Certificate-Based SSO via Identity Provider Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for certificate-based authentication on mobile devices are not ubiquitous and require app developers to make changes, and they do not effectively support multiple mobile platforms and web apps without the need for VPN installations, which is undesirable.
Innovation Solution
A technique that uses a mobile device management platform to provision access to network-accessible applications via an identity provider, enabling certificate-based authentication without requiring certificates on the mobile device, by interacting with the identity provider to obtain an authentication token for secure session establishment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VPN tunneling is used to authenticate users, then certificate-based authentication can be achieved, but VPN client installation and management on mobile devices is required
Solution Approach 1:
The patent extracts the certificate storage and authentication functionality from the mobile device itself and relocates it to a server component. The server now holds the certificates and performs authentication operations, while the mobile device only needs to communicate with the server for authentication, eliminating the need for VPN clients or local certificate management on devices.
Solution Approach 2:
The patent introduces a server as an intermediary between the mobile devices and the applications. This server acts as a mediator that stores certificates, receives authentication requests from devices, validates credentials against stored certificates, and returns authentication results, thereby eliminating the need for direct certificate management on mobile devices.
2Adaptability or versatility
If Apple iOS hook mechanism is used for authentication, then Kerberos authentication can be handled within iOS apps, but other mobile platforms and web apps are not supported
Solution Approach 1:
The patent creates a universal authentication server that can handle authentication requests from any mobile platform (iOS, Android, Windows Phone) and any application type (native apps, web apps). The server provides a single interface that works across all platforms without requiring platform-specific implementations or modifications to individual applications.
Solution Approach 2:
The authentication server serves as a universal intermediary that receives authentication requests from diverse sources (different mobile platforms and application types) and provides standardized certificate-based authentication. This mediator approach allows the system to support multiple platforms and app types without requiring each to implement platform-specific authentication mechanisms.
3Reliability
If certificate-based authentication is implemented directly on mobile devices, then authentication security is improved, but device complexity and certificate management burden increase
Solution Approach 1:
The patent extracts the certificate storage and management functionality from the mobile device and relocates it to a server. The server now maintains the certificates securely, while the mobile device only needs to communicate authentication requests to the server, eliminating the complexity of local certificate storage and management on resource-constrained mobile devices.
Solution Approach 2:
The authentication server acts as an intermediary that securely stores certificates and handles all certificate management operations. This mediator approach allows mobile devices to benefit from secure certificate-based authentication without bearing the burden of certificate storage, management, and security maintenance.
Data Source
AI summary
A technique to establish a secure session to a network-accessible application from a mobile device executing a native app. Initially, the network-accessible application is provisioned for access by an enterprise associating a set of one or more of its enterprise users with the network-accessible application. Thereafter, access to the application is enabled via an identity provider. In operation, the identity provider receives a request to validate that an enterprise user seeking access to the network-accessible application is associated with the application. The request is generated by the application in response to a login request initiated from the native app from a mobile device, wherein a certificate for the application is not available to the native app. Upon validating that the enterprise user is associated with the network-accessible application, the identity provider returns to the application an authentication token evidencing that the enterprise user is permitted to access the network-accessible application for a session.


