Application Single Sign-On With Privacy-Preserving Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on services share users' private information with service providers without user consent, compromising privacy.
Innovation Solution
A new single sign-on service allows users to authenticate across multiple authorization domains using a single set of credentials while controlling information sharing, employing local authentication and anonymous email relays to protect privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single sign-on service shares user credentials with multiple service providers, then user authentication convenience is improved, but user privacy is compromised
Solution Approach 1:
The patent introduces an intermediary authentication service that mediates between users and service providers. This intermediary verifies user credentials and grants authentication tokens without exposing actual user credentials to service providers, thus maintaining both authentication convenience and user privacy through the intermediary's buffer role
Solution Approach 2:
The patent extracts the sensitive user credential information from the authentication process. Instead of sharing actual credentials, the system extracts only the necessary authentication verification function, allowing service providers to verify authentication status without accessing or storing user credentials, thereby separating the authentication benefit from the privacy risk
Data Source
AI summary
A method and apparatus of a device that authorizes a device for a service is described. In an exemplary embodiment, the device intercepts a request for a web page from a web browser executing on the device, wherein the request includes an indication associated with an authorization request for the service and the web page provides the service. In addition, the device presents an authorization user interface on the device. The device further performs a local authorization using a set of user credentials entered via the authorization user interface. The device additionally performs a server authorization with a server. Furthermore, the device redirects the web browser to the requested web page, wherein the web browser is authorized for the service provided by the web page.


