Device Session SSO Linking for Secure Multi-App Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems require users to perform multiple authorization procedures to access different applications or resources, leading to user fatigue and potential security vulnerabilities due to long-lived access tokens that can be exploited.
Innovation Solution
A method and apparatus for establishing multi-application single sign-on (SSO) via device session establishment, where an authorization server links new sessions to an existing session using a token-based authentication challenge response, reducing the need for repeated user input and enhancing security by ensuring assurance levels are met.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users perform multiple authorization procedures to access different applications, then security assurance levels are maintained, but user fatigue increases and productivity decreases
Solution Approach 1:
The patent merges multiple authorization procedures into a single unified authorization process. When a user completes authentication for one application, the authorization server issues a token that can be reused across multiple applications, combining what would otherwise be separate authentication flows into one efficient process while maintaining security assurance levels.
Solution Approach 2:
The patent implements preliminary authentication where the user's credentials are verified in advance through a single authorization procedure. The resulting token serves as pre-established proof of authentication, eliminating the need for repeated authentication actions and reducing user fatigue while maintaining security.
2Ease of operation
If long-lived access tokens are used for single sign-on, then user convenience improves, but security vulnerabilities increase due to potential token exploitation
Solution Approach 1:
The patent implements dynamic token management where tokens have controlled lifecycles and can be revoked or invalidated under specific conditions. The authorization server can dynamically adjust token validity based on security requirements, application contexts, and user behaviors, balancing convenience with security by allowing long-lived tokens only when appropriate while maintaining the ability to respond to security threats.
3Reliability
If multiple authorization procedures are required for each application, then security control is maintained, but device complexity and system overhead increase
Solution Approach 1:
The patent implements a universal authorization mechanism where a single authorization procedure and token issuance process serves multiple applications simultaneously. The authorization server functions as a multi-functional component that can validate tokens across different applications, reducing system overhead by eliminating the need for separate authorization logic in each application while maintaining centralized security control.
Data Source
AI summary
A user device including an authenticator application may transmit signaling to an authorization server for a first authorization procedure to establish a first session between the user device and a first server of a first organization. The user device may transmit, to the authorization server, a request to access a different resource after establishing the first session. The user device may receive, by the authenticator application, an authentication challenge from the authorization server and transmit a response to the authentication challenge including a token indicative of the first session established via the first authorization procedure. The user device may establish a second session between the user device and a second server based on transmitting the response to the authentication challenge, where the second session is associated with the first session in accordance with the response to the authentication challenge including the token.


