Authentication Service Determination for SSO Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional single sign-on (SSO) systems using Security Assertion Markup Language (SAML) face challenges in securely directing unauthenticated users to appropriate Identity Providers (IdPs) within an intranet, as displaying a list of IdPs can compromise user privacy and security.

Innovation Solution

An information processing system and method that employs an authentication service determination service to redirect unauthenticated users to appropriate IdPs based on user-specific or company-specific key information, eliminating the need to display a list of IdPs and ensuring secure authentication without exposing personal information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a list of IdPs is displayed to enable user selection, then the user can choose the appropriate IdP for authentication, but user privacy and security are compromised due to exposure of personal information

Engineering Contradiction:
ImproveUser ability to select IdPVSAvoidUser privacy and security exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary component (the system determining the appropriate IdP) that mediates between the user and the list of IdPs. Instead of directly displaying the list to the user, the system automatically determines and routes the user to the appropriate IdP based on stored associations, thus eliminating the need for user selection while protecting privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs automatic IdP determination and routing without requiring user intervention or selection. The user's authentication requests are automatically directed to the correct IdP based on pre-stored key information associations, eliminating the need for users to interact with IdP lists and thereby protecting their privacy.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If user-specific or company-specific key information is used to determine authentication path, then user privacy and security are protected, but the system complexity increases due to need for storing and managing key information

Engineering Contradiction:
ImproveUser privacy and security protectionVSAvoidSystem complexity for managing key information
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-storing key information that associates users or companies with their appropriate IdPs. This preparation is done in advance, allowing the system to quickly determine the correct authentication path without complex real-time analysis, thus reducing operational complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the authentication system by creating distinct associations between key information (user-specific or company-specific) and corresponding IdPs. This segmentation allows the system to handle different users or companies through separate, pre-defined paths, simplifying the overall management structure while protecting privacy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2490396B1Information processing system, method for controlling information processing system, and program
Publication Date: 2018.05.30 CANON KK
  • EP2490396B1 patent drawingFigure 1
  • EP2490396B1 patent drawingFigure 2A~2D
  • EP2490396B1 patent drawingFigure 3

AI summary

An information processing system stores key information for determining an authentication device and information about the authentication device by associating these information pieces with each other and extract the key information from access of an unauthenticated user. Based on the information about the authentication device associated with the key information, the access of the unauthenticated user is redirected.