Authentication Protocol Management via Intermediary Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the inconvenience of needing to manually log in to multiple services, each with different authentication protocols, especially when accessing resources outside their local network, which can be time-consuming and requires separate credentials.

Innovation Solution

A protocol management system provides a single-sign-on (SSO) capability by acting as an abstraction layer to manage authentication across multiple protocols, allowing users to log in once and automatically translate their protocol to access various services, including those outside their local network, using adaptive protocol switching and multi-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually log in to each service with different authentication protocols, then each service can be accessed securely, but the login process becomes time-consuming and complex

Engineering Contradiction:
Improveauthentication securityVSAvoidlogin time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary authentication service that mediates between users and multiple services. This service establishes trusted relationships with various services in advance, allowing users to authenticate once with the intermediary and then access multiple services without repeated logins. The intermediary translates and forwards authentication credentials between different protocols, resolving the contradiction by maintaining security through protocol translation while reducing login time through single-sign-on capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service performs preliminary actions by pre-establishing trusted relationships and credential translation mechanisms with multiple services before users need to access them. By preparing authentication pathways in advance and caching credential information, the system reduces the time required for actual login while maintaining security protocols. This preliminary setup allows rapid authentication without compromising security verification.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If users access services outside their local network, then resource accessibility improves, but the need for multiple authentication protocols increases complexity

Engineering Contradiction:
Improveservice accessibilityVSAvoidauthentication protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication service achieves universality by supporting multiple authentication protocols (Kerberos, OAuth, SAML, etc.) within a single system. It can authenticate users against services across different networks and protocol requirements without requiring separate authentication mechanisms for each service. This multi-functional capability allows the system to adapt to various network environments and service types while presenting a unified authentication interface to users, thereby improving accessibility without increasing perceived complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs an intermediary authentication service that acts as a mediator between users and external services with different authentication protocols. This intermediary handles protocol translation, credential mapping, and authentication state management, allowing users to access services across network boundaries without directly dealing with protocol complexity. The intermediary absorbs the complexity of multiple protocols while presenting a simplified authentication interface to users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a management server provides single-sign-on across multiple authentication protocols, then user convenience improves, but the system complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The management server acts as an intermediary that consolidates multiple authentication protocol handling into a single system. It maintains trusted relationships with various services, translates between different authentication protocols, and manages user authentication states centrally. This intermediary approach improves user convenience by enabling single-sign-on while containing system complexity within the management server itself, shielding users from the underlying protocol complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple authentication protocol handling capabilities into a single management server system. By combining support for Kerberos, OAuth, SAML, and other protocols within one unified authentication service, the system provides single-sign-on functionality without requiring separate authentication systems for each protocol. This consolidation improves ease of operation while managing complexity through integrated protocol translation and credential management mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11159511B1Authentication protocol management
Publication Date: 2021.10.26 STRATEGY INC
  • US11159511B1 patent drawing
  • US11159511B1 patent drawing
  • US11159511B1 patent drawing

AI summary

Methods, systems, and apparatus, including computer-readable media, for authentication protocol management. In some implementations, a computing device receives data indicating a current context of a client device associated with a particular user. The computing device accesses first authentication data that demonstrates that the particular user has been authenticated using a first authentication protocol. The computing device determines that the particular user is likely to request access to a secured resource based on the current context of the client device and data indicating one or more previous resource accesses by the particular user. The computing device determines that access to the secured resource involves authentication using a second authentication protocol that is different from the first authentication protocol. In response, the computing device authenticates the particular user using the second authentication protocol and establishes an authenticated session for the particular user to access the secured resource.