Credential Mapping Service for Unified Server Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computing environments, users face the burden of managing different authentication information for various service applications that use either globally or locally trusted credentials, leading to security compromises and operational inefficiencies, as reconfiguring these applications to use a unified authentication method can be costly and technically challenging.
Innovation Solution
The system allows client computing resources to access server applications using either globally or locally trusted credentials without requiring substantial reconfiguration, by importing data from diverse service applications into a server that leverages both types of credentials for authentication, enabling a single authentication experience for users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service applications use locally trusted credentials for authentication, then each application can maintain independent security control, but users must manage multiple authentication information sets across different applications
Solution Approach 1:
The patent introduces a credential mapping service that acts as an intermediary between clients and service applications. This service maintains credential mappings that translate locally trusted credentials used by individual applications into globally trusted credentials, allowing users to authenticate once with global credentials while applications continue to use their preferred local credential verification method
Solution Approach 2:
The system implements a universal authentication mechanism where a single set of globally trusted credentials can be used across multiple service applications. The credential mapping service provides multi-functionality by supporting both local and global credential verification, enabling users to access different applications with unified authentication while applications retain their individual security policies
2Ease of operation
If service applications are reconfigured to use globally trusted credentials, then users can use a single authentication method, but reconfiguration is costly and technically challenging
Solution Approach 1:
Rather than reconfiguring applications to use global credentials directly, the patent introduces a credential mapping service as an intermediary layer. This service handles the translation and verification of credentials, allowing applications to continue using their existing local credential verification without modification, thereby avoiding costly reconfiguration while still enabling unified global authentication
Solution Approach 2:
The system performs preliminary action by pre-establishing credential mappings between local and global credentials in a centralized service. This preparation work is done separately from the application layer, allowing applications to maintain their original configuration while the mapping service handles the complexity of credential translation, thus avoiding the need for difficult application reconfiguration
3Adaptability or versatility
If multiple credential types are maintained across the network, then different applications can use their preferred authentication method, but network overhead and security risk increase
Solution Approach 1:
The patent merges the management of multiple credential types into a single centralized credential mapping service. Instead of each application independently managing its own credential verification, the system combines these functions into one service that handles all credential translations, reducing redundant credential data across the network and minimizing network overhead while maintaining support for multiple authentication methods
Data Source
AI summary
Systems, methods, computer-readable media and application program interfaces are disclosed for enabling server applications to verify purported authentication information, such as passwords, provided by clients in connection with server access requests by leveraging trusted credentials maintained by separate trusted authorities. In some cases, the server applications may lack trusted credentials that may be used to verify the purported authentication information. In those cases, the server applications may identify security principal accounts managed by the separate trusted authorities for which the provided authentication information may be purported to be valid for by the requesting clients. Further, the server applications may request the separate trusted authorities to authenticate the purported authentication information before granting access to the requesting clients. In other cases, the server applications may maintain locally trusted credentials that may be used to verify the provided authentication information without involving the separate trusted authorities.


