Identity Proxy Gateway for Multi-Provider Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for sharing identity across multiple partners or contractors are cumbersome, prone to errors, and inefficient, particularly when integrating identity providers for external parties, which can lead to increased overhead in time and cost.

Innovation Solution

An identity proxy and access gateway that proxies between multiple identity providers and multiple remote SaaS applications, allowing users to select from presented identity providers, enforcing additional access rules beyond those set by identity providers or SaaS applications, and logging connections for auditing and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the internal organization onboards the external party to their own identity provider, then the internal organization gains control of identity, but it adds overhead in terms of time and cost

Engineering Contradiction:
Improveidentity controlVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an identity federation service as an intermediary between the internal organization's identity provider and the external party's identity provider. This mediator enables automatic identity verification and federation without requiring manual onboarding processes, thus maintaining identity control while eliminating time overhead

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary identity federation setup between organizations before external parties need access. Once federated, external parties can automatically authenticate using their existing credentials without going through repeated onboarding processes, saving time while maintaining security control

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the internal organization onboards the external party to their own identity provider, then the internal organization gains control of identity, but it increases cost due to additional seat licenses

Engineering Contradiction:
Improveidentity controlVSAvoidcost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The identity federation service acts as a cost-effective intermediary that enables external parties to access internal resources using their own identity providers. This eliminates the need to purchase additional seat licenses for external contractors while maintaining identity verification and access control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a virtual copy of the identity verification process through federation, allowing external parties to authenticate against their own identity provider while the internal organization maintains control policies. This avoids the cost of duplicating full identity provider licenses for external users

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If the internal organization federates the identity with the external party's service, then both organizations can trust each other's credentials, but both organizations must dedicate time to integrate their identity providers

Engineering Contradiction:
Improveidentity trustVSAvoidintegration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent introduces a standardized identity federation service as a mediator that handles the complex integration between different identity providers. This intermediary translates and federates credentials between organizations using standard protocols, enabling mutual trust without requiring direct time-consuming integration between each organization's identity systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The identity federation service provides universal integration capabilities that work with multiple different identity provider formats and protocols. This multi-functional approach allows any organization to connect to the federation service without custom integration work, establishing trust relationships efficiently

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If the internet security service changes the authoritative DNS for the internal application, then security rules can be enforced for HTTP requests, but remote SaaS applications cannot be controlled as they are third-party services

Engineering Contradiction:
Improveaccess controlVSAvoidremote application control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an identity gateway as an intermediary layer between users and remote SaaS applications. This gateway intercepts authentication requests to third-party services, enforces organizational access control policies, and manages identity federation for remote applications that would otherwise be uncontrollable direct third-party connections

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12335263B2Identity proxy and access gateway
Publication Date: 2025.06.17 CLOUDFLARE INC
  • US12335263B2 patent drawing
  • US12335263B2 patent drawing
  • US12335263B2 patent drawing

AI summary

A server transmits to a third-party application a request for a resource that is received from a client. The server receives an authentication request from the client device that has been generated by the third-party application. The server transmits an identity provider selection page to the client device that allows the client device to select an identity provider. The server causes the client device to transmit a second authentication request to a selected identity provider. The server receives an authentication response that was generated by the identity provider that includes the identity of the user. The server enforces access rule(s) including identity-based rule(s) and/or non-identity based rule(s). If the user is permitted to access the third-party application, the server causes an authentication response to be transmitted from the client device to the third-party application that indicates the user has successfully authenticated.