Expedited Authentication API for Mobile Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for mobile device applications are cumbersome, requiring users to remember and input multiple usernames and passwords, and imposing complex restrictions on access, especially when users own the device and not the entity imposing restrictions.

Innovation Solution

Implementing an expedited authentication system where a user, once authenticated with an enterprise system, can authorize applications to access data without additional credentials, using policies to control access based on time and location, and leveraging an expedited authentication API to facilitate secure and efficient access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods are used for each application, then security control is maintained, but user convenience deteriorates due to multiple credentials required

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple authentication credentials into a single enterprise authentication. The mobile device authentication credentials are merged with application-specific credentials, allowing the user to authenticate once with the enterprise system and gain access to multiple applications without entering separate usernames and passwords for each application.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The enterprise authentication system serves as a universal authentication mechanism that works across multiple applications. The authenticated credentials obtained from the enterprise authentication server can be used to access various applications installed on the mobile device, making the authentication system multi-functional rather than application-specific.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If enterprise restrictions are imposed on mobile device applications, then security is improved, but device complexity increases due to policy management

Engineering Contradiction:
ImprovesecurityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that mediates between the enterprise's security requirements and the mobile device's application access. The enterprise authentication server acts as an intermediary that verifies credentials and enforces policies without requiring the mobile device to implement complex restriction management itself. The authentication credentials obtained from this intermediary contain embedded policy information that simplifies enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The enterprise authentication and policy enforcement actions are performed preliminarily before application access is granted. The authentication credentials are obtained in advance through enterprise authentication, and policy restrictions are established beforehand through the authentication mechanism. This preliminary action eliminates the need for complex runtime policy management on the mobile device.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If multiple applications require separate authentication, then access control is precise, but time consumption increases for users

Engineering Contradiction:
Improveaccess efficiencyVSAvoidauthentication time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent merges the authentication process for multiple applications into a single enterprise authentication event. Instead of requiring separate authentication for each application, the user performs one authentication with the enterprise system, and the authentication credentials obtained can be used across multiple applications, significantly reducing the time spent on authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The enterprise authentication is performed as a preliminary action before accessing any applications. The authentication credentials are obtained in advance and stored, allowing rapid access to multiple applications without repeating the authentication process. This preliminary authentication action eliminates the need for repeated credential entry when launching different applications.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11646887B2Policy based authentication
Publication Date: 2023.05.09 CITRIX SYSTEMS INC
  • US11646887B2 patent drawing
  • US11646887B2 patent drawing
  • US11646887B2 patent drawing

AI summary

Methods and systems for expedited authentication for mobile applications are described herein. A user of a mobile device may authenticate with an enterprise system, and thereby be granted access to enterprise applications and services on the mobile device. The user may then activate an application in a managed partition of the mobile device. The application may determine that the enterprise system supports expedited authentication. The application may request expedited authentication, and the request may be compared to policies for expedited authentication. If the request is permitted, the application may be granted access to an authorization code for expedited authentication. The application may then perform the expedited authentication, and the user may be granted access to the application when the expedited authentication has completed.