Cryptographic Proofs for Cloud SSO via On-Premises AD
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in migrating to cloud-based applications like Office 365 while maintaining security, regulatory compliance, and optimizing costs, especially when they have established on-premises Active Directories.
Innovation Solution
Utilizing user authentication to on-premises active directories through a zero trust tunnel to establish Single Sign-On (SSO) for cloud-based applications, enabling secure communication and efficient network traffic management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If organizations migrate to cloud-based applications like Office 365, then access to modern cloud services is improved, but security and compliance with on-premises Active Directory authentication is compromised
Solution Approach 1:
The patent introduces a cloud-based Identity Provider (IdP) as an intermediary between on-premises Active Directory and cloud applications. The IdP receives authentication requests from cloud apps, forwards them to on-premises AD via secure tunnel, and relays the authentication result back, enabling cloud service access while maintaining on-premises security validation
Solution Approach 2:
The authentication system is segmented into separate components: on-premises Active Directory (security authority), cloud-based Identity Provider (mediation layer), and cloud applications (service consumers). This segmentation allows each component to perform its specialized function while maintaining security boundaries
2Reliability
If secure tunneling is implemented for authentication, then security is improved, but network complexity increases
Solution Approach 1:
The authentication system performs self-service by automatically establishing secure tunnels and managing authentication workflows without requiring manual network configuration. The cloud-based IdP handles tunnel establishment, authentication request routing, and credential verification automatically
3Adaptability or versatility
If multiple authentication protocols are supported, then compatibility with different applications is improved, but system complexity increases
Solution Approach 1:
The cloud-based Identity Provider is designed with multi-functionality to support multiple authentication protocols (Kerberos, LDAP, SAML, OAuth) through a single unified system. This universal approach allows the same IdP infrastructure to serve diverse cloud applications without requiring separate authentication systems for each protocol
Data Source
AI summary
A secure connection is established between an IAM server on a data communication network and an on-premises active directory using a zero trust tunnel based on TCP forwarding. An authentication request is received from a gateway device, for the user to access a service provider hosting applications, responsive to a user request for access to the service provider hosting applications. Responsive to recognizing the user of the authentication request being associated with the established SSO session, an assertion is returned to the gateway that the user is authenticated to access the service provider. An authentication request is received from the service provider, for access to a specific application. Responsive to the group information associated with the user, an assertion is returned to the service provider that user is authenticated for use of the specific application.


