Thin Client Auto Logon for Secure Remote Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online account access methods, such as single-sign-on (SSO) approaches, pose risks of credential compromise due to server-to-server communications and require custom development on external systems, while thick client architectures offer one-click access but increase security risks by storing login functionality locally.

Innovation Solution

A thin client approach that performs automatic logon using stored user credentials without local logic, establishing a new session to access remote resources, and stores credentials centrally to prevent transmission between the user's system and external systems, thereby reducing security risks and eliminating the need for custom external system development.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-sign-on (SSO) approaches are used to provide centralized authentication, then user convenience is improved by avoiding repeated credential entry, but security is worsened due to server-to-server communications and credential transmission between systems

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the credential transmission step from the authentication process. Instead of transmitting credentials between servers or storing them locally, the system uses a thin client that performs automatic logon without credential transmission, thereby removing the security vulnerability while maintaining user convenience

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a thin client as an intermediary component that mediates between the user's browser and the external system. This thin client acts as a bridge that enables automatic authentication without exposing credentials, resolving the contradiction between convenience and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If thick client architecture is used to provide local login functionality, then user convenience is improved by enabling one-click access, but security is worsened by storing credentials and login logic locally on the user's system

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent removes the login functionality and credential storage from the user's local system. By extracting these elements, the system eliminates the security risks associated with local credential storage while maintaining automatic logon capability through a thin client that operates without local logic

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of storing credentials locally in a thick client, the system uses a thin client that temporarily assumes the session credentials during the authentication process. This copying approach allows automatic logon without persistent local storage, thereby maintaining convenience while eliminating security risks

Inventive Principle:
Principle #26Copying

3Ease of operation

If SSO, OAuth, or OpenID architectures are used to enable centralized authentication, then user convenience is improved, but system complexity is worsened due to requiring custom development on external systems

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a universal thin client solution that works with multiple external systems without requiring custom development on each system. The thin client handles the complexity of authentication internally, providing a universal interface that simplifies integration across different platforms and systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9262621B1Methods systems and articles of manufacture for implementing user access to remote resources
Publication Date: 2016.02.16 INTUIT INC
  • US9262621B1 patent drawing
  • US9262621B1 patent drawing
  • US9262621B1 patent drawing

AI summary

Methods, systems, and articles of manufacture for implementing user access to remote resources residing on an external domain. Various implementations include authenticating and authorizing a user on a first system and receiving user request to access remote resources. The first system invokes processes or modules to initiate a new session to perform auto logon on behalf of the user on a second system by using stored user's credentials and subdomain delegation techniques without user intervention. The second system authenticates and authorizes this new session to allow user access to remote resources residing thereupon. The first system further prepares the user's system to take over the new session by setting cookie(s) and also by redirecting the URL so the user may continue to use the new session to access the desired remote resources residing on the second system.