Authentication Device for Single Sign-On with History Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face challenges in implementing single sign-on, especially when dealing with complex authentication methods and conditions, such as multi-factor and adaptive authentication.

Innovation Solution

An authentication device and method that includes an authentication unit to execute an authentication process based on an authentication request containing a description of authentication conditions and methods, a history information generator to record the authentication results, and a communication unit to transmit this information to the user terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication and adaptive authentication are combined to enhance security, then authentication security is improved, but single sign-on realization becomes more difficult

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into separate functional modules: condition evaluation module, authentication method selection module, and authentication execution module. This segmentation allows complex authentication requirements to be broken down into manageable components, enabling single sign-on while maintaining security through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary authentication device is introduced between the user terminal and service provider systems. This intermediary evaluates authentication conditions, selects appropriate authentication methods, and coordinates the authentication process across multiple systems, thereby enabling single sign-on without increasing the complexity at individual service provider endpoints.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If authentication methods and conditions are diversified to enhance security, then authentication flexibility is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication flexibilityVSAvoiduser convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authentication device performs self-service by automatically evaluating authentication conditions and selecting appropriate authentication methods without requiring user intervention. The system autonomously determines which authentication factors to apply based on pre-configured conditions, maintaining user convenience while providing flexible authentication options.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authentication conditions and methods are pre-configured and evaluated in advance. The system prepares authentication parameters and selects methods before the actual authentication event, so that when authentication is needed, the process flows smoothly without requiring users to manually configure or select authentication options.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If each service provider determines authentication methods independently, then authentication customization is improved, but single sign-on capability deteriorates

Engineering Contradiction:
Improveauthentication customizationVSAvoidsingle sign-on capability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authentication device provides universal functionality by serving multiple service provider systems with different authentication requirements. It evaluates conditions and selects authentication methods that satisfy various service provider policies, enabling a single authentication action to grant access across multiple customized systems without requiring separate authentication processes for each.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12223028B2Authentication device and authentication method for single sign-on
Publication Date: 2025.02.11 FUJITSU LTD
  • US12223028B2 patent drawing
  • US12223028B2 patent drawing
  • US12223028B2 patent drawing

AI summary

An authentication device includes an authentication unit, a history information generator and a communication unit. The authentication unit executes, when a user terminal accesses a service provider system, an authentication process based on an authentication request that includes a description pertaining to an authentication condition and an authentication method that correspond to the service provider system. The history information generator generates history information. The history information includes information indicating whether the authentication condition is satisfied and information indicating a result of executing the authentication process by using the authentication method. The communication unit transmits the history information to the user terminal.