Trusted Broker Application for Secure Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users and organizations face significant burdens due to the need for separate sign-in credentials for multiple software applications, leading to increased user authentication efforts and IT inquiries about forgotten credentials.

Innovation Solution

A single sign-on system utilizing a trusted broker application on client devices, which acts as an intermediary between the identity provider and third-party applications, generating and managing tokens for user authentication, thereby eliminating the need for repeated credential entry across applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate sign-in credentials are required for each application, then security is maintained, but user authentication burden increases and IT support inquiries increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser authentication burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a broker application as an intermediary component that mediates between the identity provider and third-party applications. The broker stores authentication credentials securely on the client device and manages the authentication process, allowing users to sign in once and access multiple applications without repeatedly entering credentials, while maintaining security through controlled credential distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The broker application serves multiple functions: it acts as a credential storage vault, an authentication manager, a secure communication intermediary, and an application launcher. This multi-functional component eliminates the need for separate credential management for each application, reducing user burden while maintaining security through centralized control

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple credential sets are managed for different applications, then access control is precise, but credential management complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The broker application serves as an intermediary that manages credential storage and distribution. It maintains secure vaults for different credential sets and controls their release to appropriate applications, simplifying the management complexity while preserving precise access control through centralized credential management

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments credential management into distinct functional components: credential storage vaults, authentication protocols, and application-specific credential release mechanisms. This segmentation allows complex credential management to be broken down into manageable, modular components that work together systematically

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If centralized identity provider is used, then single sign-on is achieved, but dependency on external system increases and security policy enforcement becomes complex

Engineering Contradiction:
Improvesingle sign-on capabilityVSAvoidsystem dependency and policy enforcement
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The broker application acts as a local intermediary that caches authentication tokens and credentials from the identity provider. This allows the system to maintain single sign-on functionality while reducing real-time dependency on the external identity provider, as the broker can handle subsequent authentication requests locally

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication with the identity provider during the initial sign-in process, obtaining and storing authentication tokens in the broker's secure vault. This preliminary action enables subsequent applications to authenticate using cached credentials without repeated external verification, simplifying ongoing policy enforcement

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10470040B2Secure single sign-on to software applications
Publication Date: 2019.11.05 OKTA INC
  • US10470040B2 patent drawing
  • US10470040B2 patent drawing
  • US10470040B2 patent drawing

AI summary

After an initial user sign-on with an identity provider, and in response to an intention of the user to use a third-party application executing on a client device of the user and requiring user sign-on, the identity provider provides a client script to the third-party application. The client script facilitates user and application authentication and invokes a trusted broker application that interacts with the identity provider to enable the user to use the third-party application. The use of the trusted broker application provided by the identity provider frees the authors of third-party applications from the need to modify their applications to explicitly sign in with the identify provider. For enhanced security, conformance to an organizational security policy is verified at time of sign-on, and an authenticatable link is used to invoke the third-party application to foil attempts by malicious software to substitute another application.