Identity Provider Mesh Network for Federated Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In industries like automobile dealership, users face inconvenience due to the need to interact with multiple software applications separately and manage multiple sets of login credentials, which can be costly and disruptive to migrate to a single identity provider (IDP) system.

Innovation Solution

The implementation of an IDP mesh network that allows multiple disparate IDPs to be federated in a mesh model, enabling users to access software applications protected by any IDP in the mesh with a single set of sign-on credentials, using protocols like SAML2 and bi-directional single sign-on (SSO) endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple separate IDP systems are used for different software applications, then each application can be independently managed with its own authentication system, but users must manage multiple sets of login credentials and interact with each application separately

Engineering Contradiction:
ImproveIndependent management of software applicationsVSAvoidUser credential management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent combines multiple separate IDP systems into a unified federated identity management system where multiple IDPs are interconnected through a mesh network. This allows users to authenticate once with any IDP in the network and access multiple software applications without managing separate credentials for each application, resolving the contradiction between independent management and ease of operation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The federated identity management system creates a universal authentication mechanism that works across all software applications in the network. A single set of credentials issued by any IDP in the mesh network can be used to access multiple different applications, providing multi-functionality that eliminates the need for users to manage multiple credential sets while preserving application independence.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If users are migrated to a single IDP system, then credential management is simplified, but costly reprogramming and system migration are required

Engineering Contradiction:
ImproveCredential managementVSAvoidSystem migration cost
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The system segments the identity management architecture into independent, interoperable IDP components connected through a mesh network. Each IDP remains as a separate, autonomous system that can issue credentials independently, eliminating the need for costly migration to a centralized system while achieving simplified credential management through federated authentication across the segmented network.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If a federated IDP mesh network is implemented, then seamless authentication across multiple applications is achieved, but system complexity increases

Engineering Contradiction:
ImproveUser authenticationVSAvoidIDP network architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces standardized protocols and trust frameworks as intermediaries that mediate communication between multiple IDPs in the mesh network. These intermediaries handle the complex authentication workflows, trust verification, and credential validation automatically, providing seamless user authentication experience while abstracting away the underlying system complexity from end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250080535A1Identity provider mesh networks and related apparatuses, systems, and methods
Publication Date: 2025.03.06 CDK GLOBAL LLC
  • US20250080535A1 patent drawing
  • US20250080535A1 patent drawing
  • US20250080535A1 patent drawing

AI summary

Identity provider (IDP) mesh networks and related systems, apparatuses, and methods are disclosed. A first software domain to participate in an IDP mesh network manages first software applications of the first software domain. A first IDP of the first software domain provides access to the first software applications of the first software domain to first users registered with the first software domain responsive to first verified login credentials provided to the first IDP. The first IDP also federates, with a second IDP of a second software domain participating in the IDP mesh network, access of the first users to second software applications of the second software domain responsive to the first verified login credentials.