Identity Adaptation Provider for RTCWEB Legacy Protocol Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RTCWEB protocol suite faces compatibility issues with legacy security devices that do not support all required protocols, hindering seamless authentication and identity verification in web-based real-time communication applications.

Innovation Solution

An Identity Adaptation Provider (IdAP) system is introduced, which includes an IdP client for RTCWEB protocol communication and a RP client for non-RTCWEB protocol communication, enabling authentication and identity verification by creating proxies for both layers and facilitating authentication without receiving user secrets, thus allowing RTCWEB identity authentication even with non-RTCWEB compliant IdP servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If RTCWEB protocol is used for authentication, then real-time communication functionality is improved, but compatibility with legacy security devices deteriorates

Engineering Contradiction:
ImproveRTCWEB protocol compatibilityVSAvoidauthentication reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an Identity Adaptation Provider (IdAP) as an intermediary component that sits between the RTCWEB client and legacy IdP servers. The IdAP translates RTCWEB authentication requests into protocols that legacy IdP servers understand, and vice versa. This mediator enables RTCWEB functionality to work with non-RTCWEB compliant devices without requiring changes to either side, resolving the compatibility issue while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct functional layers: an RTCWEB layer for modern protocol communication and a non-RTCWEB layer for legacy protocol compatibility. The IdAP manages these separate layers, allowing each to operate independently according to its protocol requirements. This segmentation enables the system to maintain RTCWEB real-time communication capabilities while simultaneously supporting legacy authentication mechanisms.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If legacy IdP servers are used, then backward compatibility is improved, but RTCWEB functionality deteriorates

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidauthentication efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The IdAP serves as a translation intermediary that enables legacy IdP servers to participate in RTCWEB ecosystems. It converts RTCWEB authentication protocols into the legacy protocols that older servers understand, allowing these servers to maintain relevance in modern RTCWEB environments without requiring them to implement new protocols, thus preserving backward compatibility while enabling efficient authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The IdAP is designed as a universal adapter that can interface with multiple different authentication protocols simultaneously. It provides multi-functionality by handling both RTCWEB and legacy protocol communications through a single system component, allowing legacy servers to serve multiple purposes in the modern authentication landscape without sacrificing efficiency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If protocol translation is implemented, then adaptability to different IdP servers is improved, but system complexity increases

Engineering Contradiction:
ImproveIdP server adaptabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

By consolidating all protocol translation logic into a single IdAP intermediary component, the system manages complexity centrally rather than distributing it across multiple clients and servers. The IdAP handles the complexity of protocol conversion, negotiation, and translation in one location, making the system more adaptable to different IdP servers while keeping the overall architecture manageable and not significantly increasing operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9258292B2Adapting federated web identity protocols
Publication Date: 2016.02.09 FUTUREWEI TECHNOLOGIES INC
  • US9258292B2 patent drawing
  • US9258292B2 patent drawing
  • US9258292B2 patent drawing

AI summary

A method of performing a Real-Time Communication in Web-browsers (RTCWEB) identity authentication based on an authentication of a non-RTCWEB compliant Identity Provider (IdP) server comprising receiving, by an RTCWEB IdP client, an RTCWEB identity authentication request from a user agent, creating a session resource with a Relying Party (RP) client, wherein the RP client guards the session resource, instructing the user agent to authenticate with the RP client by employing a non-RTCWEB identity protocol to access the session resource, receiving authentication results from the non-RTCWEB compliant IdP server via the RP client, and sending an RTCWEB authentication to the user agent via the session resource.