Identity Intermediary Single Credential Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication protocols, such as SAML and OpenID, require users to manage multiple sets of credentials for different services, leading to complexity and inconvenience in accessing multiple digital resources.
Innovation Solution
An identity intermediary system that facilitates seamless authentication by generating and managing public/private key pairs, allowing a single set of credentials to access multiple services within a network, with the identity intermediary verifying and bundling credentials for each service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users manage multiple sets of credentials for different services, then authentication security is maintained, but user convenience and ease of operation deteriorate
Solution Approach 1:
The patent introduces an identity intermediary as a mediator between users and multiple services. This intermediary holds the user's credentials and presents them to various services on behalf of the user, eliminating the need for users to directly manage multiple credential sets. The intermediary translates user authentication into service-specific authentication, resolving the contradiction by reducing user burden while maintaining security through the intermediary's management of credentials.
Solution Approach 2:
The identity intermediary is designed with universal functionality to handle authentication across multiple different services. It can present different credential formats to different services while maintaining a single user credential set. This multi-functional capability allows the system to improve ease of operation by enabling single-sign-on while adapting to various service authentication requirements, thereby reducing the complexity of credential management.
2Ease of operation
If a single set of credentials is used to access multiple services, then ease of operation improves, but authentication security may deteriorate
Solution Approach 1:
The identity intermediary acts as a security mediator that maintains authentication reliability while enabling single credential access. It securely stores user credentials, manages service-specific authentication requirements, and presents appropriate credentials to each service. This intermediary layer ensures that security is not compromised by single-sign-on, as the intermediary maintains control over credential presentation and can implement service-specific security policies.
Solution Approach 2:
The system segments the authentication process into distinct layers: user credential management, credential translation, and service authentication. The identity intermediary divides the monolithic authentication flow into manageable segments, allowing security to be maintained at each stage. This segmentation enables the system to use a single user credential set while maintaining service-specific security requirements through separate authentication stages.
3Adaptability or versatility
If federated authentication is implemented with third-party authenticators, then adaptability to different services improves, but system complexity increases
Solution Approach 1:
The identity intermediary is designed with universal adaptability to work with multiple services and authentication protocols. It can translate between different authentication formats and protocols, allowing users to access diverse services without increasing their burden. The intermediary handles the complexity of federated authentication internally while presenting a simplified interface to users, thereby improving adaptability without proportionally increasing user-facing complexity.
Solution Approach 2:
The identity intermediary autonomously manages the complexity of federated authentication protocols without requiring user intervention. It automatically handles credential translation, service discovery, and authentication workflow management. This self-service capability allows the system to adapt to different services and protocols while keeping the authentication process simple for users, resolving the contradiction between adaptability and complexity.
Data Source
AI summary
Examples include service authentication for a principal. A request to access a first service of a plurality of services of a network may be received from a principal by an identity intermediary. An identifier of the first service may be stored at the identity intermediary, and an unsigned credential of the principal and a principal identifier may be transferred from the identity intermediary to a credential provider. The principal identifier and the credential signed by the credential provider may be received, and the signed credential may be transmitted to the first service for authentication.


