Aggregator System for Federated Identity Without Usernames
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current federated identity management technologies require high maintenance and initial effort for setup and configuration, especially when managing partner access to internal applications across different networks.
Innovation Solution
A system that allows users to register and sign on using any supported login identity provider, creating a secret username and password for secure access to web applications, stored in an LDAP server or distributed cloud database, eliminating the need for traditional usernames and passwords.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If federated identity management is implemented to manage partner access across networks, then access control capability is improved, but maintenance effort and setup complexity increase significantly
Solution Approach 1:
The patent introduces an aggregator system as an intermediary layer between users and multiple web applications. This aggregator handles authentication centrally by creating secret identities and mapping them to various applications, eliminating the need for complex federated identity configurations between each partner organization. The aggregator acts as a mediator that simplifies the authentication architecture while maintaining secure access control across different networks and applications.
Solution Approach 2:
The aggregator system provides universal authentication functionality that works across multiple web applications and partner organizations through a single interface. By creating a universal secret identity system that can be mapped to various applications, the patent eliminates the need for separate federated identity setups for each partner, thereby reducing overall system complexity while maintaining comprehensive access control.
2Ease of operation
If traditional username and password systems are used for each web application, then ease of access is improved, but security and maintenance burden increase
Solution Approach 1:
The patent extracts the authentication management function from individual web applications and centralizes it in the aggregator system. By taking out the username and password management from each application and replacing it with a centralized secret identity system, the patent improves security (by eliminating password exposure) while maintaining ease of access (through automatic authentication). The aggregator extracts and manages all credential-related operations centrally.
Solution Approach 2:
The aggregator system provides self-service authentication by automatically creating secret identities and handling the mapping to various web applications without requiring user intervention for each login. The system automatically manages the authentication process, reducing maintenance burden while providing seamless access to users across multiple applications.
3Reliability
If secret identities are automatically created and stored in LDAP or cloud database, then security is improved, but system complexity increases
Solution Approach 1:
The aggregator system serves as an intermediary that manages secret identity creation and storage, shielding users and individual applications from the complexity of secure credential management. By introducing the aggregator as a mediator layer between the authentication needs and the underlying LDAP or cloud database infrastructure, the patent improves security through centralized management while hiding the system complexity from end users and application developers.
Data Source
AI summary
Techniques are described in which to access a user's web applications, the user registers and signs on to an aggregator system using any supported login identity provider username and password. When the user registers for the first time, the system collects additional information to verify the user for a subsequent access to the system. The system also automatically creates a system secret username and secret, highly securely generated password, both of which are unknown and inaccessible to the user. The secret username and password are stored in a lightweight directory access protocol (LDAP) server or database or in a distributed cloud database system. The system also maps the login identity provider user name to the secret user name and password for subsequent usage.


