Federated Identity Extension for Desktop Application Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Federated identity technologies are limited in extending access to desktop applications and computer systems, as they primarily function for web-based services, failing to provide seamless authentication and access control for desktop environments.

Innovation Solution

A method that involves receiving a web-service access token, generating a system access token for a remote desktop session, and effectuating a remote desktop session associated with the system access token, allowing users to access desktop applications by synthesizing user identifiers and privileges from the web-service access token, thereby enabling access to system resources and profile settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If federated identity is used for web-based services, then authentication across security realms is enabled, but access to desktop applications and computer systems is not achieved

Engineering Contradiction:
Improveaccess capabilityVSAvoidsystem limitation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extends federated identity technology to perform multiple functions: it maintains its original capability for web-based service authentication while adding new functionality for desktop application and computer system access. The system achieves universality by making federated identity applicable across different platforms and environments (web, desktop, local systems) through a unified authentication mechanism that generates appropriate access tokens for each context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transitions federated identity from a two-dimensional web-based authentication model to a three-dimensional access model that includes web services, desktop applications, and local computer systems. This dimensional expansion is achieved by introducing new token types (system access tokens, desktop access tokens) and authentication flows that operate across multiple layers of the computing environment, enabling vertical and horizontal expansion of access capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If separate accounts are maintained for each security realm, then access control is precise, but administrative overhead increases

Engineering Contradiction:
Improveaccess controlVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple account management systems into a unified federated identity framework. Instead of maintaining separate accounts in each security realm, the system combines authentication capabilities across realms through trust relationships, allowing a single set of credentials to authenticate users across multiple domains. This consolidation maintains security through token-based access control while eliminating the need for separate account creation and management in each realm.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces federated identity tokens and authentication services as intermediaries between users and multiple security realms. These tokens act as mediators that carry user identity and authorization information across domain boundaries, eliminating the need for direct account relationships between users and each security realm. The intermediary token system maintains precise access control while reducing administrative burden by centralizing credential management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If separate accounts are created for partners, then access to remote company resources is enabled, but security risks increase

Engineering Contradiction:
Improveaccess enablementVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent changes the fundamental parameters of credential management by transitioning from permanent account-based authentication to temporary token-based authentication. System access tokens have defined lifetimes and scopes, allowing dynamic adjustment of access parameters based on specific requirements. This parameter flexibility enables easy access granting while maintaining security through time-limited, purpose-specific credentials that can be revoked without affecting underlying account structures.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent employs disposable, short-lived system access tokens instead of permanent partner accounts. These tokens are generated on-demand for specific access scenarios and automatically expire after use or after a defined period. This approach enables partners to access remote company resources easily when needed while minimizing security risks, as compromised or outdated tokens become invalid automatically and do not provide long-term access. The disposable nature of these tokens eliminates the security burden of managing permanent external accounts.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8887250B2Techniques for accessing desktop applications using federated identity
Publication Date: 2014.11.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8887250B2 patent drawing
  • US8887250B2 patent drawing
  • US8887250B2 patent drawing

AI summary

Techniques for extending federation services to access desktop applications are herein described. In addition to the foregoing, other aspects are described in the claims, drawings, and text forming a part of the present disclosure.