Aggregator technology without usernames and passwords

Patent No. US9686273 (titled "Aggregator technology without usernames and passwords") on Feb 24, 2016. The application was issued on Jun 20, 2017.

What is this patent about?

’273 is related to the field of automated identity and access management, specifically focusing on single sign-on (SSO) aggregation. The technology addresses the friction and security risks associated with managing multiple sets of credentials across various internal and public-facing web applications, particularly in federated environments where external partners or social identities need access to organizational resources.

The underlying idea behind ’273 is the creation of a hidden, system-generated identity layer that acts as a bridge between a user’s social login and their various web applications. By automatically generating a private user identity that is entirely inaccessible to the end user, the system can map public credentials (like a social media login) to highly secure, system-managed credentials. This allows the system to handle the actual authentication handshake with third-party applications without the user ever needing to know or manage the underlying passwords.

The claims of ’273 focus on a method and system for facilitating a first-time login to a third-party application by leveraging an existing session with an aggregator. The process involves receiving a login request, retrieving a user identity from a social provider, and matching it to a pre-generated private identity stored in a restricted database. Once matched, the system automatically generates a specific secondary identity for that third-party application, which is then used to bypass future credential prompts for that specific service.

In practice, the invention functions as a social single sign-on (sSSO) platform that streamlines the user experience on mobile and desktop devices. When a user interacts with a new application, the system uses the established link between the social provider and the internal secret identity to authorize the creation of a new account or a login session. This mechanism relies on a distributed directory service (such as LDAP) to store the sensitive mapping data, ensuring that the actual authentication tokens remain shielded from the user's view and potential interception.

This approach differs from traditional federation by eliminating the high maintenance and manual configuration typically required to link partner organizations. Unlike standard password managers that simply autofill known fields, this system utilizes a web crawler to identify login-required applications and proactively offers to aggregate them based on user profiles. By shifting the burden of credential generation and storage from the user to a secure, automated backend, the invention reduces the cognitive load of remembering passwords while enhancing the security of the authentication chain.

How does this patent fit in bigger picture?

Technical Landscape

In the mid-2010s when ’273 was filed, identity and access management was typically implemented using federated identity protocols that required manual mapping between external user IDs and internal application accounts. At a time when systems commonly relied on complex, high-maintenance configurations for each partner organization, cross-network access necessitated that users manage multiple sets of credentials or perform manual linking between social accounts and enterprise identities. Hardware and software constraints of the era made the seamless bridging of disparate authentication providers non-trivial, often resulting in significant administrative overhead for organizations attempting to provide secure, unified access to both internal and public-facing web applications.

Prosecution Position

The disclosed invention achieves a technical advancement in identity management through an architectural shift that decouples the user-facing authentication process from the application-level credential requirements. By implementing an aggregator system that automatically generates and stores a secret, high-security identity—comprising a username and password entirely unknown and inaccessible to the end user—the system overcomes the constraint of manual credential synchronization. This integration allows for a single sign-on experience where the system maps a public identity provider to a secure, system-managed private identity, enabling automated user provisioning and access to a plurality of aggregated web applications without requiring the user to manage or even possess the underlying credentials for those specific applications.

Claims

This patent contains a total of 14 claims, with claims 1 and 8 serving as the independent claims. The independent claims focus on a computer-implemented method and system for managing third-party application logins by matching a user's identity provider credentials to a private internal identity and automatically generating a secondary identity to facilitate subsequent access without re-authentication. The dependent claims serve to specify technical environments such as cloud networks, define various authentication data types and directory services, and detail mechanisms for sharing applications with other registered or unregistered users.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
First user identity
(Claim 1, Claim 8)
The system also maps the login identity provider user name to the secret user name and password for subsequent usage. The user registers and signs on to an aggregator system using any supported login identity provider username and password.The specific username or credential associated with a user's account at an external login identity provider.
Login identity provider
(Claim 1, Claim 8)
Examples of login identity providers include but are not limited to social networking sites, LinkedIn and Facebook. The user registers and signs on to an aggregator system using any supported login identity provider username and password or other authenticating credentials.An external service or social networking site that provides authenticating credentials used by a user to sign on to the aggregator system.
Private user identity
(Claim 1, Claim 8)
The system also automatically creates a system secret or private identity such as a secret username and secret, highly securely generated password, both of which are unknown and inaccessible to the user. The secret identity, such as secret username and password, is stored in an lightweight directory access protocol (LDAP) server or database or in a distributed cloud database system.A secret system-generated credential, such as a username and password, that is created automatically by the system and remains unknown and inaccessible to the end user.
Second storage
(Claim 1, Claim 8)
The secret username and password are stored in an lightweight directory access protocol (LDAP) server or database or in a distributed cloud database system. The second storage is only accessible by the computer system.A secure data repository, such as an LDAP server or cloud database, that is restricted to system access and stores the generated private user identities.
Second user identity
(Claim 1, Claim 8)
The second user identity is used by the computer system to allow the user to login to the third party application during subsequent logins without prompting the user to re-enter authentication credentials. It is automatically generated and associated with the private user identity and the third-party application.A generated credential associated with both the private user identity and a specific third-party application, used to facilitate subsequent logins without user re-authentication.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-03640Apr 24, 2025Avatier IP, LLC v. Microsoft Corporation

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9686273

Application Number
US15052747A
Filing Date
Feb 24, 2016
Publication Date
Jun 20, 2017
External Links
Slate, USPTO , Google Patents