Cloud SSO Directory Service Simplification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Single Sign-On (SSO) technologies face challenges in configuration and deployment, particularly when extending SSO to cloud services, requiring complex setup of directory services, federation services, and synchronization services, and often lack reliability, especially when there is no on-premises directory service.

Innovation Solution

The solution implements cloud-based SSO by validating user credentials and establishing domain control, standing up domain controllers and federation services, and replicating data between on-premises and cloud services, even without an on-premises directory, using VPN connections to synchronize data and extend private cloud infrastructure to on-premises networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSO is implemented using traditional on-premises directory services, then SSO functionality is achieved, but the system complexity and deployment difficulty increase significantly

Engineering Contradiction:
ImproveSSO functionalityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cloud-based federation service as an intermediary between on-premises applications and cloud services. This federation service handles the complex SSO coordination, authentication token management, and protocol translation, allowing organizations to achieve SSO without directly implementing complex directory services or federation infrastructure on-premises.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a virtual copy of directory service functionality through cloud-based federation services and identity providers. Instead of requiring physical on-premises directory services, the system replicates their authentication and authorization functions through cloud-based virtualized services that can be accessed remotely.

Inventive Principle:
Principle #26Copying

2Ease of operation

If SSO is extended to cloud services without on-premises directory, then cloud accessibility is improved, but system reliability deteriorates

Engineering Contradiction:
Improvecloud accessibilityVSAvoidsystem reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements backup authentication mechanisms and fallback procedures that are pre-configured in the federation service. If the primary cloud-based authentication path fails, the system automatically falls back to alternative verification methods, ensuring continuous reliability even without on-premises directory services as a backup.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent dynamically adjusts authentication parameters and security protocols based on the operational context. When cloud services are accessible, it uses cloud-based federation; when accessibility is compromised, it switches to different authentication modes, maintaining reliability through parameter adaptation rather than fixed infrastructure.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If cloud-based SSO is implemented without on-premises directory, then infrastructure simplicity is improved, but functionality is reduced

Engineering Contradiction:
Improveinfrastructure simplicityVSAvoidSSO functionality
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent designs the cloud-based federation service to perform multiple functions that traditionally required separate on-premises components. The federation service handles authentication, authorization, token management, protocol translation, and service federation simultaneously, providing universal functionality that replaces multiple specialized on-premises services with a single cloud-based platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If on-premises directory service is maintained for SSO, then SSO reliability is improved, but infrastructure complexity increases

Engineering Contradiction:
ImproveSSO reliabilityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex directory service functionality from the on-premises environment and relocates it to cloud-based services. By taking out the heavy lifting of directory maintenance, replication, and management from on-premises infrastructure and placing it in the cloud, the system maintains SSO reliability through robust cloud services while reducing on-premises infrastructure complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10176335B2Identity services for organizations transparently hosted in the cloud
Publication Date: 2019.01.08 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10176335B2 patent drawing
  • US10176335B2 patent drawing
  • US10176335B2 patent drawing

AI summary

Embodiments of the invention are disclosed for establishing single identity/single-sign on (SSO) on a cloud computing platform. In an embodiment, a user is validated to the cloud computing platform, and identifies a domain. After establishing that the user has control of the domain, the cloud computing platform configures a directory service for the domain. The user may then use the directory service on the cloud computing platform to log in to his or her computer, as well as software services hosted on the cloud computing platform.