Cross-Application Authentication Token Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Different online systems use distinct user identification methods, leading to impaired information exchange between applications on a client device, resulting in increased user interaction barriers due to the need for repeated login credentials and authentication processes.
Innovation Solution
An application associated with an online system identifies and authenticates additional applications on a client device by comparing system-authorized identifiers, generating and storing authentication tokens, and facilitating secure information exchange between the applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If different online systems use distinct user identification methods, then each system can maintain its own security and identification standards, but information exchange between applications on a client device is impaired and users must repeatedly provide login credentials
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where the first application generates authentication information (access tokens) that the second application can verify. This intermediary token system allows different online systems to maintain their own identification standards while enabling seamless information exchange without requiring users to repeatedly provide login credentials. The authentication information acts as a mediator between the two applications, resolving the contradiction between maintaining security standards and easing user authentication.
2Measurement precision
If applications associated with different online systems use different identifying information, then each application can accurately identify users within its own system, but exchange of information between applications is impaired
Solution Approach 1:
The patent implements a universal authentication information structure that can be used across different online systems. The authentication information (access token) generated by the first application serves multiple functions: it identifies the user within the first system, enables the second application to verify authentication status, and facilitates information exchange between applications. This multi-functional authentication mechanism resolves the contradiction by allowing each application to maintain its identification accuracy while enabling cross-application information exchange.
3Reliability
If users are prompted to provide login credentials for each application, then security is maintained for each online system, but user interaction and engagement are reduced
Solution Approach 1:
The patent applies preliminary authentication action where the first application generates and shares authentication information with the second application before the user needs to access functionality. This preliminary authentication eliminates the need for users to repeatedly provide login credentials when switching between applications. The authentication is performed in advance by the first application, and the resulting authentication information is reused by the second application, thereby maintaining security while significantly improving user interaction efficiency.
Data Source
AI summary
An application associated with an online system executing on a client device identifies an additional application on the client device with which the application may exchange information. To exchange information between the application and additional application, the online system receives a request for authentication information from the application that identifies the additional application and a user of the application. The online system generates and stores authentication information in association with an identifier associated with the user by the application and with an identifier of the additional application. After communicating the authentication information to the client device, the online system receives a request to verify the authentication information from the additional application. If the authentication information is verified, the online system stores an association between an identifier associated with the user by the additional application that was included in the request and the identifier associated with the user by the application.


