Credential Mapping Service for Unified Server Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing environments, users face the burden of managing different authentication information for various service applications that use either globally or locally trusted credentials, leading to security compromises and operational inefficiencies, as reconfiguring these applications to use a unified authentication method can be costly and technically challenging.

Innovation Solution

The system allows client computing resources to access server applications using either globally or locally trusted credentials without requiring substantial reconfiguration, by importing data from diverse service applications into a server that leverages both types of credentials for authentication, enabling a single authentication experience for users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service applications use locally trusted credentials for authentication, then each application can maintain independent security control, but users must manage multiple authentication information sets across different applications

Engineering Contradiction:
Improvesecurity controlVSAvoidauthentication management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a credential mapping service that acts as an intermediary between clients and service applications. This service maintains credential mappings that translate locally trusted credentials used by individual applications into globally trusted credentials, allowing users to authenticate once with global credentials while applications continue to use their preferred local credential verification method

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal authentication mechanism where a single set of globally trusted credentials can be used across multiple service applications. The credential mapping service provides multi-functionality by supporting both local and global credential verification, enabling users to access different applications with unified authentication while applications retain their individual security policies

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If service applications are reconfigured to use globally trusted credentials, then users can use a single authentication method, but reconfiguration is costly and technically challenging

Engineering Contradiction:
Improveauthentication methodVSAvoidreconfiguration cost
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

Rather than reconfiguring applications to use global credentials directly, the patent introduces a credential mapping service as an intermediary layer. This service handles the translation and verification of credentials, allowing applications to continue using their existing local credential verification without modification, thereby avoiding costly reconfiguration while still enabling unified global authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by pre-establishing credential mappings between local and global credentials in a centralized service. This preparation work is done separately from the application layer, allowing applications to maintain their original configuration while the mapping service handles the complexity of credential translation, thus avoiding the need for difficult application reconfiguration

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple credential types are maintained across the network, then different applications can use their preferred authentication method, but network overhead and security risk increase

Engineering Contradiction:
Improveauthentication methodVSAvoidnetwork overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent merges the management of multiple credential types into a single centralized credential mapping service. Instead of each application independently managing its own credential verification, the system combines these functions into one service that handles all credential translations, reducing redundant credential data across the network and minimizing network overhead while maintaining support for multiple authentication methods

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7519596B2Globally trusted credentials leveraged for server access control
Publication Date: 2009.04.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7519596B2 patent drawing
  • US7519596B2 patent drawing
  • US7519596B2 patent drawing

AI summary

Systems, methods, computer-readable media and application program interfaces are disclosed for enabling server applications to verify purported authentication information, such as passwords, provided by clients in connection with server access requests by leveraging trusted credentials maintained by separate trusted authorities. In some cases, the server applications may lack trusted credentials that may be used to verify the purported authentication information. In those cases, the server applications may identify security principal accounts managed by the separate trusted authorities for which the provided authentication information may be purported to be valid for by the requesting clients. Further, the server applications may request the separate trusted authorities to authenticate the purported authentication information before granting access to the requesting clients. In other cases, the server applications may maintain locally trusted credentials that may be used to verify the provided authentication information without involving the separate trusted authorities.