Access Manager Digital Signatures Single Sign-On Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current single sign-on systems face issues such as inconsistency in user experience, security concerns, and reluctance from service operators due to potential impersonation and unauthorized access, leading to inconvenience for users and operators.

Innovation Solution

An access manager system provides customizable single sign-on functionality, allowing service operators to configure and customize the sign-on process through an API, maintaining user information across multiple services, and using digital signatures with secret access keys to authenticate messages and prevent impersonation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single sign-on systems are implemented to reduce user burden, then user convenience is improved, but security concerns arise due to potential impersonation and unauthorized access

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted third-party authentication service as an intermediary between users and multiple services. This mediator verifies user identities and manages authentication credentials, allowing users to access multiple services with a single sign-on while maintaining security through centralized verification. The intermediary prevents impersonation by controlling the issuance and validation of authentication tokens.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where authentication decisions and security events are monitored and communicated back to relevant parties. This includes verifying digital signatures, checking authentication status, and providing feedback on authorization decisions to ensure that security policies are enforced while maintaining user convenience.

Inventive Principle:
Principle #23Feedback

2Reliability

If service operators implement their own authentication systems, then security control is improved, but device complexity and operational burden increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication system that can be used across multiple services and platforms. Instead of each service implementing its own authentication mechanism, a single multi-functional authentication service handles verification for various services, reducing overall system complexity while maintaining security control through standardized protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If digital signatures are used to verify sender identity, then security is improved, but message processing time increases

Engineering Contradiction:
Improveidentity verificationVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing trusted relationships and caching authentication credentials before actual message transmission. Digital signatures and verification keys are set up in advance, allowing for faster verification during message processing. The authentication framework is prepared beforehand to minimize processing time during actual communication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9992206B2Enhanced security for electronic communications
Publication Date: 2018.06.05 AMAZON TECH INC
  • US9992206B2 patent drawing
  • US9992206B2 patent drawing
  • US9992206B2 patent drawing

AI summary

Techniques are described for providing enhanced security for electronic communications, such as by including in a message sent between two services a digital signature that is generated by using secret information known to the services, so that the recipient receives assurance regarding the sender's identity if the recipient can replicate the received digital signature using the secret information known to the recipient. In some situations, the enhanced security is used in communications to and/or from an access manager system that provides single sign-on functionality and other functionality to other services for use with those services' users, such as to prevent malicious phishers from inappropriately gaining access to user information. Various services may use the enhanced security techniques when interacting with the access manager system at various times, such as to initiate sign-on for a user and/or to take subsequent action on behalf of a signed-on user.