Centralized Identity Platform for Multi-Cloud Security Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The traditional enterprise network perimeter has expanded beyond the physical boundaries, increasing security risks for enterprise data on unsecured devices and requiring multiple security products to manage identity services independently, leading to inefficiencies and duplication.

Innovation Solution

A unified and centralized identity platform assumes responsibility for identity-related services across multiple network security products, providing Single Sign-On and supporting authentication processes like SAML, OAuth, and OpenID Connect, with features such as metadata management and provisioning, acting as a Certificate Authority, and protecting applications with CASB.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple network security products each implement their own independent identity services, then each product can autonomously manage its authentication, but this leads to duplication of identity services and increased system complexity

Engineering Contradiction:
Improveautonomous authentication capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the identity services of multiple network security products into a single centralized identity service. This centralization eliminates duplication while maintaining autonomous authentication capabilities through standardized interfaces, thereby reducing system complexity without sacrificing reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized identity service is designed to serve multiple network security products simultaneously through a universal interface. This multi-functional approach allows a single identity service to handle authentication for various security products, reducing overall system complexity while maintaining autonomous capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If each network security product implements independent identity services, then product autonomy is maintained, but this results in duplication of services and reduced operational efficiency

Engineering Contradiction:
Improveproduct autonomyVSAvoidoperational efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent introduces a centralized identity service as an intermediary between multiple network security products and the authentication infrastructure. This mediator maintains product autonomy by providing standardized interfaces while improving operational efficiency by eliminating service duplication and enabling centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If a centralized identity service is implemented for multiple network security products, then duplication of identity services is avoided and operational efficiency improves, but this increases the complexity of integrating multiple products

Engineering Contradiction:
Improveoperational efficiencyVSAvoidintegration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent changes the interface parameters and communication protocols to standardized formats, enabling the centralized identity service to interact with multiple network security products uniformly. This standardization reduces integration complexity while maintaining high operational efficiency by avoiding duplication.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If independent identity services are used in each security product, then product-specific authentication requirements can be met, but this leads to loss of time in user authentication across multiple products

Engineering Contradiction:
Improveproduct-specific authenticationVSAvoidauthentication time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The centralized identity service performs preliminary authentication actions that are valid across multiple network security products. By establishing authentication credentials once in the centralized service, the system eliminates repeated authentication time while still meeting product-specific requirements through configurable policies.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12495044B2Unified identity platform for multiple cloud services
Publication Date: 2025.12.09 ZSCALER INC
  • US12495044B2 patent drawing
  • US12495044B2 patent drawing
  • US12495044B2 patent drawing

AI summary

Systems and methods for providing identity services are provided. A method, according to one implementation, includes a step of assuming unified and centralized responsibility for performing identity-related services for a plurality of network security products. In response to an end user device attempting to initiate a session with a selected network security product of the plurality of network security products, the method may perform the identity-related services to manage or authenticate an identity of the end user device or a user of the end user device. Then, the method includes a step of enabling the end user device to establish the session with or receive a service from the selected network security product after performing the identity-related services.