Simulated Single Sign-On Credential Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional single sign-on approaches are incompatible with many third-party applications, leading to inefficient and insecure management of access, where users must manually input and manage credentials, increasing the risk of credential compromise and misuse outside secure networks.

Innovation Solution

An access management server stores and manages security policy data, including user-specific and application-specific credentials, allowing automatic sign-on to third-party applications without revealing credentials to users, through an administration portal and user portal, using an application access tool that interacts with a browser extension to populate and submit credentials anonymously.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually manage their own sign-on credentials for third-party applications, then users can access applications, but security risk increases and user convenience decreases

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an access management server as an intermediary between users and third-party applications. The server stores credentials securely and automatically provides them during access requests, eliminating the need for users to manually manage credentials while maintaining security through centralized control and audit capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automatic credential provision where the access management server autonomously retrieves and supplies credentials to applications based on pre-configured policies, eliminating manual user intervention while maintaining secure access control.

Inventive Principle:
Principle #25Self-service

2Productivity

If conventional single sign-on is implemented, then access coordination between applications improves, but compatibility with third-party applications deteriorates

Engineering Contradiction:
Improveaccess efficiencyVSAvoidapplication compatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The access management server provides a universal credential management service that works across different application types and authentication protocols. It can manage credentials for both single sign-on compatible applications and third-party applications independently, making the system adaptable to diverse application environments without requiring application-specific configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If users have access to sign-on credentials, then they can manage their own access, but credential compromise risk increases

Engineering Contradiction:
Improveaccess managementVSAvoidcredential compromise risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts credentials from user control and places them under exclusive management of the access management server. Users no longer possess or handle credentials directly; instead, the server securely stores them and provides them automatically during authenticated access requests, eliminating the risk of credential exposure through user storage or transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11089005B2Systems and methods for simulated single sign-on
Publication Date: 2021.08.10 BANK OF AMERICA CORP
  • US11089005B2 patent drawing
  • US11089005B2 patent drawing
  • US11089005B2 patent drawing

AI summary

A system provides access to a third-party application by a user without revealing at least one sign-on credential used to access the application to the user. The system includes an access management server and a permission server. The access management server hosts a user portal. In response to a user input from the user portal requesting to access the application, the access management server requests, from the permission server, confirmation of user's permission to access the application. The permission server determines whether access is confirmed using stored permission data, which includes applications the user is currently permitted to access. If the permission server confirms the user's permission, the access management server redirects the user to a sign-on page of the application, automatically enter the sign-on credentials in an anonymized format that is not readable by the user, and automatically submits the sign-on credentials.