Proximity Single Sign-On via Identity Management Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on services share users' private information with service providers without user consent, and often lack sufficient hardware resources for easy credential input.
Innovation Solution
A proximity authorization method that allows a user to authenticate using a nearby device, performing local authorization and sending a server authorization request to an identity management server, while protecting user privacy by controlling information sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single sign-on service shares user private information with service providers, then authentication convenience is improved, but user privacy protection deteriorates
Solution Approach 1:
The patent introduces an identity management server as an intermediary between users and service providers. This server handles authentication requests and coordinates the proximity-based authorization process, preventing direct exposure of user credentials to service providers while still enabling convenient single sign-on functionality across multiple services
Solution Approach 2:
The patent uses proximity authorization requests and responses as digital copies or proxies for actual credential verification. Instead of sharing real user credentials, the system exchanges authorization tokens and proximity verification data that replicate the authentication function without exposing sensitive information
2Adaptability or versatility
If the requesting device lacks specific hardware resources for credential input, then device accessibility is improved, but authentication capability deteriorates
Solution Approach 1:
The patent creates a universal authentication mechanism where any device can serve as an authorization endorsing device for proximity-based sign-on. The system doesn't require specific hardware capabilities on the requesting device, as the endorsing device provides the necessary biometric or credential verification, making authentication accessible across diverse device types
Solution Approach 2:
The authorization endorsing device acts as an intermediary that provides the missing hardware capabilities (biometric receivers, keyboards) to the requesting device. Through proximity communication, the endorsing device performs credential input and verification, enabling devices without these resources to still complete authentication
Data Source
AI summary
A method and apparatus of a device that endorses a proximity authorization for an authorization requesting device is described. In an exemplary embodiment, the device receives a proximity authorization request from the authorization requesting device, wherein the authorization requesting device is in proximity with the authorization endorsing device. The device additionally presents a local authorization request to a user of the authorization endorsing device and receives a set of user credentials for the local authorization request. The device further performs a local authorization on the device using at least the set of user credentials. In addition, the device sends a server authorization request to an identity management server, receives an authorization response from the identity management server, and returns the authorization response.


