Bridged identity proxy authentication and authorization system and method

TWI934727BActive Publication Date: 2026-08-01EVERMORE TECH
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
EVERMORE TECH
Filing Date
2025-07-25
Publication Date
2026-08-01

Smart Images

  • Figure TWG2TB001904072_001
    Figure TWG2TB001904072_001
  • Figure TWG2TB001904072_002
    Figure TWG2TB001904072_002
  • Figure TWG2TB001904072_003
    Figure TWG2TB001904072_003
Patent Text Reader

Abstract

This invention relates to a bridged identity proxy authentication and authorization system, comprising: a user device including a user device application registered with a user identity identifier; an enterprise intranet access point server providing access to the enterprise intranet or resources; a network-connected device with a display configured to access the enterprise intranet access point server via a web browser; an identity verification server configured to execute an identity verification protocol to verify the user identity identifier; a third-party identity authorization server configured to execute a third-party identity authorization protocol to verify a third-party identity identifier; and a security node configured to execute a security node mapping layer identity verification method to verify the user identity identifier.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A bridged identity authentication and authorization system, comprising: a user device including a user device application registered with a user identity identifier; an enterprise intranet access point server providing access to an enterprise intranet or resources; a network-connected device with a display configured to access the enterprise intranet access point server via a web browser; an identity verification server configured to execute an identity verification protocol to verify the user identity identifier; a third-party identity authorization server configured to execute a third-party identity authorization protocol to verify a third-party identity identifier; and a security node configured to execute a security node mapping layer identity verification method to verify the user identity identifier. The user identity verification is completed by binding with the third-party identity verification through the identity verification server, the security node and the third-party identity authorization server, so that the third-party identity can be used to log in to the enterprise intranet access point management platform through the network device with display and the identity verification server, and the user device application acts as a proxy for the enterprise intranet access point server.

2. The bridged identity proxy authentication and authorization system as described in claim 1, wherein the security node is contained in a security node mapping layer and configured to perform a security node mapping layer authentication method.

3. The bridged identity proxy verification and authorization system as described in claim 1, wherein the third-party identity authorization agreement is an OAuth third-party identity authorization agreement, an OAuth 2.0 third-party identity authorization agreement, an OIDC third-party identity authorization agreement, or a SAML 2.0 third-party identity authorization agreement.

4. The bridged identity agent verification and authorization system as described in claim 1, wherein the user device is a desktop computer, a laptop computer, a tablet device, or a smartphone.

5. The bridged identity authentication and authorization system as described in claim 1, wherein the identity authentication protocol is a FIDO identity authentication protocol, a FIDO2 identity authentication protocol, an OIDC identity authentication protocol, or a SAML 2.0 identity authentication protocol.

6. A bridged identity proxy authentication and authorization method, comprising: providing a user device connected via a network, an enterprise intranet access point server, a network device with a display, an identity verification server, a third-party identity authorization server, and a security node, wherein the user device includes a user device application registered with a user identity, the identity verification server is configured to execute an identity verification protocol to verify the user identity, and the third-party identity authorization server is configured to execute a third-party identity authorization protocol to verify a third-party identity; A first-level identity verification bridging method is implemented to perform bridging binding between the user's identity and the third-party identity through the identity verification server, the security node, and the third-party identity authorization server; and a second-level proxy identity verification bridging method and a bridging identity authorization method are implemented to use the third-party identity through the network device with a display and the identity verification server to complete the login operation of an enterprise intranet access point management platform by proxying the enterprise intranet access point server through the user device application.

7. The bridged identity proxy authentication and authorization method as described in claim 6 further includes: implementing a security node mapping layer identity authentication method through the security node to verify and register the user identity on the user device and the enterprise intranet access point server.

8. The bridged identity proxy verification and authorization method as described in claim 6, wherein the first-level identity verification bridging method further comprises: the user device application requesting the execution of the third-party identity authorization agreement from the third-party identity authorization server through the identity verification server to verify and authorize the third-party identity recognition; executing the third-party identity authorization agreement through the third-party identity authorization server and returning an authorization result; and performing a bridging binding between the user identity recognition and the third-party identity recognition based on the authorization result, thereby completing a first-level identity bridging binding operation.

9. The bridged identity proxy authentication and authorization method as described in claim 8, wherein the second-level proxy identity authentication bridging method further comprises: requesting a session code from the identity authentication server and displaying it through the network device with a display; retrieving the session code through the user device application to authenticate the user identity on behalf of the enterprise intranet access point server; and bridging and binding the user identity with the session code to complete a second-level identity bridging and binding operation.

10. The bridged identity proxy authentication and authorization method as described in claim 9, wherein the bridged identity authorization method further comprises: based on the third-party identity recognition and the session code, the user device application requests an identity bridging authorization from the identity verification server; and, based on one of the authorization results of the identity bridging authorization, accepting the user identity recognition to log in to the enterprise intranet access point management platform.