Intermediary Application for Identity Management Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing single sign-on (SSO) and identity management systems lack interoperability, leading to costly and complex integration challenges, particularly in large enterprises with diverse platforms and proprietary solutions, and often require custom development to manage user authentication and access across multiple applications.

Innovation Solution

A platform-independent intermediary application serves as an interface between SSO and identity management systems, utilizing a workflow engine and business process mapping to facilitate seamless information flow and authentication, reducing the need for custom business logic layers and proprietary interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If proprietary SSO systems are used to streamline authentication, then user authentication efficiency is improved, but system interoperability and integration complexity worsen

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidintegration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that sits between the proprietary SSO system and identity management systems. This intermediary translates authentication requests and responses between different protocols and formats, enabling seamless integration without requiring changes to the core SSO or identity management systems. The intermediary acts as a bridge that resolves protocol incompatibilities and data format differences.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal authentication framework that can work with multiple different identity management systems and SSO implementations. The system provides multi-functional capabilities by supporting various authentication protocols (SAML, OAuth, OIDC) and identity management formats through a single integrated platform, eliminating the need for separate integration solutions for each system combination.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If custom business logic layers are developed to integrate SSO with identity management systems, then system-specific authentication requirements are met, but development cost and time increase

Engineering Contradiction:
Improvesystem-specific adaptabilityVSAvoiddevelopment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements a dynamic configuration system that allows authentication behavior to be adjusted without custom code development. The system uses configurable policies, rules engines, and parameter settings that can be modified to meet different system-specific requirements. This dynamic approach replaces static custom business logic with flexible, parameter-driven authentication workflows.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent leverages parameter changes and configuration options to adapt the authentication system to different identity management systems. By modifying authentication parameters, protocol settings, and data mapping configurations, the system can integrate with various identity management platforms without requiring custom business logic development for each integration scenario.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If proprietary interfaces are used in SSO applications, then vendor-specific functionality is optimized, but future platform integration capability deteriorates

Engineering Contradiction:
Improvevendor-specific functionalityVSAvoidfuture integration capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication system into distinct modular components: the SSO interface layer, the intermediary translation layer, and the identity management interface layer. This segmentation allows each component to be optimized for its specific vendor functionality while maintaining standardised interfaces at the boundaries. The modular architecture enables independent optimization of vendor-specific functionality without compromising future integration capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7793343B2Method and system for identity management integration
Publication Date: 2010.09.07 IMPINJ
  • US7793343B2 patent drawing
  • US7793343B2 patent drawing
  • US7793343B2 patent drawing

AI summary

A method and system for a vendor-neutral method of integrating single sign on functionality with the features of a robust identity management application in a cost effective, reliable and timely manner is disclosed. A user accesses the system through a commercially-available single sign on application. When a user requests to be logged in to one or more applications, the request is not sent to a custom business logic layer as known in the art but, instead, is directed to an intermediary application which takes action depending on the nature of the user's login information. The intermediary application serves as the interface between the single sign on application and the identity management system. The intermediary application contains a work flow or business process engine and a method for mapping the business logic. Information flows seamlessly between the single sign on application and the identity management system without regard to either products' platform or vendor.