Patent No. US9686273 (titled "Aggregator technology without usernames and passwords") on Feb 24, 2016. The application was issued on Jun 20, 2017.
’273 is related to the field of automated identity and access management, specifically focusing on single sign-on (SSO) aggregation. The technology addresses the friction and security risks associated with managing multiple sets of credentials across various internal and public-facing web applications, particularly in federated environments where external partners or social identities need access to organizational resources.
The underlying idea behind ’273 is the creation of a hidden, system-generated identity layer that acts as a bridge between a user’s social login and their various web applications. By automatically generating a private user identity that is entirely inaccessible to the end user, the system can map public credentials (like a social media login) to highly secure, system-managed credentials. This allows the system to handle the actual authentication handshake with third-party applications without the user ever needing to know or manage the underlying passwords.
The claims of ’273 focus on a method and system for facilitating a first-time login to a third-party application by leveraging an existing session with an aggregator. The process involves receiving a login request, retrieving a user identity from a social provider, and matching it to a pre-generated private identity stored in a restricted database. Once matched, the system automatically generates a specific secondary identity for that third-party application, which is then used to bypass future credential prompts for that specific service.
In practice, the invention functions as a social single sign-on (sSSO) platform that streamlines the user experience on mobile and desktop devices. When a user interacts with a new application, the system uses the established link between the social provider and the internal secret identity to authorize the creation of a new account or a login session. This mechanism relies on a distributed directory service (such as LDAP) to store the sensitive mapping data, ensuring that the actual authentication tokens remain shielded from the user's view and potential interception.
This approach differs from traditional federation by eliminating the high maintenance and manual configuration typically required to link partner organizations. Unlike standard password managers that simply autofill known fields, this system utilizes a web crawler to identify login-required applications and proactively offers to aggregate them based on user profiles. By shifting the burden of credential generation and storage from the user to a secure, automated backend, the invention reduces the cognitive load of remembering passwords while enhancing the security of the authentication chain.
In the mid-2010s when ’273 was filed, identity and access management was typically implemented using federated identity protocols that required manual mapping between external user IDs and internal application accounts. At a time when systems commonly relied on complex, high-maintenance configurations for each partner organization, cross-network access necessitated that users manage multiple sets of credentials or perform manual linking between social accounts and enterprise identities. Hardware and software constraints of the era made the seamless bridging of disparate authentication providers non-trivial, often resulting in significant administrative overhead for organizations attempting to provide secure, unified access to both internal and public-facing web applications.
The disclosed invention achieves a technical advancement in identity management through an architectural shift that decouples the user-facing authentication process from the application-level credential requirements. By implementing an aggregator system that automatically generates and stores a secret, high-security identity—comprising a username and password entirely unknown and inaccessible to the end user—the system overcomes the constraint of manual credential synchronization. This integration allows for a single sign-on experience where the system maps a public identity provider to a secure, system-managed private identity, enabling automated user provisioning and access to a plurality of aggregated web applications without requiring the user to manage or even possess the underlying credentials for those specific applications.
This patent contains a total of 14 claims, with claims 1 and 8 serving as the independent claims. The independent claims focus on a computer-implemented method and system for managing third-party application logins by matching a user's identity provider credentials to a private internal identity and automatically generating a secondary identity to facilitate subsequent access without re-authentication. The dependent claims serve to specify technical environments such as cloud networks, define various authentication data types and directory services, and detail mechanisms for sharing applications with other registered or unregistered users.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents