Proxy Session Validation for Automatic Multi-System Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in enabling users to log into multiple software systems using a single set of credentials without re-entering credentials or relying on Single Sign-On (SSO) services, especially in systems that do not support SSO or have security constraints.

Innovation Solution

A method that determines a login session for a first client device, verifies the user session between the first client device and a first software system, and automatically logs the first client device into a second user account in a second software system without requiring user intervention, using a proxy communication channel and decryption data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Single Sign-On (SSO) service is used to enable automatic login to multiple software systems, then ease of operation is improved, but device complexity and reliance on external services increase

Engineering Contradiction:
Improveease of loginVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a proxy communication channel as an intermediary between the first client device and first software system, and the second client device and second software system. This proxy mechanism enables automatic login to multiple systems without requiring direct integration or complex SSO services, resolving the contradiction by providing a simple mediation layer that maintains ease of operation while avoiding system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automatic login to the second software system without requiring user intervention or manual configuration. The proxy communication channel automatically verifies user sessions and facilitates credential passing between systems, allowing the system to serve itself rather than requiring complex SSO infrastructure or manual user actions

Inventive Principle:
Principle #25Self-service

2Productivity

If proxy communication channel is established to verify user session automatically, then productivity is improved, but loss of information may occur during proxying

Engineering Contradiction:
Improvelogin efficiencyVSAvoidverification data integrity
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent creates a copy of the verification response at the second software system during the proxying process. This copying mechanism ensures that the verification data is preserved and can be used for automatic login decisions without being lost or corrupted during transmission through the proxy channel, thus maintaining information integrity while improving login efficiency

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The proxy communication channel establishes a feedback loop where verification responses are received, copied, and used to make automatic login decisions. This feedback mechanism ensures that verification data is not lost but rather preserved and utilized throughout the authentication process, maintaining both productivity and information integrity

Inventive Principle:
Principle #23Feedback

3Ease of operation

If automatic login is implemented without user intervention, then ease of operation is improved, but security risks increase due to potential session hijacking or fraud

Engineering Contradiction:
Improveautomatic loginVSAvoidsession authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary verification of the user session authenticity through the proxy communication channel before enabling automatic login to the second software system. This preliminary action ensures that only legitimate sessions are accepted, preventing session hijacking or fraud while maintaining ease of operation through automatic login

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The proxy communication channel serves as a secure intermediary that verifies session authenticity before allowing automatic login. This intermediary layer adds a security check without requiring user intervention, resolving the contradiction by maintaining both ease of operation and session reliability through the verification mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250077642A1Validating a user session
Publication Date: 2025.03.06 VIM
  • US20250077642A1 patent drawing
  • US20250077642A1 patent drawing
  • US20250077642A1 patent drawing

AI summary

A method, system, and apparatus comprising: determining that a login session enabled a first client device to log into a first software system, whereby establishing a user session; automatically verifying the user session to ensure that the user session is authentic, by: establishing a proxy communication channel between the first client device and the first software system via a second client device and a second software system; proxying a verification request to the first software system; proxying a verification response from the first software system; storing a copy of the verification response at the second software system; obtaining decryption data; decrypting the verification response at the second software system to extract verification user data; and verifying the user session based on the verification user data; and automatically logging the first client device into the second software system based on said verifying.