Aggregator System for Federated Identity Without Usernames

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current federated identity management technologies require high maintenance and initial effort for setup and configuration, especially when managing partner access to internal applications across different networks.

Innovation Solution

A system that allows users to register and sign on using any supported login identity provider, creating a secret username and password for secure access to web applications, stored in an LDAP server or distributed cloud database, eliminating the need for traditional usernames and passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If federated identity management is implemented to manage partner access across networks, then access control capability is improved, but maintenance effort and setup complexity increase significantly

Engineering Contradiction:
Improveaccess control capabilityVSAvoidsetup and maintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an aggregator system as an intermediary layer between users and multiple web applications. This aggregator handles authentication centrally by creating secret identities and mapping them to various applications, eliminating the need for complex federated identity configurations between each partner organization. The aggregator acts as a mediator that simplifies the authentication architecture while maintaining secure access control across different networks and applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The aggregator system provides universal authentication functionality that works across multiple web applications and partner organizations through a single interface. By creating a universal secret identity system that can be mapped to various applications, the patent eliminates the need for separate federated identity setups for each partner, thereby reducing overall system complexity while maintaining comprehensive access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If traditional username and password systems are used for each web application, then ease of access is improved, but security and maintenance burden increase

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity and maintenance burden
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication management function from individual web applications and centralizes it in the aggregator system. By taking out the username and password management from each application and replacing it with a centralized secret identity system, the patent improves security (by eliminating password exposure) while maintaining ease of access (through automatic authentication). The aggregator extracts and manages all credential-related operations centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The aggregator system provides self-service authentication by automatically creating secret identities and handling the mapping to various web applications without requiring user intervention for each login. The system automatically manages the authentication process, reducing maintenance burden while providing seamless access to users across multiple applications.

Inventive Principle:
Principle #25Self-service

3Reliability

If secret identities are automatically created and stored in LDAP or cloud database, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The aggregator system serves as an intermediary that manages secret identity creation and storage, shielding users and individual applications from the complexity of secure credential management. By introducing the aggregator as a mediator layer between the authentication needs and the underlying LDAP or cloud database infrastructure, the patent improves security through centralized management while hiding the system complexity from end users and application developers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10623397B2Aggregator technology without usernames and passwords
Publication Date: 2020.04.14 AVATIER IP LLC
  • US10623397B2 patent drawing
  • US10623397B2 patent drawing
  • US10623397B2 patent drawing

AI summary

Techniques are described in which to access a user's web applications, the user registers and signs on to an aggregator system using any supported login identity provider username and password. When the user registers for the first time, the system collects additional information to verify the user for a subsequent access to the system. The system also automatically creates a system secret username and secret, highly securely generated password, both of which are unknown and inaccessible to the user. The secret username and password are stored in a lightweight directory access protocol (LDAP) server or database or in a distributed cloud database system. The system also maps the login identity provider user name to the secret user name and password for subsequent usage.