user swipes their finger in the direction they wish the screen to move. Swipe gestures can be used for a variety of reasons, including but not limited to scrolling horizontally or vertically within a menu or page. In some configurations, the touchscreen 742 supports pinch and stretch gestures, where a user pinches or stretches two fingers (e.g., thumb and forefinger) on the touchscreen 742. Pinch and stretch gestures can be used for a variety of reasons, including but not limited to gradually zooming in or out of a website, map, or image.

[0121] Although the above gestures are described using the reference to the use of one or more fingers to perform the gestures, other attachments such as toes or objects such as a stylus can be used to interact with the touchscreen 742. Therefore, the above gestures should be understood as illustrative and should not be interpreted as limiting in any way.

[0122] Data I / O interface component 744 is configured to facilitate inputting and outputting data to and from a computing device. In some configurations, data I / O interface component 744 includes a connector configured to provide a wired connection between the computing device and a computer system, for example, for synchronous operation purposes. The connector can be a proprietary connector or a standardized connector, such as USB, micro USB, mini USB, etc. In some configurations, the connector is a docking connector for docking the computing device with another device such as a docking station, audio equipment (e.g., a digital music player), or video equipment.

[0123] Audio I / O interface component 746 is configured to provide audio input and / or output capabilities to a computing device. In some configurations, audio I / O interface component 746 includes a microphone configured to acquire audio signals. In some configurations, audio I / O interface component 746 includes a headphone jack configured to provide connectivity for headphones or other external speakers. In some configurations, audio I / O interface component 746 includes a speaker for outputting audio signals. In some configurations, audio I / O interface component 746 includes an optical audio cable output.

[0124] Video I / O interface component 748 is configured to provide video input and / or output capabilities to a computing device. In some configurations, video I / O interface component 748 includes a video connector configured to receive video as input from another device (e.g., a video media player such as a DVD or BLURAY player) or to send video as output to another device (e.g., a monitor, television, or some other external display). In some configurations, video I / O interface component 748 includes a High Definition Multimedia Interface (“HDMI”), mini HDMI, micro HDMI, DisplayPort, or proprietary connector for inputting / outputting video content. In some configurations, video I / O interface component 748 or a portion thereof is combined with audio I / O interface component 746 or a portion thereof.

[0125] Camera 750 can be configured to capture still images and / or video. Camera 750 can utilize a charge-coupled device (“CCD”) or complementary metal-oxide-semiconductor (“CMOS”) image sensor to capture images. In some configurations, camera 750 includes a flash to assist in taking pictures in low-light environments. The camera 750's settings can be implemented as hardware or software buttons.

[0126] Although not shown, the computing device architecture 700 may also include one or more hardware buttons. Hardware buttons can be used to control certain operational aspects of the computing device. Hardware buttons can be dedicated buttons or multi-purpose buttons. Hardware buttons can be mechanical or sensor-based.

[0127] The power assembly 712 shown includes one or more batteries 752 that can be connected to a battery fuel gauge 754. The batteries 752 can be rechargeable or disposable. Rechargeable battery types include, but are not limited to, lithium polymer, lithium-ion, nickel-cadmium, and nickel-metal hydride. Each of the batteries 752 can be made from one or more batteries.

[0128] The battery fuel gauge 754 can be configured to measure battery parameters such as current, voltage, and temperature. In some configurations, the battery fuel gauge 754 is configured to measure the effects of battery discharge rate, temperature, lifespan, and other factors to predict remaining lifespan within a certain percentage of error. In some configurations, the battery fuel gauge 754 provides measurements to an application configured to use the measurements to present useful power management data to a user. Power management data may include one or more of the following: battery percentage used, remaining battery percentage, battery status, remaining time, remaining capacity (e.g., in watt-hours), current consumption, and voltage.

[0129] The power supply assembly 712 may also include a power connector that can be combined with one or more of the aforementioned I / O assemblies 710. The power supply assembly 712 can interface with an external power system or charging device through the I / O assemblies.

[0130] The following terms are supplementary to this disclosure.

[0131] Example Clause 1. A method for performing on a computing system, the method comprising: receiving a set of credentials from a client device at an identity provider; generating a token indicating the validity of the credential set in response to determining that the credential set meets one or more criteria, the token defining a claim for a single sign-on process associated with the credential set; transmitting the token to the client device, wherein the client device is configured to transmit a token having a request for initiating a single sign-on process for accessing a secure computing resource of a service; receiving a request for accessing the secure computing resource of the service from the client device at an agent, wherein the request includes a token defining a claim for the single sign-on process; causing the secure computing resource to generate a certificate from the token in response to determining that the request includes a token and a claim generated by the identity provider, wherein the secure computing resource is configured to transmit the certificate and the token to the identity provider; causing the identity provider to verify the token and send the certificate to a certificate authority to generate a signing certificate from the certificate, wherein the certificate authority includes secure data provided by a user for signing the certificate; and sending the signing certificate to the secure computing resource, wherein the signing certificate enables the client device to access the secure computing resource via a connection without requiring the client device to resubmit the credential set for accessing the secure computing resource.

