Intermediary Authentication System for Network Login
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face the burden of managing multiple credentials for various networks and web applications, and existing single sign-on (SSO) protocols often require redundant authentication processes, leading to inefficiencies in granting access.
Innovation Solution
A system that receives client authentication information from a first authentication server and forwards it to a second server without verifying the initial authentication, allowing network access based on the second server's confirmation, thereby streamlining the authentication process across multiple systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each network or web application implements its own authentication scheme, then security and access control are maintained, but users must remember or securely store a large number of credentials
Solution Approach 1:
The patent introduces an intermediary authentication system that sits between users and multiple web applications. This intermediary handles credential verification centrally, allowing users to authenticate once and access multiple applications without managing separate credentials for each application, thus resolving the contradiction between maintaining access control and simplifying credential management
2Ease of operation
If SSO protocols allow external authentication systems, then user convenience is improved, but redundant authentication processes are required
Solution Approach 1:
The patent implements preliminary authentication by verifying credentials against the first authentication server's database before the client device attempts authentication with the second server. This preliminary verification prevents redundant authentication processes and reduces the time users spend authenticating across multiple systems while maintaining user convenience
Data Source
AI summary
In general, in one aspect, embodiments relate to receiving, by a system comprising one or more network devices, a first client authentication information comprising a first indication that a first client device was successfully authenticated by a first authentication server based on credentials provided by the first client device, and forwarding, by the system, the first client authentication information to a second authentication server without determining that the client device was already successfully authenticated by the first authentication server based on the credentials provided by the first client device. The operations further include receiving, by the system from the second authentication server, a second indication that the first client device was successfully authenticated, and based on the second indication received by the system from the second authentication server, granting, by the system, network access to the first client device.


