I don't think so. Remember SAML and OpenID Connect use the browser to correlate the session. The client (or SP) has no access to this session information, so can't renew the session on behalf of the client. Most federation and SSO solutions today are based on redirecting the subject to the IDP. This enables the IDP to directly manage sessions in the browser.