Aggregator technology without usernames and passwords

Patent No. US9979715 (titled "Aggregator technology without usernames and passwords") on Jun 19, 2017. The application was issued on May 22, 2018.

What is this patent about?

’715 is related to the field of automated identity and access management, specifically focusing on single sign-on (SSO) systems that aggregate multiple web applications. It addresses the friction and security risks associated with managing numerous sets of credentials across disparate platforms, particularly in environments where external partners or social identities are used to access internal organizational resources.

The underlying idea behind ’715 is to decouple the user's public social identity from a highly secure, system-generated private identity that remains completely hidden from the user. By mapping a familiar social login to a secret, complex internal credential, the system eliminates the need for users to remember or manage passwords for individual aggregated applications while maintaining a robust security layer through secondary verification.

The claims of ’715 focus on a method and system that utilizes an LDAP server to manage the mapping between a social login username and a secret internal profile. The process involves receiving a social identity, identifying corresponding private data, and issuing a formatted challenge—such as a biometric request or social information query—to verify the user before granting access to a dashboard of all their linked accounts.

In practice, the invention functions as a social federation gateway that streamlines the onboarding of new devices and users. When a user attempts to log in via an unrecognized provider, the system performs a metadata-based lookup to suggest candidate identities, effectively bridging different social personas to the same internal secret account. This allows for a 'one-click' launch experience for any registered web application without the user ever interacting with the underlying passwords.

This approach differs from traditional federation technologies by removing the high maintenance and configuration overhead typically required for each partner organization. By utilizing a secret username and password generated by the system and stored in a distributed cloud database, the invention ensures that even if a user's social account is used for entry, the actual authentication to the target applications relies on credentials that are inaccessible to the end user, thereby reducing the attack surface for credential theft.

How does this patent fit in bigger picture?

Technical Landscape

In the mid-2010s when ’715 was filed, identity and access management was typically implemented using federated identity protocols that required manual mapping between external user IDs and internal application accounts. At a time when systems commonly relied on users to manually create and manage credentials for each partner network they accessed, the administrative overhead for maintaining these cross-organizational links was high. Hardware and software constraints of the era made the seamless bridging of disparate social identity providers and enterprise applications non-trivial, often forcing a trade-off between user convenience and the security of internal directory services.

Prosecution Position

The disclosed invention achieves a technical advancement in automated identity management by decoupling the user's authentication experience from the underlying credential requirements of target applications. By architecting an aggregator system that automatically generates and stores secret, system-managed identities—such as high-entropy usernames and passwords that remain unknown to the user—the system overcomes the security risks associated with user-managed passwords and the configuration complexity of traditional federation. This integration allows for a single sign-on capability where the mapping between a public identity provider and a secure internal directory occurs transparently, effectively shielding the internal authentication layer from the end user while maintaining robust access control.

Claims

This patent contains a total of 9 claims, with claims 1, 5, and 9 serving as the independent claims. The independent claims focus on a method, system, and storage medium for providing secure access to web applications through an aggregator application by utilizing social login identity providers, LDAP server verification, and formatted identity challenges to authenticate users and manage unregistered login providers. The dependent claims serve to further specify features such as the display of visual indicators for inactive accounts, the identification process for new login providers, and the automatic appearance of delegated or shared web applications within a user's interface.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Aggregator application
(Claim 1, Claim 5, Claim 9)
Such platform comprises a server that aggregates a plurality of web applications both internal to an organization and that are public facing to login identity providers including social networking sites such as for example LinkedIn or Facebook. The platform presents the aggregation of such web applications as links provided to a particular user. It should be appreciated that the technique discussed herein can also refer to the aggregator system or application, depending on the context of the discussion.A platform or server-based software that collects and presents a plurality of internal and public-facing web applications as links to a user, allowing access to multiple accounts through a single interface.
Private password
(Claim 1, Claim 5, Claim 9)
The system also automatically creates a system secret or private identity such as a secret username and secret, highly securely generated password, both of which are unknown and inaccessible to the user. The secret identity, such as secret username and password, is stored in an lightweight directory access protocol (LDAP) server or database or in a distributed cloud database system.A highly secure, system-generated credential created during initial registration that is stored in a database and used for internal verification without the user's knowledge.
Private username
(Claim 1, Claim 5, Claim 9)
The system also automatically creates a system secret or private identity such as a secret username and secret, highly securely generated password, both of which are unknown and inaccessible to the user. The system also maps the login identity provider user name to the secret user name and password for subsequent usage.A secret system-generated identifier created by the aggregator system that is mapped to the user's social login but remains unknown and inaccessible to the user.
Social login identity provider
(Claim 1, Claim 5, Claim 9)
Examples of login identity providers include but are not limited to social networking sites, Linkedin and Facebook. The user registers and signs on to an aggregator system using any supported login identity provider username and password or other authenticating credentials.An external third-party service, typically a social networking site, that provides authentication credentials used to sign on to the aggregator system.
Unregistered login identity provider
(Claim 1, Claim 5, Claim 9)
When the user logs in using a new unregistered login identity provider, and the user never enabled that login identity provider web application for the aggregator application, the aggregator application attempts to identify the user by reading a stored list of usernames and related metadata and display candidate selections from the registered login identity providers for the user to select.A new or previously unused authentication source that the user has not yet linked or enabled within the aggregator application.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-03640Apr 24, 2025Avatier IP, LLC v. Microsoft Corporation

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9979715

Application Number
US15626997A
Filing Date
Jun 19, 2017
Publication Date
May 22, 2018
External Links
Slate, USPTO , Google Patents