Cross-Platform SSO Token Service for Cloud Productivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Single Sign-On (SSO) technologies are limited in providing seamless access across different platforms and devices due to reliance on identity federation and authentication cookies, which are not platform-agnostic, restricting the use of SSO experiences, especially when multiple platforms or devices are involved.

Innovation Solution

A system and method that utilizes a token service to handle user authorization with cloud productivity applications, storing identity and access tokens, and multi-resource refresh tokens, enabling automatic sign-on across services without requiring users to re-enter credentials, by integrating with an Identity Provider and managing access tokens and refresh tokens for secure and platform-agnostic access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity federation or authentication cookies are used for SSO, then single service access is improved, but cross-platform accessibility deteriorates

Engineering Contradiction:
Improvesingle service accessVSAvoidcross-platform accessibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a token service as an intermediary component that mediates between the user and multiple cloud productivity applications. This token service stores and manages authentication tokens, allowing users to access different services across platforms without repeatedly entering credentials. The token service acts as a central mediator that handles authentication state across platform boundaries, resolving the contradiction between easy single-service access and cross-platform versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal token service that performs multiple functions: storing identity tokens, managing access tokens, handling refresh tokens, and supporting cross-platform authentication. This multi-functional system replaces the need for separate authentication mechanisms for each service or platform, providing both single-service ease of access and cross-platform adaptability through a single universal authentication infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If users provide credentials for each service, then security is improved, but user efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication where users provide their credentials once to the token service, which then stores authentication tokens for future use. This preliminary action eliminates the need for repeated credential entry across multiple services and sessions. The token service performs advance authentication and caches the results, maintaining security while dramatically improving user efficiency by avoiding redundant authentication steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The token service implements self-service authentication by automatically managing token storage, retrieval, and refresh operations. Once initial credentials are provided, the system autonomously handles subsequent authentication requests across different cloud productivity applications without requiring user intervention. This self-service mechanism maintains security through proper token management while maximizing user efficiency by eliminating manual credential re-entry.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If authentication cookies are used, then session-based SSO is improved, but platform agnosticism deteriorates

Engineering Contradiction:
Improvesession-based SSOVSAvoidplatform agnosticism
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent replaces platform-specific authentication cookies with a platform-agnostic token service intermediary. This token service stores authentication tokens in a manner that is not tied to any specific browser or platform, allowing the same authentication state to be accessed across different devices and platforms. The token service mediates between the user's authentication state and multiple cloud services, providing both session-based SSO functionality and platform independence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20210385207A1Cross-platform single sign-on accessibility of a productivity application within a software as a service platform
Publication Date: 2021.12.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20210385207A1 patent drawing
  • US20210385207A1 patent drawing
  • US20210385207A1 patent drawing

AI summary

A Cross-Platform Single Sign On (CP-SSO) experience is provided herein to enable users to access multiple services via a single login when working across different platforms. A user may work across different platform when using multiple devices, when using multiple browsers on a single device, or when an integrated application requires a separate login for access within a host web application or portal service. A proxy token service manages login requests and authentication tokens after a given service has been logged into once by a user, so that the user does not need to provide login credentials on subsequent requests for the given service. By enabling a CP-SSO experience, network efficiency is improved, and the user experience is also improved as users do not need to supply authentication credentials as frequently and may freely choose to use multiple platforms instead of limiting usage to a single platform.