Single Sign-On Security via Real-World Placeholder Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Single sign-on (SSO) services do not provide adequate security as user credentials are injected into web pages, making them visible to attackers, and traditional placeholders are detectable, compromising security.
Innovation Solution
Employing real-world placeholder data that mimics actual credentials, generated by the server for each authentication attempt, and requiring additional gestures for automated sign-on to enhance security post-authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional placeholder data is used in automated sign-on, then the sign-on process is automated and convenient, but the placeholders are detectable by attackers compromising security
Solution Approach 1:
The patent creates realistic copies of actual credential data (email addresses, names, domains) that mimic the structure and appearance of real user information. These copied placeholders are indistinguishable from genuine credentials to attackers, yet serve the automated sign-on function. The system generates fake but realistic-looking data that replicates the format and characteristics of actual user credentials.
Solution Approach 2:
The patent dynamically changes the parameters of placeholder data by generating unique, realistic credentials for each automated sign-on attempt rather than using static placeholders. The system varies email addresses, names, and domain configurations to create diverse placeholder sets that adapt to different web services, making detection through pattern recognition ineffective.
2Adaptability or versatility
If user credentials are injected into web pages for SSO, then single sign-on functionality is achieved, but credentials become visible to attackers reducing security
Solution Approach 1:
The patent introduces realistic placeholder data as an intermediary between the automated sign-on system and the web service authentication process. This mediator fulfills the credential injection requirement for SSO functionality while preventing actual user credentials from being exposed. The placeholder acts as a substitute that maintains the authentication flow without compromising security.
Solution Approach 2:
The system creates realistic copies of credential data that can be injected into web pages to maintain SSO functionality. These copied credentials mimic the appearance and structure of real authentication data, allowing the SSO process to proceed normally while preventing exposure of actual user credentials to attackers monitoring page injections.
3Reliability
If real-world placeholder data is generated for each authentication attempt, then security is enhanced by making placeholders undetectable, but system complexity increases
Solution Approach 1:
The patent implements self-service generation of realistic placeholder credentials using automated algorithms that create valid-looking email addresses, names, and domain configurations without manual intervention. The system serves itself by automatically generating diverse, realistic placeholder data sets tailored to different web service requirements, reducing the need for complex manual configuration while enhancing security.
Data Source
AI summary
One embodiment provides a method, including: receiving, from an end user device, authentication data of a user of a web service; storing, in a single sign-on service, the authentication data; receiving, at the single sign-on service, one or more initiations for the web service; generating, using a processor, real-world placeholder data for the user; and employing the real-world placeholder data in an automated sign-on process to the web service. Other embodiments are described and claimed.


