Cross-Cloud Identity Trust for Secure Single Sign-On Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in securely accessing resources across clouds with different security levels, requiring multiple user identities and lacking seamless trust relationships, leading to operational burdens and security risks.

Innovation Solution

A system that enables secure cross-cloud resource access by authenticating and authorizing administrators using tokens with user identities, establishing a two-way trust relationship between public and private clouds, and maintaining a mapping of tenants to allow end users to access private cloud services with a single user identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple user identities are used to access different clouds, then security requirements for each cloud are met, but operational burden increases and user convenience deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a federated identity management system as an intermediary that mediates between users and multiple cloud environments. This system uses standardized protocols (SAML, OAuth 2.0, OpenID Connect) to enable single sign-on across clouds, allowing users to authenticate once and gain access to multiple cloud resources without needing separate credentials for each cloud provider.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal identity provider that serves multiple functions: authentication, authorization, and session management across different cloud environments. This single identity system replaces the need for multiple separate identity management systems, providing a unified approach to accessing diverse cloud resources while maintaining security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication systems are used for each cloud, then cloud-specific security requirements are satisfied, but trust relationships between clouds are lacking and system complexity increases

Engineering Contradiction:
Improvecloud-specific securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies homogeneity by standardizing authentication and authorization mechanisms across different cloud providers. It uses uniform protocols (SAML, OAuth 2.0, OpenID Connect) and a consistent federated identity model to create homogeneous trust relationships, eliminating the need for custom integration logic for each cloud and reducing overall system complexity.

Inventive Principle:
Principle #33Homogeneity

Solution Approach 2:

The patent segments the identity management functionality into distinct components: an identity provider (IdP) that handles authentication, service providers (SPs) that handle authorization, and standardized protocols that bridge them. This segmentation allows each component to be independently configured and maintained while working together through well-defined interfaces, reducing system complexity.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If traditional multi-cloud access methods are used, then access to multiple clouds is achieved, but operational efficiency decreases and time consumption increases

Engineering Contradiction:
Improvemulti-cloud access capabilityVSAvoidoperational efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-establishing trust relationships and authentication frameworks between clouds through federated identity protocols. Users are authenticated once in advance, and their credentials are validated across multiple clouds before access is needed, eliminating repeated authentication steps and improving operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables continuous access across clouds through persistent session management and token-based authentication. Once a user is authenticated, their session state and authorization tokens are maintained and recognized across different cloud environments, allowing seamless continuous operation without interruption or re-authentication.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20260067283A1Secure cross-cloud resource access with single user identity
Publication Date: 2026.03.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20260067283A1 patent drawing
  • US20260067283A1 patent drawing
  • US20260067283A1 patent drawing

AI summary

Systems and methods are provided for a secure cross-cloud resource access based on user identity. In particular, the system includes a plurality of clouds where a first cloud enforces more restrictive access than a second cloud. In particular, an end user of the second cloud also uses user identity stored in the less restrictive first cloud. The system includes authenticating and authorizing tokens associated with an administrator of the first tenant in the first cloud and the second tenant in the second cloud. The onboarding establishes a two-way trust between the two tenants across the first and second clouds. Once established, operating an application service and accessing data resources in the second cloud is accomplished by logging into the first cloud and leverage the two-way trust to remotely launch application services in the second cloud using a tenant graph and a location service in the first cloud.