Identity Access Management Controller Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telecommunications systems lack efficient identity and access management (IAM) solutions that allow seamless access to multiple services and applications across various devices without requiring users to provide credentials for each service, leading to complexity and inconvenience.

Innovation Solution

Implementing an IAM system that associates a unique access identifier with multiple service accounts, enabling users to authenticate and access services or applications on any device, while separating device identity from user identity, and providing Single Sign-On (SSO) capabilities through an IAM controller that manages access and routes services based on user profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users provide separate credentials for each service and application on each device, then security and access control are maintained, but user convenience and ease of operation deteriorate due to the need to repeatedly enter login information

Engineering Contradiction:
Improveease of access to servicesVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges multiple service accounts associated with a user into a unified access management system. The IAM controller consolidates authentication for multiple services (telephony, data, messaging) under a single user identity, allowing the user to access any service on any device through one authentication event rather than managing separate credentials for each service.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access identifier becomes a universal key that functions across multiple services and devices. The system design allows a single user identity to universally access telephony services, data services, messaging services, and other applications across different user devices, eliminating the need for service-specific authentication while maintaining security through centralized control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the system separates device identity from user identity, then adaptability across multiple devices is improved, but device complexity increases due to the need to manage multiple service accounts and associations

Engineering Contradiction:
Improvecross-device access capabilityVSAvoididentity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The IAM controller serves as an intermediary between user identities and service accounts. Instead of requiring complex local management of multiple service accounts on each device, the IAM controller centrally manages the associations between user identities and service accounts, handling authentication and authorization transparently. This mediator approach simplifies device complexity while enabling cross-device adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments identity management into two distinct layers: user identity (portable across devices) and device identity (specific to each device). This segmentation allows the user identity to be freely associated with multiple service accounts across different devices without requiring the device itself to manage the complexity of multiple credentials, thereby improving adaptability while controlling complexity through architectural separation.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If the system implements centralized IAM control, then ease of operation is improved through single sign-on, but loss of information increases due to centralized storage of access identifiers and service associations

Engineering Contradiction:
Improvesingle sign-on convenienceVSAvoidcentralized credential storage risk
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts sensitive credential information (passwords, secrets) from the user device and stores only non-sensitive access identifiers (usernames, email addresses) locally on the device. The actual authentication credentials remain secured on the network side (IAM controller), while the device holds only reference information needed to initiate authentication. This extraction reduces the security risk of centralized storage by minimizing what is stored centrally versus locally.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9705871B2Identity and access management
Publication Date: 2017.07.11 T MOBILE US INC
  • US9705871B2 patent drawing
  • US9705871B2 patent drawing
  • US9705871B2 patent drawing

AI summary

An access management account that includes an access identifier may be used to control access to telecommunications services or applications. An access identifier is designated for obtaining access to multiple telecommunications services or applications, in which the multiple telecommunications services or applications are accessible to a user through multiple user accounts that are protected by account credentials. Once the access credential is designated, the access credential may be used to determine whether access to the one or more telecommunications services or applications is to be granted instead of using the account credentials of the multiple user accounts.