Cookie Setting Service for Cross-Domain SSO
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SAML-based authentication systems face difficulties in seamlessly integrating multiple authentication servers across different management domains, making it challenging to achieve Single Sign-On across diverse Web systems due to complexities in DNS settings and cookie management.
Innovation Solution
A method involving a cookie setting service that operates on user terminals to manage cookies for multiple authentication servers within the same group, ensuring proper notification ranges and reliance lists to facilitate authentication across different domains, even when cookies are lost or authentication servers are not directly connected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple authentication servers are integrated into a common domain using DNS, then Single Sign-On can be achieved across authentication servers, but it becomes practically difficult to let authentication servers from different management sources participate in the common domain
Solution Approach 1:
The patent segments the authentication system into multiple independent groups, each with its own domain. Cookie setting services are deployed in each group and can independently manage cookies for authentication servers within that group. This segmentation eliminates the need for complex cross-domain DNS configurations while enabling SSO within each group.
Solution Approach 2:
The cookie setting service acts as an intermediary that bridges the user terminal and authentication servers. Instead of requiring direct DNS-based domain integration, the cookie setting service mediates authentication by setting and managing cookies that enable SSO across different domains without complex DNS configurations.
2Adaptability or versatility
If a cookie setting service sets cookies with broad notification ranges to enable cross-server authentication, then authentication flexibility improves, but cookie security and precision in controlling notification ranges deteriorates
Solution Approach 1:
The patent applies local quality by allowing each cookie setting service to set cookies with notification ranges precisely tailored to its specific domain and authentication servers. Instead of using a single broad notification range for all servers, each service configures cookies with the exact scope needed for its local context, improving both security and precision.
Data Source
AI summary
A plurality of authentication servers belonging to different domains are connected to achieve a Single Sign-On using two cookies in two management systems.


