Zero Sign-On Browser Authentication via Enrollment Agent
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current zero sign-on (ZSO) solutions for web-based services require users to install custom applications or manage multiple user certificates, which can be cumbersome and insecure, especially when dealing with multiple web services.
Innovation Solution
A system that configures standard web browsers on devices to enable ZSO by using an enrollment agent and a custom certificate authority, allowing browsers to authenticate securely without user input by redirecting to a special ZSO URL and providing a user certificate through a custom certificate authority recognized only by the MDM service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If users install custom applications to achieve zero sign-on, then authentication automation is improved, but device complexity increases
Solution Approach 1:
The browser automatically selects and presents the appropriate user certificate without user intervention. The enrollment agent configures the browser to autonomously handle certificate selection based on the target web service, eliminating the need for users to manually choose from certificate lists.
Solution Approach 2:
The solution uses a standard web browser that users already have installed, making the browser serve multiple functions including web browsing and automated certificate-based authentication. This eliminates the need for separate custom applications while achieving zero sign-on functionality.
2Adaptability or versatility
If users manage multiple user certificates for different web services, then authentication capability is improved, but ease of operation deteriorates
Solution Approach 1:
The enrollment agent acts as an intermediary between the user's certificate store and the web browser. It automatically manages the selection and configuration of appropriate certificates for different web services, shielding users from the complexity of managing multiple certificates while maintaining versatile authentication capability.
Solution Approach 2:
The enrollment agent performs preliminary configuration of the browser with automated certificate selection rules before the user needs to authenticate. This pre-configuration enables the browser to automatically choose the correct certificate without user intervention during the authentication process.
3Reliability
If a custom application is used for zero sign-on, then authentication security is improved, but ease of manufacture deteriorates
Solution Approach 1:
The solution replaces the mechanical approach of installing and configuring custom applications with a software-based enrollment agent that configures the existing browser. This substitution maintains security through proper certificate management while significantly easing deployment and manufacturing.
4Adaptability or versatility
If multiple certificates are stored in the browser, then authentication versatility is improved, but certificate selection difficulty increases
Solution Approach 1:
The enrollment agent serves as an intermediary that automatically selects the appropriate certificate from the user's certificate store based on the target web service. It translates the user's authentication needs into the correct certificate selection without requiring the user to understand or manage the certificates themselves.
Solution Approach 2:
The browser, configured by the enrollment agent, performs self-service certificate selection by automatically choosing the appropriate certificate based on pre-configured rules associated with different web services. This eliminates the need for user intervention in certificate selection while maintaining authentication versatility.
Data Source
AI summary
Method for enabling zero sign-on (ZSO) through a standard web browser. The device running the browser is first enrolled with a web service using an installed enrollment agent on the device which authenticates a user of the device. After authentication, the enrollment agent stores a device profile that includes a user certificate for the user and an authority certificate issued by said web service. The device profile is stored at a device location accessible by each of the web browsers used by said device. The enrollment agent configures each of the web browsers on the device to respond correctly to ZSO certificate challenges from the web service. Once enrolled, the device's web browsers can respond correctly to a ZSO Uniform Resource Locator (URL) certificate challenge received from the web service. After a successful response to the challenge, the browser is granted a secure socket layer (SSL) connection.

