ID Federation Gateway for Seamless Multi-Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network service providers face challenges in efficiently implementing federated identity solutions across multiple services, leading to redundant user authentication processes that waste resources and diminish user experience, as existing methods require modifying each service provider's internal authentication procedures.

Innovation Solution

A method and apparatus that determine whether a user should be identified by the service provider or a different party, facilitating the use of identification data from the different party and sending user credentials to the service provider's authentication process for seamless access to multiple network resources, utilizing an ID federation gateway to abstract third-party interactions and reduce computational resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If federated identity is implemented by modifying each service provider's internal authentication procedures, then user access to multiple services is enabled, but system complexity and implementation difficulty increase significantly

Engineering Contradiction:
Improveuser access to multiple servicesVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a federated identity gateway as an intermediary component that mediates between service providers and identity providers. The gateway intercepts authentication requests, redirects users to appropriate identity providers, and receives authentication responses. This intermediary approach enables federated identity functionality without requiring modifications to each service provider's internal authentication code, thus reducing system complexity while maintaining adaptability across multiple services

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional authentication is used for each service, then each service maintains independent security control, but users must authenticate multiple times wasting network resources and time

Engineering Contradiction:
Improveindependent security controlVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication action by establishing user identity through a federated identity provider before accessing individual services. The gateway determines the user's identity domain and routes authentication through the appropriate federated identity provider once. The authentication result is then recognized across multiple services, eliminating redundant authentication steps while maintaining security control through the federated identity framework

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If federated identity gateway is introduced to abstract third-party interactions, then modification of existing authentication systems is minimized, but new system components and integration complexity are added

Engineering Contradiction:
Improvesystem implementation easeVSAvoidnumber of system components
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The federated identity gateway is designed as a universal component that handles multiple authentication protocols and identity provider types through a standardized interface. It can manage both internal corporate identity providers and external third-party identity providers using the same gateway infrastructure. This multi-functional design reduces the need for separate integration components for different identity providers, thereby easing implementation while controlling overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2537317B1Method and apparatus for identity federation gateway
Publication Date: 2024.12.04 NOKIA TECHNOLOGIES OY
  • EP2537317B1 patent drawingFigure 1
  • EP2537317B1 patent drawingFigure 2A~2C
  • EP2537317B1 patent drawingFigure 3A~3C

AI summary

Techniques for an ID federation gateway include determining whether a user associated with a request for a particular network resource is to be identified by the provider of the particular service or by a different party. The service also comprises causing the different party to provide identification data that indicates an identity for the user, if the user is to be identified by the different party. The method further comprises causing user credentials data, based on the identification data, to be sent to an authentication process of the provider for a set of one or more network resources that includes the particular network resource requested by the user, if the data indicates that the user is successfully identified.