Thin Client Auto Logon for Secure Remote Resource Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online account access methods, such as single-sign-on (SSO) approaches, pose risks of credential compromise due to server-to-server communications and require custom development on external systems, while thick client architectures offer one-click access but increase security risks by storing login functionality locally.
Innovation Solution
A thin client approach that performs automatic logon using stored user credentials without local logic, establishing a new session to access remote resources, and stores credentials centrally to prevent transmission between the user's system and external systems, thereby reducing security risks and eliminating the need for custom external system development.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If single-sign-on (SSO) approaches are used to provide centralized authentication, then user convenience is improved by avoiding repeated credential entry, but security is worsened due to server-to-server communications and credential transmission between systems
Solution Approach 1:
The patent extracts the credential transmission step from the authentication process. Instead of transmitting credentials between servers or storing them locally, the system uses a thin client that performs automatic logon without credential transmission, thereby removing the security vulnerability while maintaining user convenience
Solution Approach 2:
The patent introduces a thin client as an intermediary component that mediates between the user's browser and the external system. This thin client acts as a bridge that enables automatic authentication without exposing credentials, resolving the contradiction between convenience and security
2Ease of operation
If thick client architecture is used to provide local login functionality, then user convenience is improved by enabling one-click access, but security is worsened by storing credentials and login logic locally on the user's system
Solution Approach 1:
The patent removes the login functionality and credential storage from the user's local system. By extracting these elements, the system eliminates the security risks associated with local credential storage while maintaining automatic logon capability through a thin client that operates without local logic
Solution Approach 2:
Instead of storing credentials locally in a thick client, the system uses a thin client that temporarily assumes the session credentials during the authentication process. This copying approach allows automatic logon without persistent local storage, thereby maintaining convenience while eliminating security risks
3Ease of operation
If SSO, OAuth, or OpenID architectures are used to enable centralized authentication, then user convenience is improved, but system complexity is worsened due to requiring custom development on external systems
Solution Approach 1:
The patent creates a universal thin client solution that works with multiple external systems without requiring custom development on each system. The thin client handles the complexity of authentication internally, providing a universal interface that simplifies integration across different platforms and systems
Data Source
AI summary
Methods, systems, and articles of manufacture for implementing user access to remote resources residing on an external domain. Various implementations include authenticating and authorizing a user on a first system and receiving user request to access remote resources. The first system invokes processes or modules to initiate a new session to perform auto logon on behalf of the user on a second system by using stored user's credentials and subdomain delegation techniques without user intervention. The second system authenticates and authorizes this new session to allow user access to remote resources residing thereupon. The first system further prepares the user's system to take over the new session by setting cookie(s) and also by redirecting the URL so the user may continue to use the new session to access the desired remote resources residing on the second system.


