Identity Provider Mesh Network for Federated Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In industries like automobile dealership, users face inconvenience due to the need to interact with multiple software applications separately and manage multiple sets of login credentials, which can be costly and disruptive to migrate to a single identity provider (IDP) system.
Innovation Solution
The implementation of an IDP mesh network that allows multiple disparate IDPs to be federated in a mesh model, enabling users to access software applications protected by any IDP in the mesh with a single set of sign-on credentials, using protocols like SAML2 and bi-directional single sign-on (SSO) endpoints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple separate IDP systems are used for different software applications, then each application can be independently managed with its own authentication system, but users must manage multiple sets of login credentials and interact with each application separately
Solution Approach 1:
The patent combines multiple separate IDP systems into a unified federated identity management system where multiple IDPs are interconnected through a mesh network. This allows users to authenticate once with any IDP in the network and access multiple software applications without managing separate credentials for each application, resolving the contradiction between independent management and ease of operation.
Solution Approach 2:
The federated identity management system creates a universal authentication mechanism that works across all software applications in the network. A single set of credentials issued by any IDP in the mesh network can be used to access multiple different applications, providing multi-functionality that eliminates the need for users to manage multiple credential sets while preserving application independence.
2Ease of operation
If users are migrated to a single IDP system, then credential management is simplified, but costly reprogramming and system migration are required
Solution Approach 1:
The system segments the identity management architecture into independent, interoperable IDP components connected through a mesh network. Each IDP remains as a separate, autonomous system that can issue credentials independently, eliminating the need for costly migration to a centralized system while achieving simplified credential management through federated authentication across the segmented network.
3Ease of operation
If a federated IDP mesh network is implemented, then seamless authentication across multiple applications is achieved, but system complexity increases
Solution Approach 1:
The patent introduces standardized protocols and trust frameworks as intermediaries that mediate communication between multiple IDPs in the mesh network. These intermediaries handle the complex authentication workflows, trust verification, and credential validation automatically, providing seamless user authentication experience while abstracting away the underlying system complexity from end users.
Data Source
AI summary
Identity provider (IDP) mesh networks and related systems, apparatuses, and methods are disclosed. A first software domain to participate in an IDP mesh network manages first software applications of the first software domain. A first IDP of the first software domain provides access to the first software applications of the first software domain to first users registered with the first software domain responsive to first verified login credentials provided to the first IDP. The first IDP also federates, with a second IDP of a second software domain participating in the IDP mesh network, access of the first users to second software applications of the second software domain responsive to the first verified login credentials.


