Mobile Terminal Single Sign-On Script Replay for VPN Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience with the need to input login information twice when accessing the corporate intranet through mobile applications, as existing EMM technologies require separate authentication for the VPN and application access, affecting user experience.

Innovation Solution

A terminal single sign-on configuration method that records and replays authentication operations and login parameters for VPN access, allowing automatic authentication of mobile applications by generating a script associated with VPN login information and uploading it to a server for subsequent use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If separate authentication processes are used for VPN and application access, then security requirements are met, but user convenience deteriorates due to repeated login inputs

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication process complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent combines the VPN authentication process with the application authentication process into a single unified authentication flow. The configuration system captures and replays the entire authentication sequence (including VPN login and application access) as one integrated process, eliminating the need for separate authentication steps and reducing user burden while maintaining security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary recording of the authentication process during a configuration phase. The complete authentication sequence is captured in advance as a replayable script, so that during actual use, the system can automatically execute the pre-recorded authentication steps without requiring user intervention for each login, thereby improving convenience while preserving security controls.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If manual authentication inputs are required for each application access, then authentication security is maintained, but time consumption increases due to repeated login procedures

Engineering Contradiction:
Improveaccess efficiencyVSAvoidlogin time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent creates a copy of the authentication process in the form of a replayable script that contains the complete authentication sequence. Instead of requiring users to manually perform authentication steps each time, the system captures the authentication flow once and replays it automatically, significantly reducing the time required for subsequent application accesses while maintaining the same security verification.

Inventive Principle:
Principle #26Copying

3Reliability

If a secure tunnel is established for the application, then network security is improved, but user experience deteriorates due to the need for dual authentication inputs

Engineering Contradiction:
Improvenetwork securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent establishes the secure tunnel once during the recorded authentication process and maintains its validity for subsequent application accesses. The replayed authentication script leverages the already-established secure tunnel, eliminating the need to re-establish it or perform additional authentication steps, thereby preserving network security while continuously providing seamless user access without interruption or repeated inputs.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10033717B2Terminal single sign-on configuration, authentication method, and system, and application service system thereof
Publication Date: 2018.07.24 SANGFOR TECH INC
  • US10033717B2 patent drawing
  • US10033717B2 patent drawing
  • US10033717B2 patent drawing

AI summary

The present invention provides a terminal single sign-on configuration, authentication method, and system. The terminal single sign-on authentication method includes obtaining a VPN login information for accessing a private virtual network, where the application service system is installed on a mobile terminal; and uploading the VPN login information to a server for verification. When the VPN login information is successfully verified, a recorded script associated with the VPN login information is obtained from the server, the recorded script containing a plurality of operations and login parameters corresponding to input controls in a user interface of the application service system for authentication. The method further includes according to the recorded script, automatically replaying the plurality of operations to input the login parameters to the corresponding input controls in the user interface, such that an authentication process for the application service system is completed automatically.