Federated Authentication Server for Single Sign-On
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users accessing multiple services in federated computing systems often face the inconvenience of managing multiple authentication credentials and methods, as current systems require repeated authentication with different methods for each server, leading to user frustration and security vulnerabilities.
Innovation Solution
A method and system that allow users to authenticate once with a chosen authentication method within a federated computing system, enabling seamless access to multiple servers by maintaining user records that associate authentication methods with server identifiers, allowing the authentication server to determine and apply the appropriate authentication method based on user selections and device capabilities, thereby eliminating the need for repeated authentications across different servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication methods are used for each server, then security is improved, but user convenience deteriorates
Solution Approach 1:
The patent implements a universal authentication system where a single authentication method (such as fingerprint or facial recognition) performed once can be used across multiple servers within a federated system. The authentication result is stored and shared across the federation, allowing the same authentication to serve multiple purposes and access multiple services without repetition.
Solution Approach 2:
The system performs authentication in advance and stores the result in a federated authentication database. When a user attempts to access multiple servers, the pre-performed authentication result is retrieved and validated, eliminating the need to repeat the authentication process for each server access.
2Reliability
If multiple credentials are managed for different services, then access control is improved, but complexity of management deteriorates
Solution Approach 1:
The patent merges multiple authentication credentials and methods into a single federated authentication system. Instead of managing separate credentials for each server, the system combines them under a unified authentication framework where one set of credentials can authenticate across multiple servers through the federation.
Solution Approach 2:
The federated authentication server acts as an intermediary between users and multiple service servers. It manages the authentication credentials centrally and facilitates authentication requests across the federation, eliminating the need for users to directly manage multiple credentials with different servers.
3Ease of operation
If federated authentication is implemented, then user convenience is improved, but system complexity deteriorates
Solution Approach 1:
The patent introduces a federated authentication server as an intermediary that manages the complexity of coordinating multiple servers and authentication methods. This central mediator handles the logic of authentication verification across the federation, simplifying the user experience while containing the system complexity in a dedicated component.
Solution Approach 2:
The authentication system is segmented into distinct functional components: local authentication servers that handle specific authentication methods, and a federated authentication server that coordinates across multiple servers. This segmentation allows each component to focus on specific tasks, making the overall system more manageable despite its distributed nature.
Data Source
Figure 1
Figure 2
AI summary
A system and method for user authentication within federated computing systems are provided. In a session, a user can be authenticated multiple times by different authentication methods for different servers (130, 140, 150) of a federated system, however, once the user has been authenticated by any given authentication method, the user need not repeat that method. A system of the present invention comprises a plurality of servers (130, 140, 150) including an authentication server (130). The authentication server maintains authentication records for users, where each record includes which authentication methods apply to which servers. When a user first seeks access to a particular server (140), the server (140) identifies the user and the server (140) to the authentication server (130). If the user has already been authenticated elsewhere according to the authentication method required by the new server (140), the authentication server (130) indicates to the new server (140) that the user is authenticated, else the authentication server invokes the necessary authentication method.