Credential Management Server for Multi-Domain Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access management systems, including Single Sign-on (SSO) services, fail to efficiently manage multiple-domain access credentials for users, as they either restrict access to a single domain or require separate interfaces for each domain, lacking a unified user interface for centralized authentication across multiple domains.

Innovation Solution

A system comprising a credential management server that stores and manages separate access credentials for each domain, allowing users to perform single centralized authentication while maintaining independent access to each domain, using a service device with a web interface to interface with the credential management server and network server, ensuring each domain's security and access levels are maintained independently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized SSO service is implemented, then access to multiple applications within a single domain is simplified, but access to multiple domains remains unmanaged

Engineering Contradiction:
Improveauthentication processVSAvoidmulti-domain access capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The credential management server is designed to handle authentication across multiple domains, not just a single domain. It stores and manages credentials for multiple domains and can authenticate users to any of these domains through a unified interface, making the system versatile for multi-domain access scenarios

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a federated SSO service is implemented, then access to multiple domains is enabled, but no single user interface is provided for centralized authentication

Engineering Contradiction:
Improvemulti-domain access capabilityVSAvoiduser interface unity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent combines multiple domain-specific authentication interfaces into a single unified user interface provided by the credential management server. This unified interface presents a consistent experience to users while handling credentials for multiple domains, merging what would otherwise be separate authentication processes

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate interfaces are used for each domain, then domain-specific security protocols are maintained, but authentication becomes complex and time-consuming

Engineering Contradiction:
Improvedomain security protocolVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The credential management server pre-stores credentials for multiple domains and prepares authentication data in advance. When a user requests access, the server can quickly retrieve and provide the appropriate credentials without requiring the user to go through separate authentication processes for each domain, reducing authentication time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11799870B2System and method for the management of multi-domain access credentials of a user able to access a plurality of domains
Publication Date: 2023.10.24 MONOKEE SRL
  • US11799870B2 patent drawing
  • US11799870B2 patent drawing

AI summary

A system for managing multiple-domain access credentials of a user enabled to access a plurality of domains. The system includes a credential management server wherein access credentials of the user are separately present for each of the domains, each of the access credentials including the access level of the user for each of the domains, a service device for interfacing the credential management server and at least a network server in turn including applications and resources related to at least a domain. The service device is configured to send to the credential management server an access request to a specific domain, and the credential management server is configured to send to the service device the access credentials of the user for all the domains; consequently the service device is configured to send to the network server an access request to the specific domain, and the network server is configured to allow the user access such applications and resources of the specific domain based on the access level of the user.