[0132] Example Clause 2. The method according to Clause 1, wherein at the identity provider, a set of credentials is received from the client device, the set of credentials is logged into the identity provider, thereby generating a token, wherein when the token is returned to the identity provider, the identity provider initiates the exchange of the token for a certificate.

[0133] Example Clause 3. According to the method of Clause 1, the secure computing resource is a remote virtual machine, virtual machine, container, or data repository.

[0134] Example Clause 4. The method of Clause 1, wherein the token is sent to a secure computing resource registered with the user associated with the credentials.

[0135] Example Clause 5. The method according to Clause 1, wherein by transmitting a token from the agent to the secure computing resource, the secure computing resource generates a certificate from the token, wherein the receipt of the token at the secure computing resource causes the generation of the certificate at the secure computing resource.

[0136] Example Clause 6. According to the method of Clause 5, where the certificate includes a username and password from the credentials, and the certificate authority verifies the username and password from the credentials.

[0137] Example Clause 7. The method of Clause 1, wherein the certificate is routed to the Certificate Authority based on the address provided by a profile established by the user-configured security settings.

[0138] Example Clause 8. According to the method of Clause 1, the certificate and the signing certificate are deleted at a predetermined time after the signing certificate enables access to secure computing resources.

[0139] Example Clause 9. A method for performing on a computing system, the method comprising: receiving a set of credentials from a client device at an identity provider; generating a token indicating the validity of the credential set in response to determining that the credential set meets one or more criteria, the token defining a claim for a single sign-on process associated with the credential set; transmitting the token to the client device, wherein the client device is configured to transmit a token having a request for initiating a single sign-on process for accessing a secure computing resource of a service; receiving a request for accessing the secure computing resource of the service from the client device at an agent, wherein the request includes a token defining a claim for the single sign-on process; and, in response to determining that the request includes a token and a claim generated by the identity provider, causing the secure computing resource to generate a certificate from the token, wherein the secure computing resource is configured to... The process involves: transmitting the certificate to a proxy; causing the proxy to transmit the certificate to an identity provider, causing the identity provider to verify the token, and sending the certificate to a certificate authority to generate a signed certificate from the certificate, wherein the certificate authority includes security data provided by the user for signing the certificate; causing the signed certificate to be transmitted to a secure computing resource, causing the secure computing resource to generate a reference object, the reference object being configured to provide access to the secure computing resource; and causing the reference object to be transmitted to a gateway, wherein the gateway is configured to insert the reference object into the connection between the client device and the secure computing resource, enabling access to the secure computing resource without requiring the user to provide a set of credentials for accessing the secure computing resource, wherein the insertion of the reference object causes the reference object to be transmitted to the secure computing resource for verification of the reference object.

[0140] Example Clause 10. The method according to Clause 9, wherein at the identity provider, a set of credentials is received from the client device, the set of credentials is logged into the identity provider, thereby generating a token, wherein when the token is returned to the identity provider, the identity provider initiates the exchange of the token for a certificate.

[0141] Example Clause 11. The method according to Clause 9, wherein the secure computing resource is a remote virtual machine, virtual machine, container, or data repository.

[0142] Example Clause 12. The method according to Clause 9, wherein the token is sent to a secure computing resource registered with the user associated with the credentials.

[0143] Example Clause 13. The method according to Clause 9, wherein by transmitting a token from an agent to a secure computing resource, the secure computing resource generates a certificate from the token, wherein the receipt of the token at the secure computing resource causes the generation of the certificate at the secure computing resource.

[0144] Example Clause 14. The method of Clause 9, wherein the certificate is routed to the Certificate Authority based on the address provided in the configuration file, which is established by the user to configure security settings.

[0145] Example Clause 15. According to the method of Clause 9, the certificate and the signing certificate are deleted at a predetermined time after the signing certificate has been granted access to the secure computing resources.

