Circle of Trust Authentication for Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems require multiple logins across different entities' servers due to lack of interoperability, reducing user satisfaction and productivity, and increasing business costs.

Innovation Solution

A circle of trust is established among affiliated entities through the exchange of certificates and storage in trusted partner lists, allowing authentication assertions to be referenced and verified, enabling single sign-on across multiple servers using open and interoperable designs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication systems are used, then each server can independently authenticate users, but users must log on to each server separately reducing productivity

Engineering Contradiction:
Improveauthentication securityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a trust framework with intermediary authentication entities that mediate between users and multiple servers. Instead of direct authentication to each server, users authenticate once to a trusted entity, and that authentication is propagated through the trust chain to authorize access to multiple resources, eliminating repeated logins while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is designed to be universal, allowing a single authentication event to serve multiple functions across different servers and resources. The trust framework enables one authentication to authorize access to multiple heterogeneous resources, making the authentication mechanism multi-functional rather than requiring separate authentication for each resource

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If each entity uses its own authentication protocol, then authentication can be customized per entity, but interoperability between entities becomes problematic

Engineering Contradiction:
Improveauthentication customizationVSAvoidinteroperability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent employs parameter changes by allowing each entity to configure its authentication parameters (protocols, methods, policies) independently while maintaining compatibility through a standardized trust framework. Entities can customize their authentication parameters according to local requirements while the framework ensures interoperability by translating and recognizing these parameters across the distributed system

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual login scripts are implemented for each server, then access control can be precisely managed, but implementation cost and complexity increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trust framework enables self-service authentication where the system automatically manages authentication propagation across entities. Instead of requiring manual configuration of login scripts for each server, the framework automatically handles the authentication process by traversing the trust chain and propagating authentication tokens, reducing operational complexity while maintaining precise access control

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7716469B2Method and system for providing a circle of trust on a network
Publication Date: 2010.05.11 ORACLE AMERICAN INC
  • US7716469B2 patent drawing
  • US7716469B2 patent drawing
  • US7716469B2 patent drawing

AI summary

Embodiments of the present invention provide a circle of trust on a network. The circle of trust is configured by exchanging credential of a first and a second affiliated entity. The credentials of the first affiliated entity is stored in a trusted partner list of the second affiliated entity. The credentials of the second affiliated entity is stored in a trusted partner list of the first affiliated entity. Thereafter, a circle of trust session may be provided when a client device initiates use of a resource on a relying party device by providing an authentication assertion reference. The identity of the issuing party of the authentication is determined as a function of the authentication assertion reference. The relying party sends an authentication query containing its credential to the issuing party. The issuing party determines if the relying party is a trusted entity based upon whether the relying party's credential is contained in the trusted partner list of the issuing party.