Certificate-Based SSO via Identity Provider Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for certificate-based authentication on mobile devices are not ubiquitous and require app developers to make changes, and they do not effectively support multiple mobile platforms and web apps without the need for VPN installations, which is undesirable.

Innovation Solution

A technique that uses a mobile device management platform to provision access to network-accessible applications via an identity provider, enabling certificate-based authentication without requiring certificates on the mobile device, by interacting with the identity provider to obtain an authentication token for secure session establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN tunneling is used to authenticate users, then certificate-based authentication can be achieved, but VPN client installation and management on mobile devices is required

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidVPN client installation and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the certificate storage and authentication functionality from the mobile device itself and relocates it to a server component. The server now holds the certificates and performs authentication operations, while the mobile device only needs to communicate with the server for authentication, eliminating the need for VPN clients or local certificate management on devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a server as an intermediary between the mobile devices and the applications. This server acts as a mediator that stores certificates, receives authentication requests from devices, validates credentials against stored certificates, and returns authentication results, thereby eliminating the need for direct certificate management on mobile devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If Apple iOS hook mechanism is used for authentication, then Kerberos authentication can be handled within iOS apps, but other mobile platforms and web apps are not supported

Engineering Contradiction:
Improveplatform compatibilityVSAvoidimplementation complexity for app developers
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal authentication server that can handle authentication requests from any mobile platform (iOS, Android, Windows Phone) and any application type (native apps, web apps). The server provides a single interface that works across all platforms without requiring platform-specific implementations or modifications to individual applications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication server serves as a universal intermediary that receives authentication requests from diverse sources (different mobile platforms and application types) and provides standardized certificate-based authentication. This mediator approach allows the system to support multiple platforms and app types without requiring each to implement platform-specific authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If certificate-based authentication is implemented directly on mobile devices, then authentication security is improved, but device complexity and certificate management burden increase

Engineering Contradiction:
Improveauthentication securityVSAvoidcertificate management on device
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the certificate storage and management functionality from the mobile device and relocates it to a server. The server now maintains the certificates securely, while the mobile device only needs to communicate authentication requests to the server, eliminating the complexity of local certificate storage and management on resource-constrained mobile devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication server acts as an intermediary that securely stores certificates and handles all certificate management operations. This mediator approach allows mobile devices to benefit from secure certificate-based authentication without bearing the burden of certificate storage, management, and security maintenance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10757091B2Certificate-based single sign-on (SSO) from mobile applications over the internet
Publication Date: 2020.08.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10757091B2 patent drawing
  • US10757091B2 patent drawing
  • US10757091B2 patent drawing

AI summary

A technique to establish a secure session to a network-accessible application from a mobile device executing a native app. Initially, the network-accessible application is provisioned for access by an enterprise associating a set of one or more of its enterprise users with the network-accessible application. Thereafter, access to the application is enabled via an identity provider. In operation, the identity provider receives a request to validate that an enterprise user seeking access to the network-accessible application is associated with the application. The request is generated by the application in response to a login request initiated from the native app from a mobile device, wherein a certificate for the application is not available to the native app. Upon validating that the enterprise user is associated with the network-accessible application, the identity provider returns to the application an authentication token evidencing that the enterprise user is permitted to access the network-accessible application for a session.