Application Delivery Controller Single Sign-On Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in providing seamless authentication across disparate systems, including enterprise, SaaS, and cloud-hosted applications, where disparate hosting leads to increased management and expense due to non-shared passwords and authentication systems.

Innovation Solution

An application delivery controller (ADC) acts as an intermediary, providing single sign-on (SSO) management and integration by intercepting login requests, redirecting users to a single SSO system, and authenticating users according to application policies, allowing access to multiple hosted applications with a single set of credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If disparate authentication systems are used for different hosted applications, then each application can maintain its own authentication independence, but authentication management complexity and cost increase

Engineering Contradiction:
Improveauthentication independenceVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication system that acts as a mediator between users and multiple disparate authentication systems. This intermediary handles the complexity of coordinating different authentication mechanisms while presenting a unified interface to users, thereby maintaining authentication independence across applications while reducing management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is designed with universality to handle multiple types of authentication requests across different application hosts (enterprise, SaaS, cloud) through a single unified mechanism. This multi-functional approach allows one authentication system to serve multiple purposes and applications, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple separate login credentials are required for different applications, then each application can use its own authentication system, but user access time and convenience deteriorate

Engineering Contradiction:
Improveapplication-specific authenticationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple separate authentication processes into a single unified authentication flow. By combining the authentication mechanisms for enterprise applications, SaaS applications, and cloud-hosted applications into one coordinated system, users can access multiple applications with a single authentication action, thereby reducing authentication time while maintaining application-specific security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary authentication actions that establish user identity and authorization in advance, enabling subsequent access to multiple applications without requiring repeated authentication. This preliminary authentication setup reduces the time users would otherwise spend authenticating to each application separately.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If centralized authentication management is implemented, then authentication complexity is reduced, but system integration requirements increase

Engineering Contradiction:
Improveauthentication ease of useVSAvoidsystem integration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The intermediary authentication system serves as a mediator that simplifies integration requirements. Rather than requiring direct integration between multiple disparate authentication systems, the intermediary coordinates communication between them, thereby reducing the complexity of system integration while maintaining centralized management benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into modular components that can independently manage different application types (enterprise, SaaS, cloud) while operating under a unified architecture. This segmentation allows for easier integration and management, as each module can be configured and maintained independently while contributing to the overall centralized authentication strategy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9282097B2Systems and methods for providing single sign on access to enterprise SAAS and cloud hosted applications
Publication Date: 2016.03.08 CITRIX SYSTEMS INC
  • US9282097B2 patent drawing
  • US9282097B2 patent drawing
  • US9282097B2 patent drawing

AI summary

The solution of the present application addresses the problem of authentication across disparately hosted systems by providing a single authentication domain across SaaS and cloud hosted applications as well as traditional enterprise hosted applications. An application delivery controller intermediary to a plurality of clients and the disparately hosted applications providing single sign on management, integration and control. A user may log in via an interface provided, controlled or managed by the ADC, which in turns, authenticates the user to the application in accordance with policy and the host of the application. As such, the user may login once to gain access to a plurality of disparately hosted applications. From the user's perspective, the user seamlessly and transparently gains access to different hosted systems with different passwords and authentication via the remote access provided by the system of the present solution.