Cloud Authentication Using On-Premises Active Directory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing systems using active directory (AD) face challenges in efficiently managing user authentication and permission across on-premises environments and cloud platforms, requiring complex setups like ADFS or ADFS Proxy for ID collaboration and single sign-on.

Innovation Solution

An information processing apparatus that includes an authenticating unit to receive authentication requests with organization and domain information, and a qualification information issuing unit to generate and manage user credentials within the on-premises environment, enabling simplified directory authentication and permission management without relying on ADFS or ADFS Proxy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ADFS or ADFS Proxy is used for ID collaboration and single sign-on between on-premises active directory and cloud computing platform, then user authentication and permission management can be achieved, but system complexity increases significantly

Engineering Contradiction:
Improveuser authentication and permission managementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential authentication functionality from the complex ADFS system and implements a simplified qualification information issuance mechanism. The cloud computing platform directly issues qualification information to terminal apparatus using account information from the on-premises active directory, eliminating the need for ADFS or ADFS Proxy infrastructure while maintaining authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal authentication mechanism where the cloud computing platform's qualification information issuance unit can handle authentication requests from multiple terminal apparatus across different domains. This multi-functional approach replaces the specialized ADFS infrastructure with a more versatile direct issuance system that works across various cloud platforms and terminal devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If ADFS or ADFS Proxy is deployed for seamless authentication across environments, then user authentication capability is improved, but ease of operation deteriorates due to complex setup and configuration

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The terminal apparatus performs self-service authentication by presenting account information from the on-premises active directory to the cloud computing platform. The cloud platform's qualification information issuance unit automatically verifies and issues credentials without requiring manual configuration of ADFS infrastructure, enabling users to authenticate seamlessly without administrator intervention for complex setup.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary configuration by establishing the qualification information issuance mechanism in advance. The cloud computing platform is pre-configured with the ability to directly issue qualification information using account information from the on-premises active directory, eliminating the need for complex ADFS setup and configuration during deployment.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If traditional ADFS-based single sign-on is implemented, then user authentication across domains is achieved, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvecross-domain authenticationVSAvoidinfrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication functionality directly into the cloud computing platform, combining the qualification information issuance capability with the existing account information verification. This integration eliminates the separate ADFS infrastructure and creates a unified authentication system that maintains cross-domain authentication capability while reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10291620B2Information processing apparatus, terminal apparatus, program, and information processing system for collaborative use of authentication information between shared services
Publication Date: 2019.05.14 RICOH CO LTD
  • US10291620B2 patent drawing
  • US10291620B2 patent drawing
  • US10291620B2 patent drawing

AI summary

An information processing apparatus issuing qualification information that is used by a terminal apparatus in using a service includes an authenticating unit configured to receive an authentication request, which includes organization information, domain information, and account information in an on-premises environment, from the terminal apparatus, and search for a user belonging to an organization identified by the organization information from user administration information based on the account information in the on-premises environment in response to a correspondence between the organization information and the domain information inside organization administration information, which causes the organization information and the domain information to correspond; and a qualification information issuing unit configured to issue the qualification information to the searched user.