Proximity Single Sign-On via Identity Management Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on services share users' private information with service providers without user consent, and often lack sufficient hardware resources for easy credential input.

Innovation Solution

A proximity authorization method that allows a user to authenticate using a nearby device, performing local authorization and sending a server authorization request to an identity management server, while protecting user privacy by controlling information sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single sign-on service shares user private information with service providers, then authentication convenience is improved, but user privacy protection deteriorates

Engineering Contradiction:
Improveauthentication convenienceVSAvoiduser privacy protection
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces an identity management server as an intermediary between users and service providers. This server handles authentication requests and coordinates the proximity-based authorization process, preventing direct exposure of user credentials to service providers while still enabling convenient single sign-on functionality across multiple services

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses proximity authorization requests and responses as digital copies or proxies for actual credential verification. Instead of sharing real user credentials, the system exchanges authorization tokens and proximity verification data that replicate the authentication function without exposing sensitive information

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If the requesting device lacks specific hardware resources for credential input, then device accessibility is improved, but authentication capability deteriorates

Engineering Contradiction:
Improvedevice accessibilityVSAvoidauthentication capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal authentication mechanism where any device can serve as an authorization endorsing device for proximity-based sign-on. The system doesn't require specific hardware capabilities on the requesting device, as the endorsing device provides the necessary biometric or credential verification, making authentication accessible across diverse device types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authorization endorsing device acts as an intermediary that provides the missing hardware capabilities (biometric receivers, keyboards) to the requesting device. Through proximity communication, the endorsing device performs credential input and verification, enabling devices without these resources to still complete authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250200165A1Systems and Methods for Proximity Single Sign-On
Publication Date: 2025.06.19 APPLE INC
  • US20250200165A1 patent drawing
  • US20250200165A1 patent drawing
  • US20250200165A1 patent drawing

AI summary

A method and apparatus of a device that endorses a proximity authorization for an authorization requesting device is described. In an exemplary embodiment, the device receives a proximity authorization request from the authorization requesting device, wherein the authorization requesting device is in proximity with the authorization endorsing device. The device additionally presents a local authorization request to a user of the authorization endorsing device and receives a set of user credentials for the local authorization request. The device further performs a local authorization on the device using at least the set of user credentials. In addition, the device sends a server authorization request to an identity management server, receives an authorization response from the identity management server, and returns the authorization response.