Expedited Authentication API for Mobile Enterprise Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for mobile device applications are cumbersome, requiring users to remember and input multiple usernames and passwords, and imposing complex restrictions on access, especially when users own the device and not the entity imposing restrictions.
Innovation Solution
Implementing an expedited authentication system where a user, once authenticated with an enterprise system, can authorize applications to access data without additional credentials, using policies to control access based on time and location, and leveraging an expedited authentication API to facilitate secure and efficient access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional authentication methods are used for each application, then security control is maintained, but user convenience deteriorates due to multiple credentials required
Solution Approach 1:
The patent combines multiple authentication credentials into a single enterprise authentication. The mobile device authentication credentials are merged with application-specific credentials, allowing the user to authenticate once with the enterprise system and gain access to multiple applications without entering separate usernames and passwords for each application.
Solution Approach 2:
The enterprise authentication system serves as a universal authentication mechanism that works across multiple applications. The authenticated credentials obtained from the enterprise authentication server can be used to access various applications installed on the mobile device, making the authentication system multi-functional rather than application-specific.
2Reliability
If enterprise restrictions are imposed on mobile device applications, then security is improved, but device complexity increases due to policy management
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that mediates between the enterprise's security requirements and the mobile device's application access. The enterprise authentication server acts as an intermediary that verifies credentials and enforces policies without requiring the mobile device to implement complex restriction management itself. The authentication credentials obtained from this intermediary contain embedded policy information that simplifies enforcement.
Solution Approach 2:
The enterprise authentication and policy enforcement actions are performed preliminarily before application access is granted. The authentication credentials are obtained in advance through enterprise authentication, and policy restrictions are established beforehand through the authentication mechanism. This preliminary action eliminates the need for complex runtime policy management on the mobile device.
3Productivity
If multiple applications require separate authentication, then access control is precise, but time consumption increases for users
Solution Approach 1:
The patent merges the authentication process for multiple applications into a single enterprise authentication event. Instead of requiring separate authentication for each application, the user performs one authentication with the enterprise system, and the authentication credentials obtained can be used across multiple applications, significantly reducing the time spent on authentication.
Solution Approach 2:
The enterprise authentication is performed as a preliminary action before accessing any applications. The authentication credentials are obtained in advance and stored, allowing rapid access to multiple applications without repeating the authentication process. This preliminary authentication action eliminates the need for repeated credential entry when launching different applications.
Data Source
AI summary
Methods and systems for expedited authentication for mobile applications are described herein. A user of a mobile device may authenticate with an enterprise system, and thereby be granted access to enterprise applications and services on the mobile device. The user may then activate an application in a managed partition of the mobile device. The application may determine that the enterprise system supports expedited authentication. The application may request expedited authentication, and the request may be compared to policies for expedited authentication. If the request is permitted, the application may be granted access to an authorization code for expedited authentication. The application may then perform the expedited authentication, and the user may be granted access to the application when the expedited authentication has completed.


