Zero Sign-On Browser Authentication via Enrollment Agent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current zero sign-on (ZSO) solutions for web-based services require users to install custom applications or manage multiple user certificates, which can be cumbersome and insecure, especially when dealing with multiple web services.

Innovation Solution

A system that configures standard web browsers on devices to enable ZSO by using an enrollment agent and a custom certificate authority, allowing browsers to authenticate securely without user input by redirecting to a special ZSO URL and providing a user certificate through a custom certificate authority recognized only by the MDM service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If users install custom applications to achieve zero sign-on, then authentication automation is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication automationVSAvoiddevice complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The browser automatically selects and presents the appropriate user certificate without user intervention. The enrollment agent configures the browser to autonomously handle certificate selection based on the target web service, eliminating the need for users to manually choose from certificate lists.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The solution uses a standard web browser that users already have installed, making the browser serve multiple functions including web browsing and automated certificate-based authentication. This eliminates the need for separate custom applications while achieving zero sign-on functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If users manage multiple user certificates for different web services, then authentication capability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication capabilityVSAvoidease of operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The enrollment agent acts as an intermediary between the user's certificate store and the web browser. It automatically manages the selection and configuration of appropriate certificates for different web services, shielding users from the complexity of managing multiple certificates while maintaining versatile authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The enrollment agent performs preliminary configuration of the browser with automated certificate selection rules before the user needs to authenticate. This pre-configuration enables the browser to automatically choose the correct certificate without user intervention during the authentication process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a custom application is used for zero sign-on, then authentication security is improved, but ease of manufacture deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The solution replaces the mechanical approach of installing and configuring custom applications with a software-based enrollment agent that configures the existing browser. This substitution maintains security through proper certificate management while significantly easing deployment and manufacturing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Adaptability or versatility

If multiple certificates are stored in the browser, then authentication versatility is improved, but certificate selection difficulty increases

Engineering Contradiction:
Improveauthentication versatilityVSAvoidcertificate selection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The enrollment agent serves as an intermediary that automatically selects the appropriate certificate from the user's certificate store based on the target web service. It translates the user's authentication needs into the correct certificate selection without requiring the user to understand or manage the certificates themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The browser, configured by the enrollment agent, performs self-service certificate selection by automatically choosing the appropriate certificate based on pre-configured rules associated with different web services. This eliminates the need for user intervention in certificate selection while maintaining authentication versatility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10587603B2Zero sign-on using a web browser
Publication Date: 2020.03.10 CYBER ARK SOFTWARE LTD
  • US10587603B2 patent drawing
  • US10587603B2 patent drawing

AI summary

Method for enabling zero sign-on (ZSO) through a standard web browser. The device running the browser is first enrolled with a web service using an installed enrollment agent on the device which authenticates a user of the device. After authentication, the enrollment agent stores a device profile that includes a user certificate for the user and an authority certificate issued by said web service. The device profile is stored at a device location accessible by each of the web browsers used by said device. The enrollment agent configures each of the web browsers on the device to respond correctly to ZSO certificate challenges from the web service. Once enrolled, the device's web browsers can respond correctly to a ZSO Uniform Resource Locator (URL) certificate challenge received from the web service. After a successful response to the challenge, the browser is granted a secure socket layer (SSL) connection.