Single-Sign-On Server Automates Application Login
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of computer applications requiring separate login procedures burdens users with managing multiple authentication credentials, leading to increased security risks and maintenance costs, as users often resort to insecure practices to manage diverse login information across varying technology platforms.
Innovation Solution
A system and method that automates the login process by storing user profiles, including authentication data and application-specific information, on a single-sign-on server, which transmits this information to the client machine for seamless access to multiple applications, recognizing application screens, and facilitating revocation or reauthentication based on trigger events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate login procedures are required for each application, then security can be maintained for individual applications, but user burden and complexity increase significantly
Solution Approach 1:
The patent merges multiple separate login procedures into a single unified authentication system. The user profile server consolidates authentication data from multiple applications, allowing users to authenticate once and access multiple applications without repeating the login process for each one individually.
Solution Approach 2:
The user profile server provides universal authentication functionality across multiple applications. A single authentication mechanism serves multiple purposes by managing credentials for different applications, enabling one login to grant access to various services without requiring application-specific login procedures.
2Reliability
If users maintain different logon names and passwords for individual accounts, then security is improved, but users must write down or store credentials which increases risk of unauthorized access
Solution Approach 1:
The user profile server acts as an intermediary between the user and multiple applications. It securely stores and manages authentication credentials, allowing users to access applications without needing to remember or write down multiple passwords. The server mediates the authentication process, eliminating the need for users to store credentials in insecure locations.
3Ease of operation
If the same logon name and password combinations are used for all accounts, then ease of operation is improved, but security is compromised and unauthorized access increases
Solution Approach 1:
The system provides self-service authentication by automatically retrieving and applying the appropriate credentials for each application based on the user's profile. Users don't need to manually enter different passwords for each application; the system automatically handles credential selection and transmission, maintaining both convenience and security.
4Reliability
If users routinely change passwords and record them on paper or in computer files, then security is improved, but time is consumed and users are at greater risk of being compromised
Solution Approach 1:
The user profile server performs preliminary action by pre-storing and pre-managing authentication credentials. Instead of requiring users to remember, write down, or securely store passwords themselves, the system has already prepared and secured the credential information, eliminating the time-consuming tasks of password management while maintaining security.
Data Source
AI summary
User access to applications is controlled by associating an alias for an individual with a user profile for the individual; the user profile typically contains data referring to one or more applications. Access to an application is obtained using the data in the user profile, e.g., through automatic completion of forms or screens within an application. In addition, the user profile may be employed to limit user access to parts of an application, or to terminate a user's access to an application.


