Identity Provider Discovery System for Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity provider discovery methods are cumbersome and confusing for users, especially in cloud-based organizational services and those catering to both organizational and personal identities, as they often require users to select from multiple providers without clear knowledge of the appropriate identity provider, leading to a poor user experience and increased complexity.

Innovation Solution

Systems and methods that minimize user knowledge requirements by presenting options only when multiple providers match a user identifier, using identity information related to the organization for provider identification, and allowing account creation or retry options when no matching provider is found, thereby streamlining the identity provider discovery and disambiguation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a list of identity provider options is displayed for user selection, then users can choose from multiple providers, but the user interface becomes crowded and confusing, hurting brand equity

Engineering Contradiction:
Improvesupport for multiple identity providersVSAvoiduser interface clarity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent extracts the identity provider selection logic from the user interface by implementing automatic discovery mechanisms. Instead of displaying multiple provider options, the system automatically discovers and presents only the relevant identity provider based on user identifier analysis, thereby removing the cluttered selection interface while maintaining multi-provider support

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary discovery service that acts as a mediator between the user and multiple identity providers. This service analyzes user identifiers, queries multiple providers automatically, and returns the appropriate provider without requiring the user to see or select from a list of options, thus preserving both multi-provider capability and interface simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a shared landing page with email address input is used, then the interface is simplified, but the system cannot determine the appropriate identity provider in open cloud environments without preconceived knowledge

Engineering Contradiction:
Improveinterface simplicityVSAvoidprovider discovery capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary actions by automatically querying multiple identity providers with the user identifier before presenting options to the user. The system pre-discovers which providers have matching records and pre-determines the appropriate provider, eliminating the need for complex interface logic while maintaining adaptability to open cloud environments

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the system queries identity providers with user identifiers, receives responses about account existence, and uses this feedback to automatically determine the appropriate provider. This closed-loop approach enables the simplified interface to work effectively in open cloud environments by letting the system adapt based on provider responses

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple identity providers are supported with the same email address, then user flexibility is increased, but it becomes difficult or impossible to disambiguate the correct provider using traditional approaches

Engineering Contradiction:
Improvemulti-provider account supportVSAvoididentity disambiguation difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses feedback from identity provider queries to resolve ambiguity. When multiple providers support the same email address, the system queries each provider and receives feedback about account existence and user profile information. This feedback enables automatic disambiguation by identifying which provider has the matching account, allowing the system to handle multi-provider support without requiring manual disambiguation

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent implements self-service disambiguation where the system automatically determines the correct identity provider without user intervention. By analyzing user identifiers and querying providers automatically, the system serves itself in resolving ambiguity, eliminating the need for users to manually select or disambiguate between multiple providers

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9544310B2Discovering and disambiguating identity providers
Publication Date: 2017.01.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9544310B2 patent drawing
  • US9544310B2 patent drawing
  • US9544310B2 patent drawing

AI summary

Systems, methods, and computer-readable storage media are provided for discovering and disambiguating identity providers such that user knowledge of appropriate identity providers is minimized. Users are presented with options for selecting appropriate providers only when multiple providers have user profiles matching a user identifier. When users are presented with options for selecting appropriate providers, providers that have user profiles matching the identifier are identified utilizing identity information for the application that utilizes the identity provider for its users rather than information identifying the identity provider itself. Where it is determined that no identity provider has a user profile associated with the user identifier (or where it is determined that a particular identity provider would generally be appropriate to be utilized with the user identifier), the opportunity for users to create an authentication account with one or more identity providers or to retry with a different user identifier is provided.