Credential Manager for Secure Third-Party SSO
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional single sign-on approaches are incompatible with many third-party applications, leading to inefficient and insecure management of access, where users must manually input and manage credentials, increasing the risk of credential compromise and misuse outside secure networks.
Innovation Solution
An access management server stores and manages security policy data, including user-specific and application-specific credentials, allowing automatic sign-on to third-party applications without revealing credentials to users, using an administration portal and application access tool to map credentials to users and applications securely, and an application access tool to automatically input credentials in an anonymized format.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manually manage and input their own sign-on credentials for third-party applications, then users have direct control and visibility of their credentials, but security is compromised and credential exposure risk increases
Solution Approach 1:
The patent introduces a credential manager as an intermediary component that stores and manages sign-on credentials on behalf of users. This mediator handles credential input automatically, preventing direct user exposure to sensitive credential data while maintaining secure access to third-party applications. The credential manager acts as a trusted intermediary between the user, the organization's identity provider, and external applications.
Solution Approach 2:
The system implements automated credential management where the credential manager autonomously handles credential storage, retrieval, and input without requiring direct user interaction with sensitive credential data. The system self-manages the credential lifecycle including automatic population of sign-on forms and seamless integration with organizational identity providers, eliminating the need for users to manually handle credentials.
2Adaptability or versatility
If conventional single sign-on approaches are used, then access management is simplified and coordinated between applications, but compatibility with third-party applications is limited
Solution Approach 1:
The credential manager is designed as a universal solution that works with multiple identity providers (Azure AD, Okta, Google Workspace) and various authentication methods (passwords, MFA, SSO tokens). It provides multi-functional capability by supporting different third-party applications and authentication protocols through a single unified interface, eliminating the need for application-specific coordination configurations.
Solution Approach 2:
The system segments the complex SSO coordination task into separate functional components: the credential manager handles credential storage and management, the identity provider handles authentication validation, and the browser extension handles automatic credential input. This segmentation allows each component to operate independently with well-defined interfaces, improving compatibility without increasing overall system complexity.
3Ease of operation
If users access third-party applications outside the secure network environment, then user convenience is improved, but credential compromise risk and policy violation increase
Solution Approach 1:
The credential manager serves as a secure intermediary that enables users to access third-party applications from any location while maintaining security controls. It mediates between the user's organizational policies and external application access requirements, allowing convenient remote access while preventing credential compromise through automated secure credential management and integration with organizational identity providers.
Solution Approach 2:
The system implements feedback mechanisms through integration with organizational identity providers that provide real-time information about user permissions, security policies, and credential status. This feedback loop ensures that credential access is continuously validated against current security policies, allowing convenient access while maintaining security oversight and preventing policy violations.
Data Source
AI summary
A system provides for automatically populating a sign-on page with sign-on credentials and automatically submitting the sign-on credentials without revealing at least one of the sign-on credentials to a user. The system includes an access management server which stores sign-on credentials for accessing the application. An application access tool, which is associated with a browser extension of a web browser executed on the user's device, provides a network address for a sign-on page of the application, and the system automatically redirects the user to this sign-on page. The system uses a source code database to identify object identifiers in html source code of the sign-on page that corresponds to form fields or other objects in the sign-on page for appropriately entering and submitting sign-on credentials in the sign-on page. The credentials are entered in an anonymized format that is not readable to the user.


