Cloud SSO Manager Automating Metadata Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current single sign-on (SSO) configurations across multiple systems require manual, insecure, and time-consuming processes for metadata exchange, such as email communications, which are prone to errors and inefficiencies, especially when dealing with certificate expirations.

Innovation Solution

A cloud-based SSO configuration manager automates metadata access and sharing, enabling secure, real-time metadata exchange and monitoring across disparate systems, eliminating the need for manual point-to-point agreements and reducing errors by providing a centralized solution for configuring and monitoring SSO across various organizations and companies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual email communication is used to exchange metadata between system administrators, then security is compromised and errors increase, but automation and efficiency are reduced

Engineering Contradiction:
Improvemetadata exchange accuracyVSAvoidmetadata exchange automation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent introduces a centralized SSO configuration manager as an intermediary system that automatically exchanges metadata between disparate systems. This mediator eliminates the need for manual email communication by providing a structured, automated interface for metadata transfer, thereby improving reliability while maintaining the ability to exchange information between systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service automation where the SSO configuration manager automatically retrieves, validates, and exchanges metadata without requiring manual intervention from system administrators. The system performs self-configuration and self-monitoring, reducing human error while maintaining full automation capability.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If manual point-to-point agreements are used for SSO configuration, then system complexity increases, but automation and consistency are reduced

Engineering Contradiction:
ImproveSSO configuration flexibilityVSAvoidconfiguration management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal SSO configuration manager that can handle multiple disparate systems through a single centralized interface. This universal system performs multiple functions including metadata exchange, certificate management, and authorization coordination, thereby reducing the need for separate point-to-point configurations while maintaining adaptability to different systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments the complex SSO configuration task into manageable components: metadata extraction, validation, storage, and exchange. By dividing the configuration process into discrete, automated steps handled by the centralized manager, the system reduces overall complexity while maintaining the ability to configure multiple systems.

Inventive Principle:
Principle #1Segmentation

3Reliability

If centralized monitoring is implemented for certificate expirations, then system reliability improves, but implementation complexity increases

Engineering Contradiction:
Improvecertificate management reliabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the SSO configuration manager continuously monitors certificate expiration dates and automatically notifies relevant system administrators. The system provides real-time feedback on certificate status, enabling proactive renewal before expiration occurs, thereby improving reliability through automated monitoring and alerting.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8955080B2Managing single sign-ons between different entities
Publication Date: 2015.02.10 SAP SE
  • US8955080B2 patent drawing
  • US8955080B2 patent drawing
  • US8955080B2 patent drawing

AI summary

The disclosure generally describes computer-implemented methods, software, and systems for cloud-based single sign-on (SSO) capabilities. A computer-implemented method includes operations for identifying a first system for single sign-on capabilities, identifying a second system disparate from the first system for providing a single sign-on capability with the first system through a cloud-based SSO configuration manager, automatically accessing metadata associated with the sign-on information of the second system, the set of metadata identifying sign-on-related information for sharing at least one credential/certificate for logging in to the second system, using the metadata to obtain an authorization for a single sign-on between the first and second systems, receiving a request from the first system for authorization at the second system, and, in response to the request, providing the authorization and creating a cloud-based SSO system that includes the first and second systems.