Patent No. US10623397 (titled "Aggregator technology without usernames and passwords") on May 18, 2018. The application was issued on Apr 14, 2020.
’397 is related to the field of automated identity and access management, specifically focusing on single sign-on (SSO) aggregator systems. In modern enterprise and social environments, users must manage a growing number of credentials for various internal and public-facing web applications. Traditional federation technologies often require significant manual configuration and high maintenance for each partner organization, creating a technical barrier for seamless cross-platform access.
The underlying idea behind ’397 is to decouple the user's known credentials from the actual authentication secrets used to access aggregated applications. Instead of the user managing multiple passwords, the system generates a private identity—consisting of a secret username and a high-security password—that is entirely unknown and inaccessible to the user. By mapping a familiar social login to this hidden internal credential, the system creates a secure bridge that allows for automated application launching without the user ever needing to handle the underlying sensitive data.
The claims of ’397 focus on a method and system that utilizes an LDAP server to manage the mapping between a social login identity and the stored private credentials. The process involves receiving a social username, identifying the corresponding hidden informational data, and then issuing a secondary challenge—such as a biometric request, social information query, or a specific question-and-answer pair. Once the user passes this challenge, the system activates an aggregator interface that provides one-click access to all authorized web applications.
In practice, the invention functions as a social single sign-on (sSSO) platform that streamlines the user experience across different devices. When a user logs in via a provider like LinkedIn or Facebook, the system formats the secondary authentication challenges into data blocks compatible with that specific provider's format. Upon successful verification, the aggregator displays a dashboard of icons. A key feature of this interface is the use of a visual indicator to distinguish between applications where the user has an active account and those that are not yet enabled, ensuring the user understands their access status at a glance.
This approach differs from prior solutions by eliminating the need for users to remember or re-enter IDs and passwords when switching to new devices or adding new services. By using a distributed cloud database to store inaccessible secrets and employing a web crawler to discover and categorize new login-protected applications, the system proactively expands the user's ecosystem. Furthermore, the social federation aspect allows administrators to delegate application access to external parties securely, bypassing the cumbersome setup typically associated with traditional identity federation.
In the mid-2010s when ’397 was filed, identity and access management was typically implemented using federated identity protocols that required significant manual configuration and maintenance for each partner enterprise. At a time when systems commonly relied on users manually mapping external credentials to internal network IDs, the management of cross-domain authentication often created high administrative overhead. Hardware and software constraints of the era made the seamless aggregation of disparate internal and public-facing applications non-trivial, as secure credential synchronization across different network environments typically necessitated visible user intervention or complex directory service integrations.
The disclosed invention represents a technical advancement in automated identity management through an architectural shift that decouples user-facing authentication from backend application access. By implementing an aggregator system that automatically generates and manages secret, high-security credentials that are entirely unknown and inaccessible to the user, the system overcomes the technical constraint of requiring users to manage multiple sets of credentials for different federated environments. This integration enables a single sign-on capability where a mapping layer translates a primary identity provider login into a system-generated private identity, thereby automating the provisioning and de-provisioning process while enhancing security through the elimination of user-managed passwords for individual sub-applications.
The patent contains a total of 7 claims, with claims 1, 4, and 7 serving as the independent claims. These independent claims focus on a method, system, and computer-readable medium for providing remote access to web applications through an aggregator application using social login identity providers and LDAP server verification, specifically involving the generation of identity challenges and the visual differentiation between enabled and disabled user accounts. The dependent claims serve to further specify the authentication process for unregistered login providers and the automated interface updates when web applications are delegated or shared between users within an organization.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents