Identity Access Management Controller Single Sign-On
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telecommunications systems lack efficient identity and access management (IAM) solutions that allow seamless access to multiple services and applications across various devices without requiring users to provide credentials for each service, leading to complexity and inconvenience.
Innovation Solution
Implementing an IAM system that associates a unique access identifier with multiple service accounts, enabling users to authenticate and access services or applications on any device, while separating device identity from user identity, and providing Single Sign-On (SSO) capabilities through an IAM controller that manages access and routes services based on user profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users provide separate credentials for each service and application on each device, then security and access control are maintained, but user convenience and ease of operation deteriorate due to the need to repeatedly enter login information
Solution Approach 1:
The patent merges multiple service accounts associated with a user into a unified access management system. The IAM controller consolidates authentication for multiple services (telephony, data, messaging) under a single user identity, allowing the user to access any service on any device through one authentication event rather than managing separate credentials for each service.
Solution Approach 2:
The access identifier becomes a universal key that functions across multiple services and devices. The system design allows a single user identity to universally access telephony services, data services, messaging services, and other applications across different user devices, eliminating the need for service-specific authentication while maintaining security through centralized control.
2Adaptability or versatility
If the system separates device identity from user identity, then adaptability across multiple devices is improved, but device complexity increases due to the need to manage multiple service accounts and associations
Solution Approach 1:
The IAM controller serves as an intermediary between user identities and service accounts. Instead of requiring complex local management of multiple service accounts on each device, the IAM controller centrally manages the associations between user identities and service accounts, handling authentication and authorization transparently. This mediator approach simplifies device complexity while enabling cross-device adaptability.
Solution Approach 2:
The system segments identity management into two distinct layers: user identity (portable across devices) and device identity (specific to each device). This segmentation allows the user identity to be freely associated with multiple service accounts across different devices without requiring the device itself to manage the complexity of multiple credentials, thereby improving adaptability while controlling complexity through architectural separation.
3Ease of operation
If the system implements centralized IAM control, then ease of operation is improved through single sign-on, but loss of information increases due to centralized storage of access identifiers and service associations
Solution Approach 1:
The patent extracts sensitive credential information (passwords, secrets) from the user device and stores only non-sensitive access identifiers (usernames, email addresses) locally on the device. The actual authentication credentials remain secured on the network side (IAM controller), while the device holds only reference information needed to initiate authentication. This extraction reduces the security risk of centralized storage by minimizing what is stored centrally versus locally.
Data Source
AI summary
An access management account that includes an access identifier may be used to control access to telecommunications services or applications. An access identifier is designated for obtaining access to multiple telecommunications services or applications, in which the multiple telecommunications services or applications are accessible to a user through multiple user accounts that are protected by account credentials. Once the access credential is designated, the access credential may be used to determine whether access to the one or more telecommunications services or applications is to be granted instead of using the account credentials of the multiple user accounts.


