Cloud Authentication Endpoint Registered as Local Directory Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networked directory services systems, users face the inconvenience of needing to log in twice to access both enterprise and cloud-based resources, and additional equipment is required for authentication, making the process cumbersome and resource-intensive.

Innovation Solution

A remote or cloud-based authentication endpoint is registered as a local address in the user's directory services system, allowing a client application to authenticate without user interaction, using a service ticket that includes on-premises log-in identity, thus enabling single sign-on access to cloud-based resources without a second log-in or additional equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a user logs in to local enterprise directory services system and then logs in again to cloud-based directory services system, then access to both enterprise and cloud resources is secured, but the sign-on process becomes time-consuming and cumbersome

Engineering Contradiction:
Improvesecure accessVSAvoidsign-on time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the local enterprise directory services authentication with the cloud-based directory services authentication by registering the cloud authentication endpoint as a local address. This allows the user's local authentication ticket to be automatically accepted by the cloud service, combining two separate authentication processes into one unified sign-on experience while maintaining security for both enterprise and cloud resources

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary mechanism where the cloud authentication endpoint is registered in the local directory services system as a local address. This intermediary registration enables the local system to recognize and accept cloud service authentication requests, facilitating seamless single sign-on without requiring users to manually authenticate twice

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If additional local translation devices or federation servers are installed to translate user identities into tokens, then single sign-on is enabled, but equipment resources and system complexity increase

Engineering Contradiction:
Improvesingle sign-on capabilityVSAvoidauthentication equipment
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the authentication endpoint registration function from the cloud service and places it directly into the local directory services system. By taking out the endpoint registration task and integrating it into the local system, the patent eliminates the need for separate federation servers or translation devices, as the local directory services system itself gains the capability to recognize cloud endpoints natively

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes the local directory services system universal by enabling it to handle both traditional local authentication and cloud-based authentication through a single integrated mechanism. The system can now recognize and process authentication requests from cloud services registered as local addresses, eliminating the need for dedicated translation equipment and simplifying the overall authentication infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10749854B2Single sign-on identity management between local and remote systems
Publication Date: 2020.08.18 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10749854B2 patent drawing
  • US10749854B2 patent drawing
  • US10749854B2 patent drawing

AI summary

Single sign-on identity management between local and cloud-based systems is provided. A remote or cloud-based authentication endpoint is registered as a local device, service or resource in a user's local directory services system. A local device and associated user requesting access to cloud-based resources will then see the authentication endpoint as an internal (inside the enterprise) server and may supply an authentication ticket which includes on-premises log-in or sign-on identity for the user. The remote or cloud-based authentication endpoint may then validate the authentication ticket, and the user may then access devices, applications and services operated in association with the remote or cloud-based authentication endpoint without a second or separate log-in or sign-on and without use of additional authentication equipment at the user's enterprise network.