Authentication Proxy Engine for Seamless Single Sign-On
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in managing multiple security credentials across various web services, leading to increased risk and administrative complexity, especially in enterprise environments, where seamless and secure single sign-on (SSO) solutions are needed without compromising security or requiring extensive configuration.
Innovation Solution
A web gateway with an authentication proxy engine (PAE) that authenticates users and provides seamless SSO by intercepting page requests, auto-filling credentials, and enforcing enterprise policies, including biometric and two-factor authentication, while hiding service URLs and supporting on-the-fly data encryption for cloud storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users manually manage security credentials for each web service, then security control is maintained, but administrative complexity and time consumption increase significantly
Solution Approach 1:
The patent introduces an authentication proxy engine as an intermediary component that sits between the user and multiple web services. This proxy engine automatically manages authentication by intercepting login requests, injecting credentials, and handling authentication flows across different services. The proxy acts as a mediator that eliminates the need for users to manually manage credentials for each service, thereby reducing administrative complexity and time consumption while maintaining security control.
Solution Approach 2:
The authentication proxy engine implements self-service capabilities by automatically detecting login forms, auto-filling credentials, and completing authentication processes without user intervention. The system monitors web pages for authentication requirements and autonomously handles the credential submission process, allowing the authentication mechanism to serve itself rather than requiring manual user input for each service.
2Adaptability or versatility
If single sign-on solutions are implemented using local password repositories, then access to multiple services is simplified, but security risks increase due to centralized credential storage
Solution Approach 1:
Rather than implementing a local password repository that centralizes credential storage, the patent uses an authentication proxy engine as an intermediary that manages authentication dynamically. The proxy intercepts authentication requests and injects credentials on-demand without requiring a centralized storage mechanism on the client device. This approach maintains versatility for accessing multiple services while avoiding the security risks associated with centralized credential storage.
Solution Approach 2:
The system performs preliminary authentication actions by pre-configuring the authentication proxy engine with enterprise credentials before users need to access services. The proxy engine is pre-loaded with authentication capabilities and enterprise credentials, allowing it to automatically handle authentication requests without requiring users to store or manage passwords locally. This preliminary setup enables multi-service access while maintaining security by keeping credentials managed centrally on the server side rather than stored locally.
3Ease of operation
If proxy authentication is implemented to enable seamless SSO, then user experience is improved, but device and network complexity increases
Solution Approach 1:
The patent merges the authentication proxy functionality directly into the web gateway infrastructure, combining multiple functions (authentication, proxying, credential management) into a single integrated component. By merging the authentication proxy engine with the existing web gateway, the system improves user experience through seamless SSO while minimizing the increase in device complexity, as the proxy functionality is consolidated rather than added as a separate complex system.
Solution Approach 2:
The authentication proxy engine is designed with universal capabilities that allow it to handle authentication for multiple different web services and protocols through a single implementation. The proxy can detect and adapt to various authentication mechanisms (form-based, ticket-based, certificate-based) and service types, providing seamless SSO across diverse services without requiring separate configurations for each service. This multi-functionality reduces the overall complexity compared to implementing service-specific authentication solutions.
4Reliability
If enterprise policies are enforced through centralized authentication, then security control is improved, but system complexity and configuration requirements increase
Solution Approach 1:
The authentication proxy engine serves as an intermediary that enforces enterprise security policies by intercepting authentication requests and applying policy rules centrally. The proxy receives authentication requests from users, checks them against enterprise policies stored on the gateway server, and determines whether to grant or deny access. This centralized policy enforcement through the proxy intermediary improves security control while simplifying configuration, as policies are managed on the server side rather than requiring complex client-side configurations.
Solution Approach 2:
The system implements feedback mechanisms where the authentication proxy engine continuously monitors authentication attempts and communicates with the enterprise policy management system. When authentication requests are intercepted, the proxy queries the policy database to determine the appropriate action, and the results are fed back to control the authentication flow. This feedback loop enables automated policy enforcement without requiring manual configuration on each device, improving security control while reducing configuration complexity.
Data Source
AI summary
In an example, a web gateway is described, including an authentication proxy engine (PAE). The PAE authenticates a user device via, for example, a username and password, biometric data, or two-factor authentication. The web gateway then provides seamless and transparent single sign-on (SSO) for one or more web services. When the user requests a web page from the web service, the PAE inserts custom code that detects a login action. When the user logs in, a one-time token may be provided to auto-fill the username and password field. When the user submits the form, the PAE provides the actual credentials to the web service. The PAE may also provide authentication via authentication headers.


