Centralized Credential Management for Mobile Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience and security risks when managing multiple software applications on mobile devices, requiring manual entry of credentials for each application, which is time-consuming and increases the risk of identity fraud due to repeated exposure of personal information.

Innovation Solution

A system and method that utilizes a user agent to manage and store credential information centrally on a device and server, enabling single sign-on across multiple applications while ensuring security through encryption and synchronization of key stores across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually enter credential information for each application, then each application can be accessed securely, but the user experiences time-consuming operations and increased risk of identity fraud

Engineering Contradiction:
ImprovesecurityVSAvoidtime-consuming operation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines multiple credential management functions into a single centralized key store system. Instead of managing credentials separately for each application, the system merges all credential storage and retrieval operations into one unified mechanism, allowing users to access multiple applications without repeatedly entering credentials manually.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary actions by automatically storing and managing credential information in advance. When users first provide credentials, the system pre-stores them in the key store, so that subsequent application accesses can retrieve credentials automatically without requiring users to re-enter them each time.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If users provide credential information repeatedly for each application, then each application receives the necessary authentication data, but the risk of identity fraud increases due to repeated exposure of personal information

Engineering Contradiction:
ImproveconvenienceVSAvoididentity fraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a key store as an intermediary component between the user and applications. Instead of users directly providing credentials to each application, the key store acts as a mediator that securely stores credentials and provides them to applications as needed. This reduces the frequency of credential exposure and minimizes identity fraud risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates and manages copies of credential information in a secure key store. Rather than users repeatedly transmitting their actual credentials to multiple applications, the system uses stored copies in the key store to authenticate with applications, reducing the exposure of original personal information.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple applications are loaded onto a mobile device, then the device becomes more resourceful, but the complexity of managing credential information for each application increases

Engineering Contradiction:
ImproveresourcefulnessVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key store is designed as a universal credential management system that serves multiple applications simultaneously. Instead of requiring separate credential management mechanisms for each application, the single key store provides multi-functional support for storing, retrieving, and managing credentials across all installed applications, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8689299B2System and method for accessing a software application
Publication Date: 2014.04.01 MALIKIE INNOVATIONS LTD
  • US8689299B2 patent drawing
  • US8689299B2 patent drawing
  • US8689299B2 patent drawing

AI summary

Systems and methods for managing a user identity on a mobile device are provided. The system comprises the mobile device comprising a user agent and a client application, the user agent and the client application in communication with each other. The system further comprises an identity provider in communication with the mobile device, and a client service in communication with the mobile device. The user agent is configured to communicate with the identity provider and retrieve the user identity for the client application, and the client application is configured to transmit the user identity to the client service.