Browser Rich Client Credential Propagation for Single Sign-On
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face inefficiencies and security risks when authenticating multiple rich and thin client applications separately, often requiring multiple password entries and leading to weak password choices due to convenience, with single sign-on protocols not supporting password-based authentication effectively.
Innovation Solution
A method where a user authenticates once in a web-based application and the credential is automatically propagated to an associated rich client, using a control channel between the browser and rich client, either through an HTTP server or standard operating system mechanisms, allowing the rich client to authenticate without additional user input.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users authenticate separately to multiple clients, then each client can be accessed independently, but users must enter passwords multiple times and security risk increases
Solution Approach 1:
The patent merges the authentication processes of multiple clients by implementing a single sign-on mechanism where one authentication action propagates credentials to multiple clients, eliminating the need for separate password entries and reducing security risks associated with multiple password storages
Solution Approach 2:
The authentication system is designed to be universal across multiple client types (browser-based and rich clients), allowing a single credential to serve multiple authentication purposes simultaneously through the propagation mechanism
2Ease of operation
If single sign-on protocol is used, then authentication is simplified, but password-based authentication is not supported effectively
Solution Approach 1:
The patent introduces a credential propagation mechanism as an intermediary that bridges single sign-on protocols and password-based authentication systems, allowing credentials to be transferred between different authentication paradigms without requiring changes to existing protocols
Solution Approach 2:
The system dynamically changes authentication parameters by detecting the client type and automatically adjusting the authentication method - using single sign-on for browser clients and propagating credentials for rich clients, thereby adapting to different authentication requirements
3Ease of operation
If rich client authentication is automated, then user input is reduced, but control over authentication timing and scope is reduced
Solution Approach 1:
The authentication system is designed to be dynamic, allowing users to configure when and how rich clients are authenticated automatically - options include authenticating only when detected as running, restricting access extent, and revoking access - providing flexibility without requiring complex manual authentication processes
Data Source
AI summary
A user authenticates to a Web- or cloud-based application from a browser-based client. The browser-based client has an associated rich client. After a session is initiated from the browser-based client (and a credential obtained), the user can discover that the rich client is available and cause it to obtain the credential (or a new one) for use in authenticating the user to the application (using the rich client) automatically, i.e., without additional user input. An application interface provides the user with a display by which the user can configure the rich client authentication operation, such as specifying whether the rich client should be authenticated automatically if it detected as running, whether and what extent access to the application by the rich client is to be restricted, if and when access to the application by the rich client is to be revoked, and the like.


