Identity Management System for Silent Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As businesses increasingly deploy applications and services to the cloud, there is a growing need for robust security solutions to manage and authenticate users across various cloud-based services, particularly for sharing information, which existing technologies have not adequately addressed.

Innovation Solution

The implementation of an identity management system that includes an identity provider server and a user management server, which performs silent authentication by applying cryptographic functions and modifications to messages, providing a site token for secure access to resources, while keeping the cryptographic functions and modifications known only to the identity provider and user management servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods are used for each cloud service, then user management becomes complex and time-consuming, but security requirements are not adequately met

Engineering Contradiction:
Improveuser managementVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple authentication functions into a single identity provider that handles authentication across multiple cloud services. The identity provider consolidates user credentials and authentication logic, eliminating the need for separate authentication systems at each service while maintaining strong security through centralized cryptographic verification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The identity provider acts as an intermediary between users and cloud services. It receives authentication requests from services, verifies credentials using cryptographic functions, and returns authentication results. This mediator approach simplifies service implementation while ensuring consistent security across all services.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic functions are implemented at each service, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts cryptographic functionality from individual cloud services and consolidates it in a dedicated identity provider. Services no longer need to implement their own cryptographic verification logic; instead, they delegate authentication to the identity provider, which handles all cryptographic operations centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The identity provider serves multiple cloud services with a single authentication system. It implements universal cryptographic verification that works across all participating services, eliminating the need for each service to have specialized security implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If single sign-on is implemented across cloud services, then user convenience is improved, but authentication security may be compromised

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary cryptographic verification of user credentials before granting access to any service. The identity provider validates authentication tokens using pre-shared cryptographic keys and verification algorithms, ensuring security is established before the convenience of single sign-on takes effect.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical authentication mechanisms (password checking, session management) with cryptographic verification. The identity provider uses cryptographic signatures and verification functions to authenticate users, providing both convenience and strong security through mathematical proofs rather than procedural checks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11570164B2System and method of single sign on to master website and silent authentication for subservient websites
Publication Date: 2023.01.31 DELL PROD LP
  • US11570164B2 patent drawing
  • US11570164B2 patent drawing
  • US11570164B2 patent drawing

AI summary

Systems and methods are provided that may be implemented as an identity management system to provide a single sign on to a master website and silent authentication for subservient websites. The identity management system may include an identity provider server and a user management server. The identity provider server may authenticate a user, redirect an authenticated user to the user management server, and receive and verify a silent authentication request including a cryptographic signature and a modified message on behalf of the authenticated user from the user management server.