Domain Authentication System for Tenant Resource Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content management systems face challenges in handling multiple tenants with different domain types, requiring separate authentication configurations and instances, which complicates resource sharing and management.

Innovation Solution

A system that detects the domain from a tenant's request, identifies a site ID from a database, and routes traffic to either a default or custom site for authentication, allowing for single-instance management of both dedicated and shared domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication configurations and instances are used for each tenant with different domain types, then authentication reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication configurations into a single authentication instance by introducing a domain type detection mechanism that routes different domain types to appropriate authentication methods within the same system, eliminating the need for separate instances while maintaining authentication reliability

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed to be universal by implementing a domain type detection capability that allows a single authentication configuration to handle multiple domain types (dedicated and shared domains) through different authentication methods, making the system multi-functional without requiring separate configurations

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple instances are used to manage different domain types, then authentication adaptability is improved, but productivity decreases

Engineering Contradiction:
Improvedomain type adaptabilityVSAvoidresource management efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system implements dynamic adaptability by detecting the domain type at runtime and automatically selecting the appropriate authentication method (dedicated domain authentication or shared domain authentication), allowing the system to adapt to different domain types without requiring multiple static instances, thereby improving resource management efficiency

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If separate instances are deployed for different domain types, then authentication precision is improved, but loss of time increases

Engineering Contradiction:
Improvedomain authentication precisionVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary domain type detection and classification before initiating the authentication process, allowing it to quickly route the authentication request to the appropriate method without requiring multiple authentication instances, thereby maintaining authentication precision while reducing authentication time

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10951600B2Domain authentication
Publication Date: 2021.03.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10951600B2 patent drawing
  • US10951600B2 patent drawing
  • US10951600B2 patent drawing

AI summary

Various systems and methods for domain authentication are described herein. In an example, the method may include detecting a domain from a request of a tenant for access to a farm. The method may also include identifying a presence of a site ID from a database of the farm based on the domain. The method may also include sending an authentication request to a default site or a custom site, the authentication request managed through a site manager based on the identified presence of the site ID in the database of the farm. The method may also include routing traffic from the tenant to the farm in response to satisfaction of the authentication request.