Email Client Device Verification via Identity Provider
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current email services, such as OUTLOOK MOBILE, lack a mechanism to authenticate mobile devices accessing user email accounts, making it difficult for IT administrators to ensure that corporate email access is restricted to authorized and managed devices, thereby compromising data security.
Innovation Solution
Implementing a single sign-on experience that federates user authentication with an identity provider, which also authenticates the mobile device using device-specific credentials like certificates, ensuring only authorized devices can access the email service through protocols like SAML and VPN tunnel authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If username and password authentication is used for email access, then user authentication is enabled, but device authentication and access control are restricted
Solution Approach 1:
The patent combines user authentication and device authentication into a unified authentication process. The email client integrates both user credentials verification and device certificate validation, merging two separate authentication mechanisms into a single coordinated flow that requires both user and device to be authorized for email access.
Solution Approach 2:
The authentication system is designed to handle multiple authentication types universally. It can process both traditional username/password authentication and device certificate-based authentication through a common interface, allowing the system to adapt to different authentication scenarios while maintaining a consistent user experience.
2Reliability
If device-specific authentication is implemented, then device access control is improved, but authentication complexity increases
Solution Approach 1:
The patent introduces an identity provider as an intermediary between the email client and the authentication authorities. The identity provider receives authentication requests, coordinates both user and device verification, and returns a unified authentication result. This mediator simplifies the complexity by centralizing the coordination logic and shielding the email client from dealing with multiple authentication systems directly.
Solution Approach 2:
The authentication process is segmented into distinct components: user credential verification, device certificate validation, and unified authentication decision-making. Each component operates independently but coordinates through standardized interfaces, allowing the system to manage complexity through modular design while maintaining strong access control.
3Ease of operation
If federated authentication with identity provider is used, then single sign-on experience is provided, but authentication verification steps increase
Solution Approach 1:
The system performs preliminary device authentication and certificate validation before the user even attempts to access email. The device certificate is verified in advance, and the authentication state is cached or pre-established, so that when the user logs in, the process is expedited. This preliminary action maintains security while improving user experience by reducing perceived authentication steps.
Solution Approach 2:
The identity provider provides feedback mechanisms that allow the email client to understand the authentication state without requiring users to manually verify each step. The system automatically receives and processes authentication results, device verification status, and access permissions, presenting a streamlined interface to users while performing comprehensive verification in the background.
Data Source
AI summary
Disclosed are various examples for single-sign on by way of managed mobile devices. For example, an identity provider service can receive a request for an identity assertion from an email client executed in a client device. The identity provider service can then detect a platform associated with the client device. The device and the user's identity can be authenticated so that an IT administrator can specify that only authorized devices can access email using the email client.


