Intermediary Authentication System for Network Login

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the burden of managing multiple credentials for various networks and web applications, and existing single sign-on (SSO) protocols often require redundant authentication processes, leading to inefficiencies in granting access.

Innovation Solution

A system that receives client authentication information from a first authentication server and forwards it to a second server without verifying the initial authentication, allowing network access based on the second server's confirmation, thereby streamlining the authentication process across multiple systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each network or web application implements its own authentication scheme, then security and access control are maintained, but users must remember or securely store a large number of credentials

Engineering Contradiction:
Improveaccess controlVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication system that sits between users and multiple web applications. This intermediary handles credential verification centrally, allowing users to authenticate once and access multiple applications without managing separate credentials for each application, thus resolving the contradiction between maintaining access control and simplifying credential management

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If SSO protocols allow external authentication systems, then user convenience is improved, but redundant authentication processes are required

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication by verifying credentials against the first authentication server's database before the client device attempts authentication with the second server. This preliminary verification prevents redundant authentication processes and reduces the time users spend authenticating across multiple systems while maintaining user convenience

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10581827B2Using application level authentication for network login
Publication Date: 2020.03.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10581827B2 patent drawing
  • US10581827B2 patent drawing
  • US10581827B2 patent drawing

AI summary

In general, in one aspect, embodiments relate to receiving, by a system comprising one or more network devices, a first client authentication information comprising a first indication that a first client device was successfully authenticated by a first authentication server based on credentials provided by the first client device, and forwarding, by the system, the first client authentication information to a second authentication server without determining that the client device was already successfully authenticated by the first authentication server based on the credentials provided by the first client device. The operations further include receiving, by the system from the second authentication server, a second indication that the first client device was successfully authenticated, and based on the second indication received by the system from the second authentication server, granting, by the system, network access to the first client device.