Intermediary Server Credential-Free Login Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity systems face challenges in securely managing user credentials for remote access to web-based and native applications, particularly in preventing credential exposure and unauthorized access, due to human errors and sophisticated threats.

Innovation Solution

A centralized login system using an intermediary server that mirrors webpage state between the client browser and the server, allowing authentication without exposing credentials to the user or client device, and enables secure, tamper-evident, and immutable data storage for access logs and permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user credentials are stored locally on client devices for remote access, then ease of operation is improved, but security is worsened due to credential exposure and potential unauthorized access

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts credentials from the client device environment entirely. Instead of storing credentials locally on user devices, the system uses an intermediary server that holds credentials in a secure credential store. The intermediary server acts as a credential manager that never exposes actual credentials to client devices, thus removing the security vulnerability of local credential storage while maintaining operational ease through automated authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary server as a mediator between user devices and remote applications. This intermediary server manages credentials centrally and handles authentication operations without requiring credentials to be present on client devices. The intermediary server mediates all authentication requests, preventing direct credential exposure while enabling seamless user access to remote applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex and frequently changing passwords are implemented, then security is improved, but ease of operation is worsened due to user management difficulties

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service functionality where the intermediary server automatically manages credential operations. Users do not manually handle complex passwords or authentication tokens. The system automatically generates, stores, rotates, and manages credentials in the secure credential store, and handles authentication operations without requiring user intervention. This eliminates the operational burden of complex password management while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Reliability

If centralized credential management is implemented, then security is improved by preventing credential exposure, but device complexity is worsened due to additional intermediary infrastructure

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the intermediary server to perform multiple functions within a single system. The intermediary server not only manages credentials but also handles authentication operations, mediates communication between client devices and remote applications, and provides secure storage for credentials. This multi-functional approach consolidates what could be multiple separate components into a single unified system, reducing overall system complexity while maintaining centralized credential management security benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11265307B2Credential-free user login to remotely executed applications
Publication Date: 2022.03.01 ALTR SOLUTIONS INC
  • US11265307B2 patent drawing
  • US11265307B2 patent drawing
  • US11265307B2 patent drawing

AI summary

Provided is a process including: receiving, with an intermediary server, a request to access web content at a web server; submitting, from the intermediary server a value by which possession of an access credential is demonstrated, wherein the value is withheld from the client web browser; receiving, by the intermediary web browser, instructions to store in web browser memory an access token; and sending, from the intermediary server, to the client web browser executing on the client computing device, instructions to store the access token in browser memory of the client web browser, thereby authenticating the client web browser without the client web browser having access to the value by which possession of the access credential is demonstrated.