Identity Intermediary Single Credential Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication protocols, such as SAML and OpenID, require users to manage multiple sets of credentials for different services, leading to complexity and inconvenience in accessing multiple digital resources.

Innovation Solution

An identity intermediary system that facilitates seamless authentication by generating and managing public/private key pairs, allowing a single set of credentials to access multiple services within a network, with the identity intermediary verifying and bundling credentials for each service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users manage multiple sets of credentials for different services, then authentication security is maintained, but user convenience and ease of operation deteriorate

Engineering Contradiction:
Improveease of accessing multiple servicesVSAvoidcomplexity of managing multiple credentials
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an identity intermediary as a mediator between users and multiple services. This intermediary holds the user's credentials and presents them to various services on behalf of the user, eliminating the need for users to directly manage multiple credential sets. The intermediary translates user authentication into service-specific authentication, resolving the contradiction by reducing user burden while maintaining security through the intermediary's management of credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identity intermediary is designed with universal functionality to handle authentication across multiple different services. It can present different credential formats to different services while maintaining a single user credential set. This multi-functional capability allows the system to improve ease of operation by enabling single-sign-on while adapting to various service authentication requirements, thereby reducing the complexity of credential management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If a single set of credentials is used to access multiple services, then ease of operation improves, but authentication security may deteriorate

Engineering Contradiction:
Improveease of accessing multiple servicesVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The identity intermediary acts as a security mediator that maintains authentication reliability while enabling single credential access. It securely stores user credentials, manages service-specific authentication requirements, and presents appropriate credentials to each service. This intermediary layer ensures that security is not compromised by single-sign-on, as the intermediary maintains control over credential presentation and can implement service-specific security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the authentication process into distinct layers: user credential management, credential translation, and service authentication. The identity intermediary divides the monolithic authentication flow into manageable segments, allowing security to be maintained at each stage. This segmentation enables the system to use a single user credential set while maintaining service-specific security requirements through separate authentication stages.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If federated authentication is implemented with third-party authenticators, then adaptability to different services improves, but system complexity increases

Engineering Contradiction:
Improveability to access different servicesVSAvoidcomplexity of authentication protocol
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The identity intermediary is designed with universal adaptability to work with multiple services and authentication protocols. It can translate between different authentication formats and protocols, allowing users to access diverse services without increasing their burden. The intermediary handles the complexity of federated authentication internally while presenting a simplified interface to users, thereby improving adaptability without proportionally increasing user-facing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The identity intermediary autonomously manages the complexity of federated authentication protocols without requiring user intervention. It automatically handles credential translation, service discovery, and authentication workflow management. This self-service capability allows the system to adapt to different services and protocols while keeping the authentication process simple for users, resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11882120B2Identity intermediary service authorization
Publication Date: 2024.01.23 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11882120B2 patent drawing
  • US11882120B2 patent drawing
  • US11882120B2 patent drawing

AI summary

Examples include service authentication for a principal. A request to access a first service of a plurality of services of a network may be received from a principal by an identity intermediary. An identifier of the first service may be stored at the identity intermediary, and an unsigned credential of the principal and a principal identifier may be transferred from the identity intermediary to a credential provider. The principal identifier and the credential signed by the credential provider may be received, and the signed credential may be transmitted to the first service for authentication.