Cloud Authentication Using On-Premises Active Directory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud computing systems using active directory (AD) face challenges in efficiently managing user authentication and permission across on-premises environments and cloud platforms, requiring complex setups like ADFS or ADFS Proxy for ID collaboration and single sign-on.
Innovation Solution
An information processing apparatus that includes an authenticating unit to receive authentication requests with organization and domain information, and a qualification information issuing unit to generate and manage user credentials within the on-premises environment, enabling simplified directory authentication and permission management without relying on ADFS or ADFS Proxy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ADFS or ADFS Proxy is used for ID collaboration and single sign-on between on-premises active directory and cloud computing platform, then user authentication and permission management can be achieved, but system complexity increases significantly
Solution Approach 1:
The patent extracts the essential authentication functionality from the complex ADFS system and implements a simplified qualification information issuance mechanism. The cloud computing platform directly issues qualification information to terminal apparatus using account information from the on-premises active directory, eliminating the need for ADFS or ADFS Proxy infrastructure while maintaining authentication reliability.
Solution Approach 2:
The patent creates a universal authentication mechanism where the cloud computing platform's qualification information issuance unit can handle authentication requests from multiple terminal apparatus across different domains. This multi-functional approach replaces the specialized ADFS infrastructure with a more versatile direct issuance system that works across various cloud platforms and terminal devices.
2Reliability
If ADFS or ADFS Proxy is deployed for seamless authentication across environments, then user authentication capability is improved, but ease of operation deteriorates due to complex setup and configuration
Solution Approach 1:
The terminal apparatus performs self-service authentication by presenting account information from the on-premises active directory to the cloud computing platform. The cloud platform's qualification information issuance unit automatically verifies and issues credentials without requiring manual configuration of ADFS infrastructure, enabling users to authenticate seamlessly without administrator intervention for complex setup.
Solution Approach 2:
The system performs preliminary configuration by establishing the qualification information issuance mechanism in advance. The cloud computing platform is pre-configured with the ability to directly issue qualification information using account information from the on-premises active directory, eliminating the need for complex ADFS setup and configuration during deployment.
3Adaptability or versatility
If traditional ADFS-based single sign-on is implemented, then user authentication across domains is achieved, but device complexity and configuration requirements increase
Solution Approach 1:
The patent merges the authentication functionality directly into the cloud computing platform, combining the qualification information issuance capability with the existing account information verification. This integration eliminates the separate ADFS infrastructure and creates a unified authentication system that maintains cross-domain authentication capability while reducing overall system complexity.
Data Source
AI summary
An information processing apparatus issuing qualification information that is used by a terminal apparatus in using a service includes an authenticating unit configured to receive an authentication request, which includes organization information, domain information, and account information in an on-premises environment, from the terminal apparatus, and search for a user belonging to an organization identified by the organization information from user administration information based on the account information in the on-premises environment in response to a correspondence between the organization information and the domain information inside organization administration information, which causes the organization information and the domain information to correspond; and a qualification information issuing unit configured to issue the qualification information to the searched user.


