Aggregator technology without usernames and passwords

Patent No. US10623397 (titled "Aggregator technology without usernames and passwords") on May 18, 2018. The application was issued on Apr 14, 2020.

What is this patent about?

’397 is related to the field of automated identity and access management, specifically focusing on single sign-on (SSO) aggregator systems. In modern enterprise and social environments, users must manage a growing number of credentials for various internal and public-facing web applications. Traditional federation technologies often require significant manual configuration and high maintenance for each partner organization, creating a technical barrier for seamless cross-platform access.

The underlying idea behind ’397 is to decouple the user's known credentials from the actual authentication secrets used to access aggregated applications. Instead of the user managing multiple passwords, the system generates a private identity—consisting of a secret username and a high-security password—that is entirely unknown and inaccessible to the user. By mapping a familiar social login to this hidden internal credential, the system creates a secure bridge that allows for automated application launching without the user ever needing to handle the underlying sensitive data.

The claims of ’397 focus on a method and system that utilizes an LDAP server to manage the mapping between a social login identity and the stored private credentials. The process involves receiving a social username, identifying the corresponding hidden informational data, and then issuing a secondary challenge—such as a biometric request, social information query, or a specific question-and-answer pair. Once the user passes this challenge, the system activates an aggregator interface that provides one-click access to all authorized web applications.

In practice, the invention functions as a social single sign-on (sSSO) platform that streamlines the user experience across different devices. When a user logs in via a provider like LinkedIn or Facebook, the system formats the secondary authentication challenges into data blocks compatible with that specific provider's format. Upon successful verification, the aggregator displays a dashboard of icons. A key feature of this interface is the use of a visual indicator to distinguish between applications where the user has an active account and those that are not yet enabled, ensuring the user understands their access status at a glance.

This approach differs from prior solutions by eliminating the need for users to remember or re-enter IDs and passwords when switching to new devices or adding new services. By using a distributed cloud database to store inaccessible secrets and employing a web crawler to discover and categorize new login-protected applications, the system proactively expands the user's ecosystem. Furthermore, the social federation aspect allows administrators to delegate application access to external parties securely, bypassing the cumbersome setup typically associated with traditional identity federation.

How does this patent fit in bigger picture?

Technical Landscape

In the mid-2010s when ’397 was filed, identity and access management was typically implemented using federated identity protocols that required significant manual configuration and maintenance for each partner enterprise. At a time when systems commonly relied on users manually mapping external credentials to internal network IDs, the management of cross-domain authentication often created high administrative overhead. Hardware and software constraints of the era made the seamless aggregation of disparate internal and public-facing applications non-trivial, as secure credential synchronization across different network environments typically necessitated visible user intervention or complex directory service integrations.

Prosecution Position

The disclosed invention represents a technical advancement in automated identity management through an architectural shift that decouples user-facing authentication from backend application access. By implementing an aggregator system that automatically generates and manages secret, high-security credentials that are entirely unknown and inaccessible to the user, the system overcomes the technical constraint of requiring users to manage multiple sets of credentials for different federated environments. This integration enables a single sign-on capability where a mapping layer translates a primary identity provider login into a system-generated private identity, thereby automating the provisioning and de-provisioning process while enhancing security through the elimination of user-managed passwords for individual sub-applications.

Claims

The patent contains a total of 7 claims, with claims 1, 4, and 7 serving as the independent claims. These independent claims focus on a method, system, and computer-readable medium for providing remote access to web applications through an aggregator application using social login identity providers and LDAP server verification, specifically involving the generation of identity challenges and the visual differentiation between enabled and disabled user accounts. The dependent claims serve to further specify the authentication process for unregistered login providers and the automated interface updates when web applications are delegated or shared between users within an organization.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Aggregator application
(Claim 1, Claim 4, Claim 7)
Such platform comprises a server that aggregates a plurality of web applications both internal to an organization and that are public facing to login identity providers including social networking sites such as for example LinkedIn or Facebook. The platform presents the aggregation of such web applications as links provided to a particular user. It should be appreciated that the technique discussed herein can also refer to the aggregator system or application, depending on the context of the discussion.A platform or server-based software that collects and presents a plurality of web applications (both internal and public-facing) as links to a user, enabling access to multiple accounts through a single interface.
Lightweight directory access protocol (LDAP) server
(Claim 1, Claim 4, Claim 7)
The secret identity, such as secret username and password, is stored in a lightweight directory access protocol (LDAP) server or database or in a distributed cloud database system. The LDAP server comprising a microprocessor and a memory that stores the user's informational data.A directory service or database used to store the user's informational data and the secret private identity, and which facilitates the comparison of login credentials to trigger the aggregator application.
Private username and/or private password
(Claim 1, Claim 4, Claim 7)
The system also automatically creates a system secret or private identity such as a secret username and secret, highly securely generated password, both of which are unknown and inaccessible to the user. The system also maps the login identity provider user name to the secret user name and password for subsequent usage.A system-generated secret identity created automatically by the aggregator during registration that is mapped to the user's social login but remains unknown and inaccessible to the user.
Social login identity provider
(Claim 1, Claim 4, Claim 7)
Examples of login identity providers include but are not limited to social networking sites, Linkedin and Facebook. The user registers and signs on to an aggregator system using any supported login identity provider username and password or other authenticating credentials.An external third-party service, typically a social networking site, that provides authentication credentials (username and password) used by the user to initially sign on to the aggregator system.
Visual indicator
(Claim 1, Claim 4, Claim 7)
The LDAP server causes the aggregator application to activate and display on the remote computer also web applications on which the user does not have accounts and subsequently are not enabled. The aggregator application is configured to display a visual indicator to indicate that the applications do not have an account for the user and subsequently are not enabled.A graphical display element within the aggregator interface that distinguishes web applications for which the user does not have an active or enabled account.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-03640Apr 24, 2025Avatier IP, LLC v. Microsoft Corporation

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US10623397

Application Number
US15984193A
Filing Date
May 18, 2018
Publication Date
Apr 14, 2020
External Links
Slate, USPTO , Google Patents