Cross-Domain SSO Policy Automation via Attribute Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Single Sign-On (SSO) systems across different domains face challenges in sharing authentication results due to limitations in HTTP Cookie usage and vendor-specific access management methods, leading to time-consuming and labor-intensive account registration and federation processes, which hinder the quick adoption of cloud services like SaaS.

Innovation Solution

A policy update system that automates the process of account federation and registration by evaluating user attribute changes and updating policies dynamically, allowing for non-manual determination of service permissions, thereby streamlining the SSO process across domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If HTTP Cookie is used for authentication result sharing, then single-domain SSO is achieved, but cross-domain authentication sharing is limited

Engineering Contradiction:
Improvecross-domain authentication sharingVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication information management server as an intermediary component that mediates between multiple service providers and users. This server stores authentication results centrally and provides them to authorized service providers across different domains, enabling cross-domain SSO without requiring direct trust relationships between all service providers. The intermediary resolves the contradiction by allowing broad authentication sharing while maintaining controlled system complexity through centralized management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication information management server provides universal authentication services to multiple service providers across different domains. Instead of implementing separate authentication mechanisms for each domain or service provider, the system uses a single universal authentication result that can be shared across multiple domains. This multi-functional approach enables cross-domain authentication sharing while avoiding the complexity of implementing multiple separate authentication systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If manual account federation and registration processes are used, then service permissions can be determined, but time-consuming and labor-intensive operations occur

Engineering Contradiction:
Improveaccount federation speedVSAvoidaccount registration time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing trust relationships and authentication mechanisms between service providers and the authentication information management server before actual user authentication occurs. User attribute information is collected and stored in advance, and authentication results are maintained ready for quick retrieval. This preliminary preparation eliminates the need for time-consuming manual account federation and registration processes when users actually access services, significantly reducing account registration time while maintaining high productivity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If advance account federation and registration are required before SSO, then service permissions can be established, but quick adoption of cloud services is hindered

Engineering Contradiction:
Improvecloud service adoption speedVSAvoidpreparation process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system enables self-service by allowing users to authenticate themselves once with the authentication information management server, which then automatically provides authentication results to multiple service providers without requiring manual account federation or registration at each service provider. The authentication information management server automatically manages the complexity of trust relationships and authentication configurations, enabling quick adoption of cloud services while maintaining necessary security and permission controls through automated processes rather than manual preparation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9600655B2Policy update system and policy update apparatus
Publication Date: 2017.03.21 KK TOSHIBA
  • US9600655B2 patent drawing
  • US9600655B2 patent drawing
  • US9600655B2 patent drawing

AI summary

According to one embodiment, a policy update system includes a server apparatus configured to be able to provide a plurality of services to a user, the server apparatus including storage device for storing a first user ID; a policy storage device configured to store a plurality of policies, each policy being composed of condition describing user attribute information in which a plurality of items including a second user ID corresponding to the first user ID are associated, and each policy specifying a use privilege of each service; a policy update apparatus configured to be able to update each stored policy; and a user attribute information storage device configured to store post-change user attribute information, and a change content for each second user ID.