Authentication Management System for Enterprise Cloud Protocol Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in bridging authentication between enterprise-level protocols like LDAP and cloud-native protocols such as OAuth or OIDC, particularly in managing identity and access for enterprise applications hosted on private on-premise networks, which complicates central governance and integration with cloud-based services.

Innovation Solution

An authentication management system acts as a proxy bridge between enterprise-level authentication protocols (e.g., LDAP) and cloud-native authentication protocols (e.g., OAuth 2.0), translating requests and responses to enable seamless authentication without altering on-premise applications, allowing central identity management and supporting modern identity standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprise applications use traditional enterprise-level authentication protocols (LDAP), then compatibility with existing on-premise systems is maintained, but integration with cloud-native services and centralized identity management becomes complex

Engineering Contradiction:
Improveauthentication protocol compatibilityVSAvoididentity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication management system that acts as an intermediary between enterprise applications using LDAP and cloud-native services requiring OAuth 2.0 or OIDC. This mediator translates authentication requests from enterprise protocols to cloud-native protocols, enabling integration without requiring changes to existing applications or cloud services, thus resolving the contradiction between maintaining protocol compatibility and simplifying identity management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If on-premise applications are modified to support cloud-native authentication protocols, then integration with cloud services improves, but system stability and existing functionality may be compromised

Engineering Contradiction:
Improvecloud integration capabilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication system into distinct components: enterprise applications remain unchanged and continue using LDAP, while a separate authentication management system handles protocol translation to OAuth 2.0 or OIDC for cloud service integration. This segmentation allows cloud integration capabilities to be added without modifying or risking the stability of existing on-premise applications.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If a bridge system is introduced to translate between authentication protocols, then protocol compatibility improves, but system complexity increases

Engineering Contradiction:
Improveprotocol translation capabilityVSAvoidauthentication system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication management system is designed as a universal platform that can handle multiple enterprise authentication protocols (LDAP) and translate to multiple cloud-native protocols (OAuth 2.0, OIDC). This multi-functional design consolidates what could be multiple separate translation systems into a single unified solution, reducing overall system complexity while maintaining broad protocol compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12074877B2Management of user authentication between enterprise-level authentication protocol and cloud-native authentication protocol
Publication Date: 2024.08.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • US12074877B2 patent drawing
  • US12074877B2 patent drawing
  • US12074877B2 patent drawing

AI summary

Examples described herein relate to an authentication management system and a method for managing authentication of a user between an enterprise-level authentication protocol and a cloud-native authentication protocol. The authentication management system may receive an authentication request from an application hosted on a private on-premise network to authenticate a user using the enterprise-level authentication protocol. The authentication request is generated by the application upon receiving an access request from the user via a software as-a-service (SaaS) cloud platform in a cloud-native authentication protocol. Further, the authentication management system may generate an authentication response compliant with the enterprise-level authentication protocol based on an authentication reply that is formatted in compliance to the cloud-native authentication protocol and received from a cloud-native identity and authentication management system based on the authentication request. The authentication management system may then send the authentication response to the application.