Biometric Single Sign-On with Active Directory Join
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Clinical and pharmaceutical workflows face inefficiencies due to the time-consuming process of multiple logins and logouts across various on-premises and cloud services, which wastes time and resources for healthcare professionals.
Innovation Solution
A method and system for instant single sign-on that uses biometric authentication to capture user identification, performs an active directory join operation, and launches a browser with an HTML page featuring clickable icons for provisioned services, enabling no-click access to both on-premises and cloud services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional single sign-on processes are used with multiple logins and logouts across different services, then security authentication is maintained, but time efficiency and productivity deteriorate due to repeated manual authentication steps
Solution Approach 1:
The system performs preliminary biometric authentication and service provisioning before the user needs to access services. The authentication server pre-establishes user credentials and service access rights, so when the user launches the browser, authentication is already complete and services are ready for immediate access without repeated login steps.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the user and multiple services. This server handles all authentication requests centrally, verifying user identity once through biometric data and then managing access to both on-premises and cloud services, eliminating the need for separate logins to each service.
2Reliability
If manual mouse-clicking and keyboard input are required to access services after authentication, then service security is maintained, but ease of operation and productivity worsen due to multiple manual interaction steps
Solution Approach 1:
The system enables self-service by automatically provisioning services to the user based on pre-established authentication. Once the user's identity is verified through biometric authentication, the system automatically grants access to authorized services without requiring the user to manually navigate, click, or input credentials for each service.
Solution Approach 2:
Service provisioning is performed in advance during the authentication phase. The authentication server determines which services the user is authorized to access and prepares access credentials beforehand, so when the user needs to access services, everything is already configured and ready for immediate use.
3Reliability
If multiple authentication steps are required for accessing on-premises and cloud services, then comprehensive security coverage is achieved, but device complexity and operational complexity increase
Solution Approach 1:
The authentication server is designed as a universal system that handles both on-premises and cloud service authentication through a single interface. It accepts biometric authentication data and manages access rights across different service types and deployment environments, providing comprehensive security coverage through one multi-functional system rather than multiple separate authentication mechanisms.
Data Source
AI summary
A method, a non-transitory computer readable medium, and a system are disclosed for a single sign-on for services. The method includes: receiving, on a computer processor, user identification captured by a biometric device of a user; forwarding, by the computer processor, the user identification to an authentication server; receiving, on the computer processor, a user JSON Web Token (user-JWT), user principle name, active directory domain name, and user domain name password, upon authentication of the user by the authentication server; performing, by the computer processor, an active directory join operation with an active directory using the user principle name, the active directory domain name, and the user domain name password; launching, on the computer processor, a browser that communicates with the authentication server; and receiving, on the computer processor, an HTML page constructed with JavaScript code with clickable icons for provisioned services from the authentication server.


