Cross-Domain SSO Policy Automation via Attribute Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Single Sign-On (SSO) systems across different domains face challenges in sharing authentication results due to limitations in HTTP Cookie usage and vendor-specific access management methods, leading to time-consuming and labor-intensive account registration and federation processes, which hinder the quick adoption of cloud services like SaaS.
Innovation Solution
A policy update system that automates the process of account federation and registration by evaluating user attribute changes and updating policies dynamically, allowing for non-manual determination of service permissions, thereby streamlining the SSO process across domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If HTTP Cookie is used for authentication result sharing, then single-domain SSO is achieved, but cross-domain authentication sharing is limited
Solution Approach 1:
The patent introduces an authentication information management server as an intermediary component that mediates between multiple service providers and users. This server stores authentication results centrally and provides them to authorized service providers across different domains, enabling cross-domain SSO without requiring direct trust relationships between all service providers. The intermediary resolves the contradiction by allowing broad authentication sharing while maintaining controlled system complexity through centralized management.
Solution Approach 2:
The authentication information management server provides universal authentication services to multiple service providers across different domains. Instead of implementing separate authentication mechanisms for each domain or service provider, the system uses a single universal authentication result that can be shared across multiple domains. This multi-functional approach enables cross-domain authentication sharing while avoiding the complexity of implementing multiple separate authentication systems.
2Productivity
If manual account federation and registration processes are used, then service permissions can be determined, but time-consuming and labor-intensive operations occur
Solution Approach 1:
The system performs preliminary actions by pre-establishing trust relationships and authentication mechanisms between service providers and the authentication information management server before actual user authentication occurs. User attribute information is collected and stored in advance, and authentication results are maintained ready for quick retrieval. This preliminary preparation eliminates the need for time-consuming manual account federation and registration processes when users actually access services, significantly reducing account registration time while maintaining high productivity.
3Adaptability or versatility
If advance account federation and registration are required before SSO, then service permissions can be established, but quick adoption of cloud services is hindered
Solution Approach 1:
The system enables self-service by allowing users to authenticate themselves once with the authentication information management server, which then automatically provides authentication results to multiple service providers without requiring manual account federation or registration at each service provider. The authentication information management server automatically manages the complexity of trust relationships and authentication configurations, enabling quick adoption of cloud services while maintaining necessary security and permission controls through automated processes rather than manual preparation.
Data Source
AI summary
According to one embodiment, a policy update system includes a server apparatus configured to be able to provide a plurality of services to a user, the server apparatus including storage device for storing a first user ID; a policy storage device configured to store a plurality of policies, each policy being composed of condition describing user attribute information in which a plurality of items including a second user ID corresponding to the first user ID are associated, and each policy specifying a use privilege of each service; a policy update apparatus configured to be able to update each stored policy; and a user attribute information storage device configured to store post-change user attribute information, and a change content for each second user ID.


