Cloud Identity Intermediary for External Website Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in extending identity provider services to external websites and applications that do not support standard identity management systems like SAML, as rewriting these systems to adopt such protocols is time-consuming and expensive.

Innovation Solution

Implementing a system that allows users to authenticate with external websites from a cloud-based computing environment using identity services like Salesforce identity, which provides single sign-on (SSO) and social sign-on capabilities, without requiring web developers to handle authentication services directly, by using HTML meta tags and JavaScript functions to integrate with the cloud-based identity provider.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations implement standard identity management systems like SAML for external websites, then authentication security and centralized identity management are improved, but implementation time and cost increase significantly due to required system rewriting

Engineering Contradiction:
Improveauthentication securityVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary component that bridges cloud-based identity services and external websites without requiring the websites to be rewritten. This intermediary handles the authentication protocol translation and communication, allowing standard SAML-based identity management to be applied to non-compliant external sites through a mediating layer rather than direct integration

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If organizations implement standard identity management systems like SAML for external websites, then authentication security and centralized identity management are improved, but implementation cost increases due to system rewriting requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The intermediary component serves as a cost-effective solution by eliminating the need for expensive system rewriting. It provides a standardized interface that connects cloud identity services to external websites through existing protocols, reducing implementation costs while maintaining security standards

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If cloud-based identity services are integrated with external websites, then user authentication convenience is improved, but system complexity increases due to integration requirements

Engineering Contradiction:
Improveuser authentication convenienceVSAvoidsystem integration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complex authentication logic from the external website integration process and consolidates it into a separate cloud-based identity service component. This extraction allows the external websites to maintain simple implementation while the complex authentication handling is performed by the dedicated identity service, reducing overall system integration complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11128624B2Systems, methods, and apparatuses for logging in to an external website from a cloud based computing environment
Publication Date: 2021.09.21 SALESFORCE INC
  • US11128624B2 patent drawing
  • US11128624B2 patent drawing
  • US11128624B2 patent drawing

AI summary

Systems, methods, and apparatuses for implementing authentication of a user login to an external website from a community in a cloud based computing environment. An exemplary system having at least a processor and a memory therein includes means for identifying a first domain where a user is to be allowed to login to an external web page hosted thereon, and means for connecting the external web page with a community of a cloud computing environment hosted on a second domain different than the identified first domain, the connecting means handling how the connected community authenticates the user when the user logs into the external web page and providing one of a plurality of login experiences for the user based on conditions determined at run time.