Digital Assistant Portal Authentication for Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise mobility management systems lack the ability to securely integrate digital assistants with third-party applications, compromising security and convenience, as they struggle to manage access and verify user identity effectively.

Innovation Solution

A system that allows digital assistants to link with a portal application within an enterprise mobility management system, using a two-part authentication process involving OAuth tokens and SAML assertions to ensure authorized access to third-party applications, enabling managed access without requiring users to log in individually.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital assistants store access credentials for third-party applications, then convenience is improved, but security control by EMM system deteriorates

Engineering Contradiction:
Improveconvenience of digital assistant accessVSAvoidEMM system control over enterprise data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The EMM system acts as an intermediary between the digital assistant and third-party applications. Instead of the digital assistant directly storing credentials, the EMM system receives authentication requests from the digital assistant, verifies user identity, and grants access to third-party applications on behalf of the user. This maintains security control while enabling convenient access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If EMM system verifies user identity for each digital assistant request, then security is improved, but convenience deteriorates

Engineering Contradiction:
Improveuser identity verificationVSAvoidconvenience of digital assistant
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The EMM system performs preliminary authentication and establishes a trusted session between the digital assistant and the user's account. Once authenticated, the digital assistant can make requests without requiring repeated verification of user identity for each individual request. The initial authentication establishes ongoing access permissions.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If digital assistants are integrated with enterprise applications, then functionality is improved, but security management complexity increases

Engineering Contradiction:
Improveintegration capabilityVSAvoidsecurity management structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The EMM system provides a universal authentication framework that works across multiple digital assistant platforms and third-party applications. Rather than implementing separate security mechanisms for each integration scenario, the EMM system offers a single, standardized approach to managing digital assistant access to enterprise data across different applications and services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11601412B2Securely managing digital assistants that access third-party applications
Publication Date: 2023.03.07 VMWARE INC
  • US11601412B2 patent drawing
  • US11601412B2 patent drawing
  • US11601412B2 patent drawing

AI summary

Systems herein allow a digital assistant to make requests to applications, such as third-party applications, that access data in an enterprise mobility management (“EMM”) system. The digital assistant can link to a portal application and receive a token that identifies a user. A remote application on a user device can establish a session with the portal application as part of a single sign on (“SSO”). The session can identify the same user. The portal application can then link the digital assistant to the remote application. When the digital assistant makes a request to the portal application, a notification can be pushed to the remote application. The user can confirm the request, establishing an authorized session during which time the digital assistant can make additional requests to the portal application. The portal application can service the requests by accessing third-party applications available through the portal application and authorized for access by the SSO.