Email Client Device Verification via Identity Provider

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current email services, such as OUTLOOK MOBILE, lack a mechanism to authenticate mobile devices accessing user email accounts, making it difficult for IT administrators to ensure that corporate email access is restricted to authorized and managed devices, thereby compromising data security.

Innovation Solution

Implementing a single sign-on experience that federates user authentication with an identity provider, which also authenticates the mobile device using device-specific credentials like certificates, ensuring only authorized devices can access the email service through protocols like SAML and VPN tunnel authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password authentication is used for email access, then user authentication is enabled, but device authentication and access control are restricted

Engineering Contradiction:
Improvedata securityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines user authentication and device authentication into a unified authentication process. The email client integrates both user credentials verification and device certificate validation, merging two separate authentication mechanisms into a single coordinated flow that requires both user and device to be authorized for email access.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed to handle multiple authentication types universally. It can process both traditional username/password authentication and device certificate-based authentication through a common interface, allowing the system to adapt to different authentication scenarios while maintaining a consistent user experience.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If device-specific authentication is implemented, then device access control is improved, but authentication complexity increases

Engineering Contradiction:
Improvedevice access controlVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity provider as an intermediary between the email client and the authentication authorities. The identity provider receives authentication requests, coordinates both user and device verification, and returns a unified authentication result. This mediator simplifies the complexity by centralizing the coordination logic and shielding the email client from dealing with multiple authentication systems directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into distinct components: user credential verification, device certificate validation, and unified authentication decision-making. Each component operates independently but coordinates through standardized interfaces, allowing the system to manage complexity through modular design while maintaining strong access control.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If federated authentication with identity provider is used, then single sign-on experience is provided, but authentication verification steps increase

Engineering Contradiction:
Improveuser experienceVSAvoidauthentication process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary device authentication and certificate validation before the user even attempts to access email. The device certificate is verified in advance, and the authentication state is cached or pre-established, so that when the user logs in, the process is expedited. This preliminary action maintains security while improving user experience by reducing perceived authentication steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The identity provider provides feedback mechanisms that allow the email client to understand the authentication state without requiring users to manually verify each step. The system automatically receives and processes authentication results, device verification status, and access permissions, presenting a streamlined interface to users while performing comprehensive verification in the background.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11444932B2Device verification of an installation of an email client
Publication Date: 2022.09.13 OMNISSA LLC
  • US11444932B2 patent drawing
  • US11444932B2 patent drawing
  • US11444932B2 patent drawing

AI summary

Disclosed are various examples for single-sign on by way of managed mobile devices. For example, an identity provider service can receive a request for an identity assertion from an email client executed in a client device. The identity provider service can then detect a platform associated with the client device. The device and the user's identity can be authenticated so that an IT administrator can specify that only authorized devices can access email using the email client.