Mobile Identity Management via User Agent Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience and security risks due to the repetitive process of entering user identity information across multiple client applications on mobile devices, which also increases the risk of personal data exposure to untrusted entities.

Innovation Solution

A system and method that employs a user agent on the mobile device to manage and securely store user identity information, allowing centralized access and storage through an identity provider, enabling single sign-on across applications and limiting direct access to sensitive data by client applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user identity information is stored locally in each client application, then each application can access the information independently, but the user must repeatedly enter information and security risks increase

Engineering Contradiction:
Improvelogin convenienceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a user agent as an intermediary component that manages user identity information centrally. The user agent stores credentials securely and provides them to client applications through controlled access, eliminating the need for repeated entry while maintaining security through centralized management and authentication protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If user identity information is shared across multiple applications, then login process is simplified, but data exposure to untrusted entities increases

Engineering Contradiction:
Improverepetitive login timeVSAvoiddata exposure risk
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The user agent acts as a secure intermediary that controls information flow between the user's identity data and multiple applications. It implements authentication and authorization mechanisms that allow time-saving information sharing while preventing unauthorized access to untrusted applications through its mediating control layer

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If each application manages its own credentials, then application independence is maintained, but user convenience decreases due to multiple logins

Engineering Contradiction:
Improveapplication independenceVSAvoidmulti-application login process
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The user agent is designed as a universal component that serves multiple client applications simultaneously. It provides a single sign-on mechanism that works across different applications while maintaining their operational independence, allowing users to log in once and access multiple applications without re-entering credentials

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2676497B1System and method for identity management for mobile devices
Publication Date: 2018.04.18 BLACKBERRY LTD
  • EP2676497B1 patent drawingFigure 1(a)
  • EP2676497B1 patent drawingFigure 1(b)
  • EP2676497B1 patent drawingFigure 2

AI summary

Systems and methods for managing a user identity on a mobile device are provided. The system comprises the mobile device comprising a user agent and a client application, the user agent and the client application in communication with each other. The system further comprises an identity provider in communication with the mobile device, and a client service in communication with the mobile device. The user agent is configured to communicate with the identity provider and retrieve the user identity for the client application, and the client application is configured to transmit the user identity to the client service.