Patent No. US9979715 (titled "Aggregator technology without usernames and passwords") on Jun 19, 2017. The application was issued on May 22, 2018.
’715 is related to the field of automated identity and access management, specifically focusing on single sign-on (SSO) systems that aggregate multiple web applications. It addresses the friction and security risks associated with managing numerous sets of credentials across disparate platforms, particularly in environments where external partners or social identities are used to access internal organizational resources.
The underlying idea behind ’715 is to decouple the user's public social identity from a highly secure, system-generated private identity that remains completely hidden from the user. By mapping a familiar social login to a secret, complex internal credential, the system eliminates the need for users to remember or manage passwords for individual aggregated applications while maintaining a robust security layer through secondary verification.
The claims of ’715 focus on a method and system that utilizes an LDAP server to manage the mapping between a social login username and a secret internal profile. The process involves receiving a social identity, identifying corresponding private data, and issuing a formatted challenge—such as a biometric request or social information query—to verify the user before granting access to a dashboard of all their linked accounts.
In practice, the invention functions as a social federation gateway that streamlines the onboarding of new devices and users. When a user attempts to log in via an unrecognized provider, the system performs a metadata-based lookup to suggest candidate identities, effectively bridging different social personas to the same internal secret account. This allows for a 'one-click' launch experience for any registered web application without the user ever interacting with the underlying passwords.
This approach differs from traditional federation technologies by removing the high maintenance and configuration overhead typically required for each partner organization. By utilizing a secret username and password generated by the system and stored in a distributed cloud database, the invention ensures that even if a user's social account is used for entry, the actual authentication to the target applications relies on credentials that are inaccessible to the end user, thereby reducing the attack surface for credential theft.
In the mid-2010s when ’715 was filed, identity and access management was typically implemented using federated identity protocols that required manual mapping between external user IDs and internal application accounts. At a time when systems commonly relied on users to manually create and manage credentials for each partner network they accessed, the administrative overhead for maintaining these cross-organizational links was high. Hardware and software constraints of the era made the seamless bridging of disparate social identity providers and enterprise applications non-trivial, often forcing a trade-off between user convenience and the security of internal directory services.
The disclosed invention achieves a technical advancement in automated identity management by decoupling the user's authentication experience from the underlying credential requirements of target applications. By architecting an aggregator system that automatically generates and stores secret, system-managed identities—such as high-entropy usernames and passwords that remain unknown to the user—the system overcomes the security risks associated with user-managed passwords and the configuration complexity of traditional federation. This integration allows for a single sign-on capability where the mapping between a public identity provider and a secure internal directory occurs transparently, effectively shielding the internal authentication layer from the end user while maintaining robust access control.
This patent contains a total of 9 claims, with claims 1, 5, and 9 serving as the independent claims. The independent claims focus on a method, system, and storage medium for providing secure access to web applications through an aggregator application by utilizing social login identity providers, LDAP server verification, and formatted identity challenges to authenticate users and manage unregistered login providers. The dependent claims serve to further specify features such as the display of visual indicators for inactive accounts, the identification process for new login providers, and the automatic appearance of delegated or shared web applications within a user's interface.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents