Enterprise Authentication Gateway for Third-Party Protocol Support

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions do not adequately allow third-party application developers to implement their own authentication protocols for enterprise-managed applications on mobile devices like iOS and Android, while preserving enterprise authentication protocols and enabling innovation in authentication technology.

Innovation Solution

A method and system for authenticating client devices in enterprise systems through a gateway device, allowing third-party authentication support to enable third-party application developers to implement their own authentication protocols while maintaining enterprise security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party application developers implement their own authentication protocols for enterprise-managed applications, then authentication innovation and developer flexibility are improved, but enterprise security control and protocol consistency deteriorate

Engineering Contradiction:
Improveauthentication protocol flexibilityVSAvoidenterprise security control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a gateway device as an intermediary between third-party authentication servers and enterprise resources. This gateway translates and mediates authentication protocols, allowing third-party developers to use their own authentication methods while the gateway ensures enterprise security requirements are met. The gateway acts as a buffer that enables protocol diversity without compromising enterprise security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If enterprise systems allow multiple authentication protocols, then developer innovation and application compatibility are improved, but system complexity and authentication management deteriorate

Engineering Contradiction:
Improveauthentication protocol supportVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct components: third-party authentication servers, gateway devices, and enterprise resources. Each component maintains its own authentication protocol independently. The gateway device handles protocol translation and coordination, allowing multiple protocols to coexist without increasing overall system complexity. This segmentation enables protocol diversity while keeping management straightforward.

Inventive Principle:
Principle #1Segmentation

3Productivity

If third-party authentication technologies are integrated into enterprise systems, then authentication capability and developer freedom are improved, but security risk and protocol compatibility issues deteriorate

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The gateway device serves as a security intermediary that validates and controls all authentication interactions between third-party servers and enterprise resources. It implements security policies, validates authentication results, and ensures protocol compatibility. This intermediary approach enables third-party authentication capabilities while mitigating security risks through centralized control and validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3162103B1Enterprise authentication via third party authentication support
Publication Date: 2019.10.02 CITRIX SYSTEMS INC
  • EP3162103B1 patent drawingFigure 1
  • EP3162103B1 patent drawingFigure 2
  • EP3162103B1 patent drawingFigure 3

AI summary

Methods and systems are disclosed for providing approaches to enterprise authentication via third party authentication support. The methods and systems may include transmitting, by a computing device to an authentication device, a request to authenticate a client device application via a forms login protocol, and transmitting, by the computing device to the client device application, a first credential form retrieved from an authentication device generated by an extension device. The methods and systems may also include receiving, by the computing device from the client device application, a first authentication credential, and transmitting, by the computing device to the authentication service via the extension device, the first authentication credential. The methods and systems may also include transmitting, by the computing device and in response to a successful validation of the first authentication credential, an approval of the request made by the client device application to authenticate via the forms login protocol.