Cloud SSO Directory Service Simplification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Single Sign-On (SSO) technologies face challenges in configuration and deployment, particularly when extending SSO to cloud services, requiring complex setup of directory services, federation services, and synchronization services, and often lack reliability, especially when there is no on-premises directory service.
Innovation Solution
The solution implements cloud-based SSO by validating user credentials and establishing domain control, standing up domain controllers and federation services, and replicating data between on-premises and cloud services, even without an on-premises directory, using VPN connections to synchronize data and extend private cloud infrastructure to on-premises networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SSO is implemented using traditional on-premises directory services, then SSO functionality is achieved, but the system complexity and deployment difficulty increase significantly
Solution Approach 1:
The patent introduces a cloud-based federation service as an intermediary between on-premises applications and cloud services. This federation service handles the complex SSO coordination, authentication token management, and protocol translation, allowing organizations to achieve SSO without directly implementing complex directory services or federation infrastructure on-premises.
Solution Approach 2:
The patent creates a virtual copy of directory service functionality through cloud-based federation services and identity providers. Instead of requiring physical on-premises directory services, the system replicates their authentication and authorization functions through cloud-based virtualized services that can be accessed remotely.
2Ease of operation
If SSO is extended to cloud services without on-premises directory, then cloud accessibility is improved, but system reliability deteriorates
Solution Approach 1:
The patent implements backup authentication mechanisms and fallback procedures that are pre-configured in the federation service. If the primary cloud-based authentication path fails, the system automatically falls back to alternative verification methods, ensuring continuous reliability even without on-premises directory services as a backup.
Solution Approach 2:
The patent dynamically adjusts authentication parameters and security protocols based on the operational context. When cloud services are accessible, it uses cloud-based federation; when accessibility is compromised, it switches to different authentication modes, maintaining reliability through parameter adaptation rather than fixed infrastructure.
3Device complexity
If cloud-based SSO is implemented without on-premises directory, then infrastructure simplicity is improved, but functionality is reduced
Solution Approach 1:
The patent designs the cloud-based federation service to perform multiple functions that traditionally required separate on-premises components. The federation service handles authentication, authorization, token management, protocol translation, and service federation simultaneously, providing universal functionality that replaces multiple specialized on-premises services with a single cloud-based platform.
4Reliability
If on-premises directory service is maintained for SSO, then SSO reliability is improved, but infrastructure complexity increases
Solution Approach 1:
The patent extracts the complex directory service functionality from the on-premises environment and relocates it to cloud-based services. By taking out the heavy lifting of directory maintenance, replication, and management from on-premises infrastructure and placing it in the cloud, the system maintains SSO reliability through robust cloud services while reducing on-premises infrastructure complexity.
Data Source
AI summary
Embodiments of the invention are disclosed for establishing single identity/single-sign on (SSO) on a cloud computing platform. In an embodiment, a user is validated to the cloud computing platform, and identifies a domain. After establishing that the user has control of the domain, the cloud computing platform configures a directory service for the domain. The user may then use the directory service on the cloud computing platform to log in to his or her computer, as well as software services hosted on the cloud computing platform.


