Authentication Proxy Engine for Seamless Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in managing multiple security credentials across various web services, leading to increased risk and administrative complexity, especially in enterprise environments, where seamless and secure single sign-on (SSO) solutions are needed without compromising security or requiring extensive configuration.

Innovation Solution

A web gateway with an authentication proxy engine (PAE) that authenticates users and provides seamless SSO by intercepting page requests, auto-filling credentials, and enforcing enterprise policies, including biometric and two-factor authentication, while hiding service URLs and supporting on-the-fly data encryption for cloud storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users manually manage security credentials for each web service, then security control is maintained, but administrative complexity and time consumption increase significantly

Engineering Contradiction:
Improvecredential managementVSAvoidtime for authentication
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent introduces an authentication proxy engine as an intermediary component that sits between the user and multiple web services. This proxy engine automatically manages authentication by intercepting login requests, injecting credentials, and handling authentication flows across different services. The proxy acts as a mediator that eliminates the need for users to manually manage credentials for each service, thereby reducing administrative complexity and time consumption while maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication proxy engine implements self-service capabilities by automatically detecting login forms, auto-filling credentials, and completing authentication processes without user intervention. The system monitors web pages for authentication requirements and autonomously handles the credential submission process, allowing the authentication mechanism to serve itself rather than requiring manual user input for each service.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If single sign-on solutions are implemented using local password repositories, then access to multiple services is simplified, but security risks increase due to centralized credential storage

Engineering Contradiction:
Improveaccess to multiple servicesVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Rather than implementing a local password repository that centralizes credential storage, the patent uses an authentication proxy engine as an intermediary that manages authentication dynamically. The proxy intercepts authentication requests and injects credentials on-demand without requiring a centralized storage mechanism on the client device. This approach maintains versatility for accessing multiple services while avoiding the security risks associated with centralized credential storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication actions by pre-configuring the authentication proxy engine with enterprise credentials before users need to access services. The proxy engine is pre-loaded with authentication capabilities and enterprise credentials, allowing it to automatically handle authentication requests without requiring users to store or manage passwords locally. This preliminary setup enables multi-service access while maintaining security by keeping credentials managed centrally on the server side rather than stored locally.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If proxy authentication is implemented to enable seamless SSO, then user experience is improved, but device and network complexity increases

Engineering Contradiction:
Improveuser experienceVSAvoidproxy configuration
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the authentication proxy functionality directly into the web gateway infrastructure, combining multiple functions (authentication, proxying, credential management) into a single integrated component. By merging the authentication proxy engine with the existing web gateway, the system improves user experience through seamless SSO while minimizing the increase in device complexity, as the proxy functionality is consolidated rather than added as a separate complex system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication proxy engine is designed with universal capabilities that allow it to handle authentication for multiple different web services and protocols through a single implementation. The proxy can detect and adapt to various authentication mechanisms (form-based, ticket-based, certificate-based) and service types, providing seamless SSO across diverse services without requiring separate configurations for each service. This multi-functionality reduces the overall complexity compared to implementing service-specific authentication solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If enterprise policies are enforced through centralized authentication, then security control is improved, but system complexity and configuration requirements increase

Engineering Contradiction:
Improvesecurity controlVSAvoidpolicy configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication proxy engine serves as an intermediary that enforces enterprise security policies by intercepting authentication requests and applying policy rules centrally. The proxy receives authentication requests from users, checks them against enterprise policies stored on the gateway server, and determines whether to grant or deny access. This centralized policy enforcement through the proxy intermediary improves security control while simplifying configuration, as policies are managed on the server side rather than requiring complex client-side configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the authentication proxy engine continuously monitors authentication attempts and communicates with the enterprise policy management system. When authentication requests are intercepted, the proxy queries the policy database to determine the appropriate action, and the results are fed back to control the authentication flow. This feedback loop enables automated policy enforcement without requiring manual configuration on each device, improving security control while reducing configuration complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10554624B2Proxy authentication for single sign-on
Publication Date: 2020.02.04 MCAFEE LLC
  • US10554624B2 patent drawing
  • US10554624B2 patent drawing
  • US10554624B2 patent drawing

AI summary

In an example, a web gateway is described, including an authentication proxy engine (PAE). The PAE authenticates a user device via, for example, a username and password, biometric data, or two-factor authentication. The web gateway then provides seamless and transparent single sign-on (SSO) for one or more web services. When the user requests a web page from the web service, the PAE inserts custom code that detects a login action. When the user logs in, a one-time token may be provided to auto-fill the username and password field. When the user submits the form, the PAE provides the actual credentials to the web service. The PAE may also provide authentication via authentication headers.