Device Session SSO Linking for Secure Multi-App Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems require users to perform multiple authorization procedures to access different applications or resources, leading to user fatigue and potential security vulnerabilities due to long-lived access tokens that can be exploited.

Innovation Solution

A method and apparatus for establishing multi-application single sign-on (SSO) via device session establishment, where an authorization server links new sessions to an existing session using a token-based authentication challenge response, reducing the need for repeated user input and enhancing security by ensuring assurance levels are met.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users perform multiple authorization procedures to access different applications, then security assurance levels are maintained, but user fatigue increases and productivity decreases

Engineering Contradiction:
Improvesecurity assurance levelVSAvoiduser efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple authorization procedures into a single unified authorization process. When a user completes authentication for one application, the authorization server issues a token that can be reused across multiple applications, combining what would otherwise be separate authentication flows into one efficient process while maintaining security assurance levels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements preliminary authentication where the user's credentials are verified in advance through a single authorization procedure. The resulting token serves as pre-established proof of authentication, eliminating the need for repeated authentication actions and reducing user fatigue while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If long-lived access tokens are used for single sign-on, then user convenience improves, but security vulnerabilities increase due to potential token exploitation

Engineering Contradiction:
Improveuser convenienceVSAvoidtoken exploitation risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic token management where tokens have controlled lifecycles and can be revoked or invalidated under specific conditions. The authorization server can dynamically adjust token validity based on security requirements, application contexts, and user behaviors, balancing convenience with security by allowing long-lived tokens only when appropriate while maintaining the ability to respond to security threats.

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple authorization procedures are required for each application, then security control is maintained, but device complexity and system overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authorization mechanism where a single authorization procedure and token issuance process serves multiple applications simultaneously. The authorization server functions as a multi-functional component that can validate tokens across different applications, reducing system overhead by eliminating the need for separate authorization logic in each application while maintaining centralized security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260039642A1Multi-application single-sign on via device session establishment
Publication Date: 2026.02.05 OKTA INC
  • US20260039642A1 patent drawing
  • US20260039642A1 patent drawing
  • US20260039642A1 patent drawing

AI summary

A user device including an authenticator application may transmit signaling to an authorization server for a first authorization procedure to establish a first session between the user device and a first server of a first organization. The user device may transmit, to the authorization server, a request to access a different resource after establishing the first session. The user device may receive, by the authenticator application, an authentication challenge from the authorization server and transmit a response to the authentication challenge including a token indicative of the first session established via the first authorization procedure. The user device may establish a second session between the user device and a second server based on transmitting the response to the authentication challenge, where the second session is associated with the first session in accordance with the response to the authentication challenge including the token.