Intermediary Appliance for Automatic Form-Based Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network systems require repetitive and time-consuming user authentication processes for accessing protected resources, leading to password fatigue and decreased user interaction efficiency.

Innovation Solution

An intermediary device or appliance is configured to provide form-based single sign-on functionality by automatically detecting and completing login forms, using a Single Sign-On (SSO) module that manages network traffic between clients and servers, and populates login forms with user authentication credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional login forms are used for each resource access, then security is maintained through authentication, but user interaction efficiency deteriorates due to repetitive authentication

Engineering Contradiction:
ImprovesecurityVSAvoiduser interaction efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication by having users log in once to a gateway, which then automatically handles subsequent authentication for multiple protected resources throughout the session, eliminating the need for repeated login actions

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An intermediary gateway device is introduced between clients and protected resources. This gateway intercepts authentication requests, manages session state, and automatically completes login forms for downstream resources, acting as a mediator that maintains security while improving user efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automatic form filling is implemented, then user efficiency is improved, but system complexity increases due to the intermediary device

Engineering Contradiction:
Improveuser efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The gateway device performs multiple functions including authentication interception, session management, automatic form filling, and cookie handling within a single unified system, reducing the need for multiple separate components and thereby managing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If single sign-on is implemented across multiple resources, then the need for repetitive authentication is reduced, but the complexity of managing authentication state increases

Engineering Contradiction:
Improveauthentication timeVSAvoidauthentication state management
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system uses cookies to provide feedback mechanisms that maintain authentication state across multiple resource accesses. The gateway reads and writes cookies to track session state, automatically determining whether authentication has already occurred and adjusting behavior accordingly

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8966603B2Systems and methods for intercepting and automatically filling in forms by the appliance for single-sign on
Publication Date: 2015.02.24 CITRIX SYSTEMS INC
  • US8966603B2 patent drawing
  • US8966603B2 patent drawing
  • US8966603B2 patent drawing

AI summary

The present invention is directed towards systems and methods for form-based single sign-on by a user desiring access to one or more protected resources, e.g., protected web pages, protected web-served applications, etc. In various embodiments, a single sign-on (SSO) module is in operation on an intermediary device, which is disposed in a network to manage internet traffic between a plurality of clients and a plurality of servers. The intermediary device can identify an authentication response from a server and forward the authentication response to the SSO module. The SSO module can complete a login form in the authentication response with a client's authentication data, return the completed login form to the server and forward cookies associated with the authentication response to the client. In various embodiments, multiple login forms can be completed, transparently to the client, by the SSO module on a client's behalf and reduce time expended by a client in obtaining access to protected resources.