[0146] A computer-readable storage medium having encoded computer-executable instructions thereon, the computer-executable instructions causing one or more processing units of a system to: receive a set of credentials from a client device at an identity provider; generate a token indicating the validity of the credential set in response to determining that the credential set meets one or more criteria, the token defining a claim for a single sign-on process associated with the credential set; transmit the token to the client device, wherein the client device is configured to transmit a token having a request for initiating a single sign-on process for accessing a secure computing resource of a service; receive a request for accessing the secure computing resource of the service from the client device at an agent, wherein the request includes a token defining a claim for the single sign-on process; cause the secure computing resource to generate a certificate from the token in response to determining that the request includes a token and a claim generated by the identity provider, wherein the secure computing resource is configured to transmit the certificate and the token to the identity provider; cause the identity provider to verify the token and send a certificate transmission to a certificate authority to generate a signed certificate from the certificate, wherein the certificate authority includes secure data provided by a user for signing the certificate; and send the signed certificate to the secure computing resource, wherein the signed certificate enables the client device to access the secure computing resource via a connection without requiring the user to resubmit the credential set for accessing the secure computing resource.

[0147] Example Clause 17. A computer-readable storage medium pursuant to Clause 16, wherein at the identity provider, a set of credentials is received from a client device, the set of credentials is logged into the identity provider, a token is generated, and wherein when the token is returned to the identity provider, the identity provider initiates the exchange of the token for a certificate.

[0148] Example Clause 18. A computer-readable storage medium pursuant to Clause 16, wherein the secure computing resource is a remote virtual machine, virtual machine, container, or data repository.

[0149] Example Clause 19. A computer-readable storage medium pursuant to Clause 16, wherein a token is sent to a secure computing resource registered with the user associated with the credential.

[0150] Example Clause 20. A computer-readable storage medium pursuant to Clause 16, wherein by transmitting a token from an agent to a secure computing resource, the secure computing resource generates a certificate from the token, wherein the receipt of the token at the secure computing resource causes the generation of the certificate at the secure computing resource.

[0151] Finally, although various configurations have been described in language specific to structural features and / or methodological actions, it should be understood that the subject matter defined in the accompanying drawings is not necessarily limited to the specific features or actions described. Rather, specific features and actions are disclosed as exemplary forms for implementing the claimed subject matter.

Claims

1. A method for execution on a computing system, the method comprising: A set of credentials is received from a client device at an identity provider that operates on the computing system, wherein the client device is separate from the computing system. In response to determining that the credential set meets one or more criteria, a token indicating the validity of the credential set is generated at the identity provider, the token defining a claim for a single sign-on process for a user associated with the credential set; The token is transmitted from the computing system to the client device, wherein the client device is configured to transmit the token to the agent with a request to initiate the single sign-on process for accessing the secure computing resources of the services executed on the computing system; The agent receives a request from the client device for accessing the secure computing resources of the service, wherein the request includes a token defining the claim for the single sign-on process for the user associated with the credential set; In response to determining that the request includes the token and the claim generated by the identity provider, the secure computing resource at the service generates an unsigned certificate from the token, wherein the secure computing resource is configured to transmit the unsigned certificate and the token defining the claim to the identity provider; The identity provider at the secure computing resource verifies the token and sends the unsigned certificate to the certificate authority at the secure computing resource to generate a signed certificate from the unsigned certificate, wherein the certificate authority includes secure data provided by the user for signing the unsigned certificate; as well as Send the signing certificate to the secure computing resource, wherein the signing certificate enables the client device to access the secure computing resource via a connection without requiring the client device to resubmit the credential set and without requiring the secure computing resource to generate another unsigned certificate for accessing the secure computing resource.

2. The method of claim 1, wherein at the identity provider, the credential set is received from the client device, the credential set is logged into the identity provider, and the token is generated, wherein when the token is returned to the identity provider, the identity provider initiates the exchange of the token for the certificate.

3. The method of claim 1, wherein the secure computing resource is a remote virtual machine, virtual machine, container, or data repository.

4. The method of claim 1, wherein the token is sent to the secure computing resource registered with the user associated with the credential.

5. The method of claim 1, wherein by transmitting the token from the proxy to the secure computing resource, the secure computing resource generates the certificate from the token, wherein receiving the token at the secure computing resource causes the generation of the certificate at the secure computing resource.

6. The method of claim 1, wherein the certificate is routed to the certificate authority based on an address provided by a configuration file, the configuration file being established by the user-configured security settings.

7. The method of claim 1, wherein the certificate and the signing certificate are deleted at a predetermined time after the signing certificate enables access to the secure computing resource.

8. The method of claim 1, wherein sending the signature certificate to the secure computing resource is achieved through the verification of the token and the generation of the signature certificate from the certificate.

