Federated Provisioning via Trust Proxy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inefficiencies due to the need for multiple authentication processes when accessing resources across different domains, which hinders seamless access and increases user burden, despite advancements in secure authentication mechanisms and federated computing environments.

Innovation Solution

A method and system where federated domains interact within a federated environment, utilizing trust proxies and trust services to manage trust relationships, allowing for single-sign-on operations and provisioning users across domains, enabling seamless access by interpreting and translating authentication assertions and user account information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication processes are implemented across different domains, then security is improved, but user efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple authentication processes into a single unified authentication event through federated single-sign-on. When a user authenticates to one domain, that authentication is combined and recognized across all federated domains, eliminating the need for separate authentication processes at each domain while maintaining security standards.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication mechanism achieves universality by creating a single authentication credential that functions across multiple domains. The federated single-sign-on system allows one authentication event to serve multiple domains simultaneously, making the authentication process multi-functional rather than domain-specific.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If federated single-sign-on is implemented, then user efficiency is improved, but provisioning complexity increases

Engineering Contradiction:
Improveuser efficiencyVSAvoidprovisioning complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary provisioning system that manages user accounts across federated domains. This intermediary layer handles the complexity of creating, modifying, and synchronizing user accounts and entitlements across multiple domains, shielding users from the underlying complexity while enabling seamless single-sign-on functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary provisioning actions by automatically creating and configuring user accounts across federated domains before users need to access resources. When a user is provisioned at one domain, the system proactively sets up corresponding accounts and entitlements at other domains in advance, eliminating the need for manual provisioning at each domain.

Inventive Principle:
Principle #10Preliminary action

3Manufacturing precision

If manual user provisioning is performed at each domain, then access control precision is improved, but administrative burden increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidadministrative burden
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The patent implements self-service provisioning where the system automatically manages user account creation, modification, and synchronization across federated domains without requiring manual administrative intervention at each domain. The provisioning system autonomously handles account entitlements and access rights, maintaining precise access control while eliminating repetitive manual provisioning tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system employs feedback mechanisms to automatically detect and respond to provisioning needs across federated domains. When a user's account or entitlements are modified at one domain, the system receives feedback and automatically propagates these changes to other domains, ensuring access control precision is maintained without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8607322B2Method and system for federated provisioning
Publication Date: 2013.12.10 SERVICENOW INC
  • US8607322B2 patent drawing
  • US8607322B2 patent drawing
  • US8607322B2 patent drawing

AI summary

A method and a system are presented in which federated domains interact within a federated environment. Domains within a federation can initiate federated single-sign-on operations for a user at other federated domains. A point-of-contact server within a domain relies upon a trust proxy within the domain to manage trust relationships between the domain and the federation. Trust proxies interpret assertions from other federated domains as necessary. Trust proxies may have a trust relationship with one or more trust brokers, and a trust proxy may rely upon a trust broker for assistance in interpreting assertions. When a user is provisioned at a particular federated domain, the federated domain can provision the user to other federated domains within the federated environment. A provision operation may include creating or deleting an account for a user, pushing updated user account information including attributes, and requesting updates on account information including attributes.