Centralized Authentication for Distributed Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face cumbersome and insecure processes when accessing data across different company networks, requiring separate logins and managing multiple access credentials, with no unified view of data from various networks.

Innovation Solution

A distributed network system with a central server system, transformation service, and security module that allows users to access and manage data from multiple business object servers through a single login, providing a unified view of data by harmonizing business objects across different servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users access data from multiple company networks using current technology, then data access capability is improved, but user operation complexity increases due to separate logins and credential management for each network

Engineering Contradiction:
Improvedata access capabilityVSAvoiduser operation complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a centralized authentication service as an intermediary between users and multiple company networks. This service manages user credentials and authentication states centrally, allowing users to authenticate once and access multiple networks without manual re-login. The intermediary handles the complexity of multi-network authentication behind the scenes, resolving the contradiction between broad data access capability and simple user operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users log into multiple computer networks to access data, then data accessibility is improved, but security risk increases due to managing multiple login credentials

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The centralized authentication service acts as a secure intermediary that manages all credential storage and authentication operations. Instead of users managing multiple credentials across different networks, the intermediary service securely handles authentication for all networks through a unified interface. This centralizes security management, reduces the attack surface, and eliminates the need for users to store and manage multiple sensitive credentials locally, thereby reducing security risks while maintaining broad data accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service authentication where the centralized service automatically manages credential validation, authentication state tracking, and secure access grant/revocation across all networks. The service monitors and manages security operations autonomously without requiring user intervention in credential management, reducing the security risks associated with manual credential handling while preserving access flexibility.

Inventive Principle:
Principle #25Self-service

3Reliability

If data is stored decentrally on different server systems, then system reliability is improved, but data access complexity increases when accessing data across multiple networks

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddata access complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized authentication service serves as an intermediary layer between users and the decentralized server systems. It manages authentication states and access permissions centrally while the actual data remains distributed across multiple servers. This intermediary handles the complexity of coordinating access across decentralized systems, presenting a unified access interface to users while maintaining the reliability benefits of decentralized storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication service is designed as a universal system that can authenticate users across multiple different company networks and server systems through a single interface. It provides multi-functional capabilities including credential management, authentication state tracking, and access coordination across diverse decentralized systems, thereby reducing data access complexity while preserving system reliability through decentralized architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If separate login credentials are provided for each network, then network security is improved, but user time consumption increases due to managing multiple credentials

Engineering Contradiction:
Improvenetwork securityVSAvoiduser time consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The centralized authentication service acts as an intermediary that manages all network credentials centrally. Users authenticate once through this intermediary, which then handles the credential validation and access grant processes for multiple networks automatically. This eliminates the need for users to manually manage and input credentials for each network separately, significantly reducing time consumption while the intermediary maintains network security through centralized, controlled credential verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2915304B1Method and system for accessing data in a distributed network system
Publication Date: 2019.06.05 OMS SOFTWARE
  • EP2915304B1 patent drawingFigure 1
  • EP2915304B1 patent drawingFigure 2
  • EP2915304B1 patent drawingFigure 3

AI summary

A method and a system for accessing data using a client device in a distributed network system are provided, wherein at least one business object server stores a number of business objects, wherein - each business object server comprises a number of offices, wherein each business object in the respective business object server is assigned to an office, - a central server system receives an access request message from the client device, wherein the access request message comprises at least one explicit client identifier, - the central server system uses the client identifier to ascertain at least one access authorization, wherein an access authorization indicates the offices and the business objects of the offices that the client device is permitted to access, and - the central server system produces access instructions for the business objects that the client device is permitted to access, wherein the access instructions are used to read the business objects from the respective office in the respective business object server and to transmit them to the client device.