Authentication Broker Service for Enterprise Access Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large enterprises face challenges in managing access for a large number of diverse and continuously changing external users, as maintaining individual accounts for them can significantly tax the information technology department.
Innovation Solution
An authentication broker service is introduced, which works in conjunction with an authentication service to authenticate users by establishing trust relationships between the relying computing entity, the authentication broker service, and the authentication service that issued the user's identity, allowing the broker service to send authentication responses to verify user identities without requiring individual accounts for external users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individual accounts are created and maintained for external users, then authentication security is improved, but IT department workload and system complexity increase significantly
Solution Approach 1:
The patent introduces an authentication broker service as an intermediary between the relying computing entity and external users. The broker service receives authentication requests from the relying entity, validates credentials against stored authentication information, and returns authentication results. This intermediary approach maintains security by centralizing authentication logic while reducing the complexity of managing individual accounts for each external user, as the broker service handles the authentication overhead centrally rather than requiring the relying entity to manage each user account individually.
2Measurement precision
If individual accounts are created and maintained for external users, then access control precision is improved, but administrative burden and time consumption increase
Solution Approach 1:
The authentication broker service enables external users to authenticate themselves using their own credentials without requiring manual account creation or management by the IT department. The broker service automatically validates credentials against stored authentication information and returns authentication results to the relying computing entity. This self-service approach maintains precise access control by verifying each user's credentials while eliminating the time-consuming administrative burden of manually creating, updating, and maintaining individual user accounts.
3Reliability
If the enterprise issues identities directly to external users, then authentication reliability is improved, but system adaptability to diverse external users decreases
Solution Approach 1:
The authentication broker service provides a universal authentication mechanism that can handle diverse external users from different organizations with varying authentication requirements. Instead of requiring the relying computing entity to issue identities directly to each external user, the broker service serves as a universal authentication point that can validate credentials from multiple external sources. This multi-functional approach maintains authentication reliability by centralizing validation logic while increasing system adaptability to accommodate diverse external users from different enterprises with different authentication protocols and credential formats.
Data Source
AI summary
A user is authenticated for a relying computing entity (e.g., an enterprise) through an authentication broker service, wherein a trust relationship exists between the relying computing entity and the authentication broker service. The authentication broker service has a trust relationship with the relying computing entity and the authentication service that issued the identity of the user. The relying computing entity asks the authentication broker service to authenticate the identity of the user. The authentication broker service captures the user's credential (or directs the authentication service to do so) and sends an authentication response (e.g., a token) to the relying computing entity in order to authenticate the identity of the user to the relying computing entity. The relying computing entity verifies the authentication response based on the trust relationship between the relying computing entity and the authentication broker service.


