Centralized Access Control Module for SSO Agent Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current single sign-on (SSO) session management systems are burdensome and costly due to the need for multiple access management agents across various platforms and versions, leading to high hardware and software administration and maintenance requirements, which can impact network performance and user experience.

Innovation Solution

A hardware and software configuration that includes an access control module on the application server intercepting login requests, redirecting them to a proxy gateway where application-specific access management agents authenticate the user, reducing the need for agents on each server and simplifying maintenance by distributing network load across multiple gateways.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple access management agents are deployed on each server for different applications, then authentication and access control for multiple applications is enabled, but device complexity and maintenance requirements increase significantly

Engineering Contradiction:
Improveauthentication capabilityVSAvoidagent deployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the access management agents from the application servers and relocates them to a centralized session management server. This separation removes the complexity of deploying and maintaining multiple agents on each server while preserving the ability to authenticate users across multiple applications. The centralized server handles all authentication requests for different applications through a single location.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The centralized session management server performs multiple functions that were previously distributed across separate agents: it manages authentication for multiple applications, handles session creation and validation, and provides access control policies. This multi-functional design eliminates the need for separate agents on each server while maintaining comprehensive authentication capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If access management agents are installed on each server, then application-specific authentication is achieved, but hardware and software administration and maintenance costs increase

Engineering Contradiction:
Improveauthentication securityVSAvoidadministration and maintenance
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges all access management functions into a single centralized session management server. Instead of having separate agents on each server that need individual administration, all authentication and access control operations are consolidated in one location, significantly reducing administration and maintenance efforts while maintaining secure authentication across applications.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If a centralized session management server is used, then maintenance and upgrade time is reduced, but network traffic and processing load on the server increase

Engineering Contradiction:
Improvemaintenance efficiencyVSAvoidnetwork processing load
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent segments the authentication process into distinct phases: authentication requests are sent to the centralized session management server, which validates credentials and creates sessions. Once authenticated, users can access applications directly without repeated authentication. This segmentation reduces the server's ongoing processing load while maintaining efficient maintenance through centralized control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8832814B2System and method for providing access to a software application
Publication Date: 2014.09.09 FMR CORP
  • US8832814B2 patent drawing
  • US8832814B2 patent drawing
  • US8832814B2 patent drawing

AI summary

System and method configured to provide an access management system configuration that provides the benefits of single sign-on while reducing internal hardware and administration maintenance costs. The system is reconfigured to provide an access control module that directs authentication network traffic such that access management agents are not required to be installed on the application server for each protected application. The system provides a redirection of a login request from the application server to an external security gateway that authenticates the user via policy and sends authenticated user credentials on a back channel to the access control module to obtain a session cookie which is redirected back to the user so the user can establish a session with the application. The solution reduces the plethora of agents to be maintained and upgraded in order to remain compatible with the evolving hosting software, reducing both hardware and administration maintenance costs.