Cryptographic Proofs for Cloud SSO via On-Premises AD

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in migrating to cloud-based applications like Office 365 while maintaining security, regulatory compliance, and optimizing costs, especially when they have established on-premises Active Directories.

Innovation Solution

Utilizing user authentication to on-premises active directories through a zero trust tunnel to establish Single Sign-On (SSO) for cloud-based applications, enabling secure communication and efficient network traffic management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If organizations migrate to cloud-based applications like Office 365, then access to modern cloud services is improved, but security and compliance with on-premises Active Directory authentication is compromised

Engineering Contradiction:
Improveaccess to cloud servicesVSAvoidsecurity authentication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a cloud-based Identity Provider (IdP) as an intermediary between on-premises Active Directory and cloud applications. The IdP receives authentication requests from cloud apps, forwards them to on-premises AD via secure tunnel, and relays the authentication result back, enabling cloud service access while maintaining on-premises security validation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into separate components: on-premises Active Directory (security authority), cloud-based Identity Provider (mediation layer), and cloud applications (service consumers). This segmentation allows each component to perform its specialized function while maintaining security boundaries

Inventive Principle:
Principle #1Segmentation

2Reliability

If secure tunneling is implemented for authentication, then security is improved, but network complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system performs self-service by automatically establishing secure tunnels and managing authentication workflows without requiring manual network configuration. The cloud-based IdP handles tunnel establishment, authentication request routing, and credential verification automatically

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple authentication protocols are supported, then compatibility with different applications is improved, but system complexity increases

Engineering Contradiction:
Improveapplication compatibilityVSAvoidauthentication system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cloud-based Identity Provider is designed with multi-functionality to support multiple authentication protocols (Kerberos, LDAP, SAML, OAuth) through a single unified system. This universal approach allows the same IdP infrastructure to serve diverse cloud applications without requiring separate authentication systems for each protocol

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12445428B2Cryptographic proofs for seamless single sign-on (SSO) to cloud services based on on-premises authentication
Publication Date: 2025.10.14 FORTINET INC
  • US12445428B2 patent drawing
  • US12445428B2 patent drawing
  • US12445428B2 patent drawing

AI summary

A secure connection is established between an IAM server on a data communication network and an on-premises active directory using a zero trust tunnel based on TCP forwarding. An authentication request is received from a gateway device, for the user to access a service provider hosting applications, responsive to a user request for access to the service provider hosting applications. Responsive to recognizing the user of the authentication request being associated with the established SSO session, an assertion is returned to the gateway that the user is authenticated to access the service provider. An authentication request is received from the service provider, for access to a specific application. Responsive to the group information associated with the user, an assertion is returned to the service provider that user is authenticated for use of the specific application.