Authentication Broker for Federated SSO Interoperability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of storage area networks (SANs) makes centralized management difficult due to resource dispersion, and existing federated single sign-on (SSO) solutions struggle to integrate different authentication technologies across private, public, and hybrid cloud deployments, as they do not interoperate effectively.
Innovation Solution
A broker-based solution that establishes trust between authentication domains using an authentication broker layer, which enables seamless access to protected services by proxying client requests and retrieving security tokens, thereby decoupling trust establishment from access and allowing adaptation to various protocols and policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If federated SSO solutions are implemented across multiple authentication domains, then interoperability between private, public, and hybrid cloud deployments is improved, but system complexity increases due to the need to integrate different authentication technologies and protocols
Solution Approach 1:
An authentication broker is introduced as an intermediary component that mediates between multiple authentication domains. The broker receives authentication requests, determines the appropriate target domain, forwards requests to the correct authentication service, and manages token retrieval and validation. This intermediary approach enables interoperability across different authentication technologies (SAML, OAuth, OpenID Connect) without requiring direct integration between all domains, thereby reducing overall system complexity while maintaining versatility.
Solution Approach 2:
The authentication broker is designed as a universal component that can handle multiple authentication protocols and communicate with various authentication domains (private cloud, public cloud, hybrid cloud). It provides multi-functional capabilities including request routing, protocol translation, token management, and session validation, allowing a single system to serve multiple authentication technologies and domains without requiring separate specialized systems for each protocol.
2Adaptability or versatility
If authentication requests are forwarded to multiple authentication domains, then access to protected services across domains is enabled, but response time increases due to additional network communication and token retrieval steps
Solution Approach 1:
The authentication broker performs preliminary actions by maintaining a registry of authentication domains and their characteristics (supported protocols, endpoint URLs, token formats). This pre-configured knowledge base allows the broker to quickly determine the appropriate target domain and protocol for incoming authentication requests without performing complex real-time discovery or negotiation, thereby reducing authentication response time while still enabling cross-domain access.
Solution Approach 2:
The authentication broker creates and manages simplified representations (copies) of authentication tokens and session information. Instead of requiring direct communication between all authentication domains, the broker creates local copies of authentication state information that can be validated and processed locally, reducing the need for repeated network round-trips and accelerating authentication response times across domains.
Data Source
AI summary
Example embodiments of the present invention provide a method, an apparatus, and a computer program product for brokering establishment of a trusted relationship between a first domain and a second domain. The method includes receiving, from a first domain, a request to establish a trusted relationship with a second domain and brokering establishment of the trusted relationship between the first domain and the second. Other example embodiments include brokering authenticated access for a client in the first domain to a resource in the second domain according to the established trusted relationship.


