Identity Assertion Framework for Cross-Domain Token Federation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems in electronic communications face inefficiencies and security challenges when users need to access services across multiple security domains, requiring multiple token issuances and lacking a unified framework for policy enforcement and token federation.
Innovation Solution
An identity assertion framework (IAF) is established, utilizing a security token service (STS) to issue, manage, and federate security tokens across domains, with support for policies, multiple encoding formats, and encryption algorithms, enabling seamless cross-domain authentication and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users access services across multiple security domains, then service accessibility is improved, but the number of authentication operations increases
Solution Approach 1:
The system performs preliminary authentication by issuing a security token that contains authentication assertions. This token is obtained in advance and can be reused across multiple security domains, eliminating the need for repeated authentication operations when accessing services in different domains.
Solution Approach 2:
The patent introduces a security token as an intermediary that mediates between the user and multiple security domains. The token contains authentication assertions that are recognized across domains, allowing the user to access services without direct repeated authentication interactions with each domain.
2Adaptability or versatility
If multiple tokens are issued for cross-domain access, then service accessibility is improved, but system complexity increases
Solution Approach 1:
The security token is designed as a universal credential that can be used across multiple security domains. Instead of requiring separate tokens for each domain, the single token contains authentication assertions that are recognized and accepted by multiple domains, simplifying token management while enabling cross-domain access.
3Productivity
If security tokens are federated across domains, then authentication efficiency is improved, but security policy enforcement difficulty increases
Solution Approach 1:
The system incorporates feedback mechanisms where security policies are evaluated and enforced based on the authentication assertions contained in the security token. The relying party receives the token, evaluates it against security policies, and makes authorization decisions, creating a feedback loop that maintains security while enabling efficient federated authentication.
Data Source
AI summary
Systems and methods for implementing an identity assertion framework to authenticate a user in a federation of security domains are provided. A first security token service associated with a first security domain is configured to receive a request for a first token from a device and issue the first token based on a first issuing policy of the first security domain. A token authenticator associated with a second security domain is configured to determine that the first token is not issued in the second security domain. A hardware-processor-implemented second security token service is configured to receive the first token from the token authenticator, determine that the first token was issued by the first security token service, and validate the first token based on a local federation policy that defines a federation agreement between the first security domain and the second security domain.