9. A method for execution on a computing system, the method comprising: A set of credentials is received from a client device at an identity provider that operates on the computing system, wherein the client device is separate from the computing system. In response to determining that the credential set meets one or more criteria, a token indicating the validity of the credential set is generated at the identity provider, the token defining a claim for a single sign-on process for a user associated with the credential set; The token is transmitted from the computing system to the client device, wherein the client device is configured to transmit the token to the agent with a request to initiate the single sign-on process for accessing the secure computing resources of the services executed on the computing system; The agent receives a request from the client device for accessing the secure computing resources of the service, wherein the request includes a token defining the claim for the single sign-on process for the user associated with the credential set; In response to determining that the request includes the token and the claim generated by the identity provider, the secure computing resource at the service generates an unsigned certificate from the token, wherein the secure computing resource is configured to transmit the unsigned certificate to the agent; The identity provider verifies the token and sends the unsigned certificate to a certificate authority to generate a signed certificate from the unsigned certificate, wherein the certificate authority includes secure data provided by the user for signing the unsigned certificate; This causes the signing certificate to be transmitted to the secure computing resource, causing the secure computing resource to use the serial number of the signing certificate to generate a reference object, the reference object being configured to provide access to the secure computing resource located at the system. as well as The reference object is transmitted to a gateway configured to insert the reference object into a connection between the client device and the secure computing resource, enabling access to the secure computing resource without requiring the user to provide the set of credentials for accessing the secure computing resource, wherein the insertion of the reference object causes the reference object to be transmitted to the secure computing resource for authentication of the reference object.

10. The method of claim 9, wherein the credential set is received from the client device at the identity provider, the credential set is logged into the identity provider, and the token is generated, wherein when the token is returned to the identity provider, the identity provider initiates the exchange of the token for the certificate.

11. The method of claim 9, wherein the secure computing resource is a remote virtual machine, a virtual machine, a container, or a data repository.

12. The method of claim 9, wherein the token is sent to the secure computing resource registered with the user associated with the credential.

13. The method of claim 9, wherein by transmitting the token from the proxy to the secure computing resource, the secure computing resource generates the certificate from the token, wherein receiving the token at the secure computing resource causes the generation of the certificate at the secure computing resource.

14. The method of claim 9, wherein the certificate is routed to the certificate authority based on an address provided by a configuration file, the configuration file being established by the user-configured security settings.

15. The method of claim 9, wherein the certificate and the signing certificate are deleted at a predetermined time after the signing certificate enables access to the secure computing resource.

16. A computer-readable storage medium having computer-executable instructions encoded thereon to cause one or more processing units of a computing system to: A set of credentials is received from a client device at an identity provider that operates on the computing system, wherein the client device is separate from the computing system. In response to determining that the credential set meets one or more criteria, a token indicating the validity of the credential set is generated at the identity provider, the token defining a claim for a single sign-on process for a user associated with the credential set; The token is transmitted from the computing system to the client device, wherein the client device is configured to transmit the token to the agent with a request to initiate the single sign-on process for accessing the secure computing resources of the services executed on the computing system; The agent receives a request from the client device for accessing the secure computing resources of the service, wherein the request includes a token defining the claim for the single sign-on process for the user associated with the credential set; In response to determining that the request includes the token and the claim generated by the identity provider, the secure computing resource at the service generates an unsigned certificate from the token, wherein the secure computing resource is configured to transmit the unsigned certificate and the token defining the claim to the identity provider; The identity provider at the secure computing resource verifies the token and sends the unsigned certificate to the certificate authority at the secure computing resource to generate a signed certificate from the unsigned certificate, wherein the certificate authority includes secure data provided by the user for signing the unsigned certificate; as well as Send the signing certificate to the secure computing resource, wherein the signing certificate enables the client device to access the secure computing resource via a connection without requiring the client device to resubmit the credential set and without requiring the secure computing resource to generate another unsigned certificate for accessing the secure computing resource.

17. The computer-readable storage medium of claim 16, wherein at the identity provider, the credential set is received from the client device, the credential set is logged into the identity provider, and the token is generated, wherein when the token is returned to the identity provider, the identity provider initiates the exchange of the token for the certificate.

18. The computer-readable storage medium of claim 16, wherein the secure computing resource is a remote virtual machine, virtual machine, container, or data repository.

19. The computer-readable storage medium of claim 16, wherein the token is sent to the secure computing resource registered with a user associated with the credential.

20. The computer-readable storage medium of claim 16, wherein by transmitting the token from the agent to the secure computing resource, the secure computing resource generates the certificate from the token, wherein receiving the token at the secure computing resource causes the generation of the certificate at the secure computing resource.