External Application SSO for Thick-Client Apps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for single sign-on (SSO) in thick-client applications are inefficient, requiring technical expertise, heavy server configurations, and are not compliant with cross-platforms, limiting their ability to handle multiple applications effectively.

Innovation Solution

A system and method that enables SSO through an external application using a receiving module, authentication module, encryption module, launching module, and display module, which receives and encrypts user credentials, authenticates them, launches applications via an event-driven protocol, and stores credentials, allowing seamless access to multiple thick-client applications without modifying the applications themselves.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If screen-scraping technique is used for SSO integration, then thick-client applications can be accessed, but the sign-on breaks when screen resolution changes and heavy server configurations are required

Engineering Contradiction:
ImproveSSO compatibility with thick-client applicationsVSAvoidsign-on stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary component that acts as a bridge between the SSO system and thick-client applications. This intermediary captures authentication events through system-level hooks rather than screen scraping, eliminating the dependency on visual display parameters like screen resolution. The intermediary translates authentication requests into appropriate application-specific authentication actions, providing stable and reliable sign-on across different display configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If desktop application development frameworks are used, then SSO can be achieved for thick-clients, but the solution is not cross-platform compliant and requires lengthy development

Engineering Contradiction:
ImproveSSO implementation easeVSAvoidplatform compatibility
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal SSO solution that operates across multiple platforms (Windows, macOS, Linux) by using platform-independent system-level authentication mechanisms. The system employs standardized authentication protocols and event hooks that are available across different operating systems, eliminating the need for platform-specific development frameworks. This multi-functional approach allows the same SSO infrastructure to serve diverse thick-client applications regardless of the underlying operating system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If conventional SSO techniques are used, then existing enterprise solutions can be leveraged, but technical expertise and external consultation are required increasing time and costs

Engineering Contradiction:
ImproveSSO deployment efficiencyVSAvoidimplementation time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements a self-service SSO deployment mechanism that automatically detects the presence of thick-client applications, configures appropriate authentication hooks, and establishes SSO integration without requiring manual intervention from technical experts. The system performs automatic application discovery, configuration generation, and activation, eliminating the need for external consultation and reducing implementation time from weeks to minutes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9985955B2System and method for single sign-on for thick-client applications
Publication Date: 2018.05.29 ILANTUS TECH PVT LTD
  • US9985955B2 patent drawing
  • US9985955B2 patent drawing
  • US9985955B2 patent drawing

AI summary

The embodiments herein provide a system and method to enable a single sign-on into a plurality of thick-client applications through an external application. The system includes an authentication module for authenticating the user credentials for the plurality of thick-client applications received by a receiving module. The authenticated user credentials for the plurality of thick-client applications is stored in a data based and encrypted with an encryption module. The plurality of thick-client applications is launched with a launching module. A display module is provided to display the user credentials for launching the plurality of thick-client applications.