Single Sign-On Security via Real-World Placeholder Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Single sign-on (SSO) services do not provide adequate security as user credentials are injected into web pages, making them visible to attackers, and traditional placeholders are detectable, compromising security.

Innovation Solution

Employing real-world placeholder data that mimics actual credentials, generated by the server for each authentication attempt, and requiring additional gestures for automated sign-on to enhance security post-authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional placeholder data is used in automated sign-on, then the sign-on process is automated and convenient, but the placeholders are detectable by attackers compromising security

Engineering Contradiction:
Improveautomated sign-on convenienceVSAvoiddetectability of placeholders by attackers
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates realistic copies of actual credential data (email addresses, names, domains) that mimic the structure and appearance of real user information. These copied placeholders are indistinguishable from genuine credentials to attackers, yet serve the automated sign-on function. The system generates fake but realistic-looking data that replicates the format and characteristics of actual user credentials.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent dynamically changes the parameters of placeholder data by generating unique, realistic credentials for each automated sign-on attempt rather than using static placeholders. The system varies email addresses, names, and domain configurations to create diverse placeholder sets that adapt to different web services, making detection through pattern recognition ineffective.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If user credentials are injected into web pages for SSO, then single sign-on functionality is achieved, but credentials become visible to attackers reducing security

Engineering Contradiction:
ImproveSSO functionalityVSAvoidcredential visibility to attackers
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces realistic placeholder data as an intermediary between the automated sign-on system and the web service authentication process. This mediator fulfills the credential injection requirement for SSO functionality while preventing actual user credentials from being exposed. The placeholder acts as a substitute that maintains the authentication flow without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates realistic copies of credential data that can be injected into web pages to maintain SSO functionality. These copied credentials mimic the appearance and structure of real authentication data, allowing the SSO process to proceed normally while preventing exposure of actual user credentials to attackers monitoring page injections.

Inventive Principle:
Principle #26Copying

3Reliability

If real-world placeholder data is generated for each authentication attempt, then security is enhanced by making placeholders undetectable, but system complexity increases

Engineering Contradiction:
Improvesecurity against credential theftVSAvoidsystem complexity for generating placeholders
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service generation of realistic placeholder credentials using automated algorithms that create valid-looking email addresses, names, and domain configurations without manual intervention. The system serves itself by automatically generating diverse, realistic placeholder data sets tailored to different web service requirements, reducing the need for complex manual configuration while enhancing security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20160255074A1Single sign-on service security protections
Publication Date: 2016.09.01 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US20160255074A1 patent drawing
  • US20160255074A1 patent drawing
  • US20160255074A1 patent drawing

AI summary

One embodiment provides a method, including: receiving, from an end user device, authentication data of a user of a web service; storing, in a single sign-on service, the authentication data; receiving, at the single sign-on service, one or more initiations for the web service; generating, using a processor, real-world placeholder data for the user; and employing the real-world placeholder data in an automated sign-on process to the web service. Other embodiments are described and claimed.