Federated Identity Extension for Desktop Application Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Federated identity technologies are limited in extending access to desktop applications and computer systems, as they primarily function for web-based services, failing to provide seamless authentication and access control for desktop environments.
Innovation Solution
A method that involves receiving a web-service access token, generating a system access token for a remote desktop session, and effectuating a remote desktop session associated with the system access token, allowing users to access desktop applications by synthesizing user identifiers and privileges from the web-service access token, thereby enabling access to system resources and profile settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If federated identity is used for web-based services, then authentication across security realms is enabled, but access to desktop applications and computer systems is not achieved
Solution Approach 1:
The patent extends federated identity technology to perform multiple functions: it maintains its original capability for web-based service authentication while adding new functionality for desktop application and computer system access. The system achieves universality by making federated identity applicable across different platforms and environments (web, desktop, local systems) through a unified authentication mechanism that generates appropriate access tokens for each context.
Solution Approach 2:
The patent transitions federated identity from a two-dimensional web-based authentication model to a three-dimensional access model that includes web services, desktop applications, and local computer systems. This dimensional expansion is achieved by introducing new token types (system access tokens, desktop access tokens) and authentication flows that operate across multiple layers of the computing environment, enabling vertical and horizontal expansion of access capabilities.
2Reliability
If separate accounts are maintained for each security realm, then access control is precise, but administrative overhead increases
Solution Approach 1:
The patent merges multiple account management systems into a unified federated identity framework. Instead of maintaining separate accounts in each security realm, the system combines authentication capabilities across realms through trust relationships, allowing a single set of credentials to authenticate users across multiple domains. This consolidation maintains security through token-based access control while eliminating the need for separate account creation and management in each realm.
Solution Approach 2:
The patent introduces federated identity tokens and authentication services as intermediaries between users and multiple security realms. These tokens act as mediators that carry user identity and authorization information across domain boundaries, eliminating the need for direct account relationships between users and each security realm. The intermediary token system maintains precise access control while reducing administrative burden by centralizing credential management.
3Ease of operation
If separate accounts are created for partners, then access to remote company resources is enabled, but security risks increase
Solution Approach 1:
The patent changes the fundamental parameters of credential management by transitioning from permanent account-based authentication to temporary token-based authentication. System access tokens have defined lifetimes and scopes, allowing dynamic adjustment of access parameters based on specific requirements. This parameter flexibility enables easy access granting while maintaining security through time-limited, purpose-specific credentials that can be revoked without affecting underlying account structures.
Solution Approach 2:
The patent employs disposable, short-lived system access tokens instead of permanent partner accounts. These tokens are generated on-demand for specific access scenarios and automatically expire after use or after a defined period. This approach enables partners to access remote company resources easily when needed while minimizing security risks, as compromised or outdated tokens become invalid automatically and do not provide long-term access. The disposable nature of these tokens eliminates the security burden of managing permanent external accounts.
Data Source
AI summary
Techniques for extending federation services to access desktop applications are herein described. In addition to the foregoing, other aspects are described in the claims, drawings, and text forming a part of the present disclosure.


