Identity Assertion Framework for Cross-Domain Token Federation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems in electronic communications face inefficiencies and security challenges when users need to access services across multiple security domains, requiring multiple token issuances and lacking a unified framework for policy enforcement and token federation.

Innovation Solution

An identity assertion framework (IAF) is established, utilizing a security token service (STS) to issue, manage, and federate security tokens across domains, with support for policies, multiple encoding formats, and encryption algorithms, enabling seamless cross-domain authentication and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users access services across multiple security domains, then service accessibility is improved, but the number of authentication operations increases

Engineering Contradiction:
Improveservice accessibilityVSAvoidauthentication operations
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The system performs preliminary authentication by issuing a security token that contains authentication assertions. This token is obtained in advance and can be reused across multiple security domains, eliminating the need for repeated authentication operations when accessing services in different domains.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security token as an intermediary that mediates between the user and multiple security domains. The token contains authentication assertions that are recognized across domains, allowing the user to access services without direct repeated authentication interactions with each domain.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple tokens are issued for cross-domain access, then service accessibility is improved, but system complexity increases

Engineering Contradiction:
Improvecross-domain accessVSAvoidtoken management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security token is designed as a universal credential that can be used across multiple security domains. Instead of requiring separate tokens for each domain, the single token contains authentication assertions that are recognized and accepted by multiple domains, simplifying token management while enabling cross-domain access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If security tokens are federated across domains, then authentication efficiency is improved, but security policy enforcement difficulty increases

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidpolicy enforcement
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system incorporates feedback mechanisms where security policies are evaluated and enforced based on the authentication assertions contained in the security token. The relying party receives the token, evaluates it against security policies, and makes authorization decisions, creating a feedback loop that maintains security while enabling efficient federated authentication.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9571285B2Identity assertion framework
Publication Date: 2017.02.14 EBAY INC
  • US9571285B2 patent drawing
  • US9571285B2 patent drawing
  • US9571285B2 patent drawing

AI summary

Systems and methods for implementing an identity assertion framework to authenticate a user in a federation of security domains are provided. A first security token service associated with a first security domain is configured to receive a request for a first token from a device and issue the first token based on a first issuing policy of the first security domain. A token authenticator associated with a second security domain is configured to determine that the first token is not issued in the second security domain. A hardware-processor-implemented second security token service is configured to receive the first token from the token authenticator, determine that the first token was issued by the first security token service, and validate the first token based on a local federation policy that defines a federation agreement between the first security domain and the second security domain.