Intermediary Application for Identity Management Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing single sign-on (SSO) and identity management systems lack interoperability, leading to costly and complex integration challenges, particularly in large enterprises with diverse platforms and proprietary solutions, and often require custom development to manage user authentication and access across multiple applications.
Innovation Solution
A platform-independent intermediary application serves as an interface between SSO and identity management systems, utilizing a workflow engine and business process mapping to facilitate seamless information flow and authentication, reducing the need for custom business logic layers and proprietary interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If proprietary SSO systems are used to streamline authentication, then user authentication efficiency is improved, but system interoperability and integration complexity worsen
Solution Approach 1:
The patent introduces an intermediary component that sits between the proprietary SSO system and identity management systems. This intermediary translates authentication requests and responses between different protocols and formats, enabling seamless integration without requiring changes to the core SSO or identity management systems. The intermediary acts as a bridge that resolves protocol incompatibilities and data format differences.
Solution Approach 2:
The patent creates a universal authentication framework that can work with multiple different identity management systems and SSO implementations. The system provides multi-functional capabilities by supporting various authentication protocols (SAML, OAuth, OIDC) and identity management formats through a single integrated platform, eliminating the need for separate integration solutions for each system combination.
2Adaptability or versatility
If custom business logic layers are developed to integrate SSO with identity management systems, then system-specific authentication requirements are met, but development cost and time increase
Solution Approach 1:
The patent implements a dynamic configuration system that allows authentication behavior to be adjusted without custom code development. The system uses configurable policies, rules engines, and parameter settings that can be modified to meet different system-specific requirements. This dynamic approach replaces static custom business logic with flexible, parameter-driven authentication workflows.
Solution Approach 2:
The patent leverages parameter changes and configuration options to adapt the authentication system to different identity management systems. By modifying authentication parameters, protocol settings, and data mapping configurations, the system can integrate with various identity management platforms without requiring custom business logic development for each integration scenario.
3Reliability
If proprietary interfaces are used in SSO applications, then vendor-specific functionality is optimized, but future platform integration capability deteriorates
Solution Approach 1:
The patent segments the authentication system into distinct modular components: the SSO interface layer, the intermediary translation layer, and the identity management interface layer. This segmentation allows each component to be optimized for its specific vendor functionality while maintaining standardised interfaces at the boundaries. The modular architecture enables independent optimization of vendor-specific functionality without compromising future integration capabilities.
Data Source
AI summary
A method and system for a vendor-neutral method of integrating single sign on functionality with the features of a robust identity management application in a cost effective, reliable and timely manner is disclosed. A user accesses the system through a commercially-available single sign on application. When a user requests to be logged in to one or more applications, the request is not sent to a custom business logic layer as known in the art but, instead, is directed to an intermediary application which takes action depending on the nature of the user's login information. The intermediary application serves as the interface between the single sign on application and the identity management system. The intermediary application contains a work flow or business process engine and a method for mapping the business logic. Information flows seamlessly between the single sign on application and the identity management system without regard to either products' platform or vendor.


