Anonymous Identifier Mediator for Third-Party App Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users of client devices often need to provide separate identifying information to different third-party systems, leading to multiple sign-on requirements and the need to share personally identifying information, which can be inconvenient and insecure.
Innovation Solution
An online system allows users to interact with third-party applications without installing them on their client device by generating an anonymous identifier for additional users, enabling them to access and use third-party applications through a frame on their device without sharing personal information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional single sign-on methods are used to allow users to access third-party systems, then user identification is simplified, but personally identifying information (email address, name, profile image) is exposed to third-party systems
Solution Approach 1:
The patent introduces an intermediary identifier system where the online system acts as a mediator between users and third-party systems. Instead of directly sharing personal information, the online system generates intermediary identifiers (such as anonymous IDs or application-specific identifiers) that enable third-party systems to identify and interact with users without exposing personally identifying information. This intermediary layer resolves the contradiction by maintaining user identification functionality while protecting personal information privacy.
Solution Approach 2:
The patent extracts the personally identifying information from the authentication process. By separating the identification function from personal data, the system uses only necessary identifiers (like anonymous IDs) for authentication purposes, leaving personal information (email, name, profile image) extracted and retained privately by the user and online system. This extraction approach enables authentication while eliminating unnecessary personal information exposure.
2Adaptability or versatility
If users install third-party applications on their client devices, then full application functionality is available, but users must separately provide identifying information to each application
Solution Approach 1:
The patent implements a universal identifier system that works across multiple third-party applications. The online system generates identifiers that can be used consistently across different applications, allowing a single authentication mechanism to serve multiple purposes. This universality enables users to access various third-party applications without needing to separately authenticate to each one, reducing the complexity of multiple sign-on requirements while maintaining full application functionality.
3Productivity
If users provide personally identifying information to third-party systems, then access to content and services is granted, but security and privacy risks increase
Solution Approach 1:
The patent changes the parameter of user identification from personally identifying information to anonymous or minimal identifiers. By transforming the identification parameter from sensitive personal data to non-sensitive identifiers, the system maintains the ability to grant access to content and services while significantly reducing security and privacy risks. This parameter change allows productivity to improve without the accompanying increase in harmful factors.
Data Source
AI summary
An online system provides a user with access to applications associated with third parry systems via the online system and generates an identifier that identifies the user to a third party system without providing the third party system with information personally identifying the user. Using an identifier that identifies an additional user to the third party system, an online system user may invite the additional user to use an application associated with the third party system without installing the application on the additional user's client device. When the user invites the additional user to use the application, the online system sends the third party system associated with the application the identifier identifying the additional user to the third party system. If the additional user accepts the invitation, the online system or third party system provides application content to the additional user via a frame on the additional user's client device.


