Federated Identity Provider for Mobile Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience and insecurity due to the need to repeatedly enter multiple usernames and passwords for various applications and services, especially on mobile devices, where single sign-on solutions from the browser context do not function effectively due to containerization limitations.

Innovation Solution

Implementing a single sign-on experience for mobile applications by using a federated identity provider that stores authentication tokens, allowing multiple client applications to authenticate without requiring users to re-enter credentials, even if published by different developers, and eliminating the need for specific software development kits (SDKs).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users establish separate accounts with unique usernames and passwords for each application and service, then security credentials can be individually managed for each service, but users face inconvenience and must repeatedly enter credentials for each application

Engineering Contradiction:
Improvesecurity credential managementVSAvoidlogin convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple separate authentication credentials into a single federated account system. Users establish one account with a federated identity provider that can authenticate across multiple applications and services, eliminating the need to manage separate usernames and passwords for each application while maintaining security through centralized credential management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The federated account serves multiple functions across different applications and services. A single set of security credentials established with the federated identity provider can be used to authenticate to any application or service that supports the federation protocol, providing universal access without requiring application-specific credentials.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If users set weak passwords that are short or easy to remember to cope with multiple accounts, then ease of remembering credentials is improved, but security is compromised

Engineering Contradiction:
Improvepassword memorabilityVSAvoidsecurity strength
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

By consolidating multiple password requirements into a single federated account, users only need to remember one strong password instead of multiple weak passwords. The federated identity provider handles the single set of security credentials, allowing users to maintain strong security while improving memorability through reduction of credential quantity.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If browser-based single sign-on solutions are implemented on mobile devices, then users can access multiple services with single credentials, but containerization limitations prevent effective implementation

Engineering Contradiction:
Improvesingle sign-on capabilityVSAvoidcross-application functionality
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a federated identity provider as an intermediary between mobile applications and users. This intermediary handles authentication across application boundaries using a protocol that works within mobile device containerization constraints, enabling single sign-on functionality without requiring changes to individual application containers or operating system-level access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12063208B2Single sign-on for unmanaged mobile devices
Publication Date: 2024.08.13 OMNISSA LLC
  • US12063208B2 patent drawing
  • US12063208B2 patent drawing
  • US12063208B2 patent drawing

AI summary

Disclosed are various examples for providing a single sign-on experience for mobile applications that may or may not be managed. A first application executed in a client device sends an access request to a service provider. The first application receives a redirection response from the service provider that redirects the first application to an identity provider. The first application then receives a further redirection response from the identity provider that causes the first application to request an identity assertion from a second application executed in the client device. The first application receives the identity assertion from the second application. The first authentication then authenticates with the service provider using the identity assertion.